Earlier quoted context omitted.
Unfortunately it's one of the most bug-ridden and unreliable pieces of software I've ever used. I encounter issues with it on a daily basis, but the burden of switching and a lack of superior options keeps me locked in.
I stopped paying them when they killed local valuts, and secondarily when then moved away from native apps. I drifted along on the old 7.x client for awhile with local values. I've more or less switched to apple keychain/passwords at this point. I need a solution for linux, and have been thinking about some kind of simple 1-way sync issue that dumps stuff from keychain into some other tool for use on linux.
LastPass notifies users of yet another data breach
211–220 of 246 posts
Re: LastPass notifies users of yet another data breach
#212Earlier quoted context omitted.
Unfortunately it's one of the most bug-ridden and unreliable pieces of software I've ever used. I encounter issues with it on a daily basis, but the burden of switching and a lack of superior options keeps me locked in.
Any example bugs that you've encountered in the last week?
It won't ask me for my secret key, which I have an can provide immediately, no, it won't allow me to authenticate myself with the phone, because our enterprise vault logs off quickly, I must however do a some absurdly obscure dance because FY, that's why.
Re: LastPass notifies users of yet another data breach
#213Earlier quoted context omitted.
Did they need to give them all of this? customer names, phone numbers, email addresses, physical addresses, support case data, sales-related data.
Generally yes, if you want to use a Customer Relationship Management system like Salesforce. Customer names, contact information, and info about what they bought from you is table stakes data for CRM is it not?
Re: LastPass notifies users of yet another data breach
#214I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP. The lesson here is to get off of LP ASAP, you can figure out where to go later.
this is... such a bad idea lol
Re: LastPass notifies users of yet another data breach
#215Earlier quoted context omitted.
How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.
KeepassXC comes with its own share of risks (supply-chain attacks, zero-day vulnerability detections etc). No matter, which 3p software you are using, you are effectively gambling on the chance that none of those risks materialize. The only alternative is to personally audit the code - library by library, script by script and build it yourself. But even that carries risks: https://www.cs.cmu.edu/~rdriley/487/papers/T…
If I keep a KeepassXC database on a set of devices, sync'd using syncthing, then for a large range of threats I'd need to be a target of interest.
This is in contrast to LastPass which is going to attract a ton of blackhat attention.
Yes, supply chain attacks are possible but they're equally possible for lastpass.
Switching to a self-hosted solution isn't perfect. Nothing is, and pointing that out isn't particularly useful.
What it does do is eliminate whole class of threats: large scale, broad based attacks against a single, high value target.
In fact I'd argue writing passwords down in a notebook or putting them in a naked text file on your computer is better than trusting a centralized service like LP.
Of course, if you are a target of interest, the calculus changes entirely.
Re: LastPass notifies users of yet another data breach
#216Re: LastPass notifies users of yet another data breach
#217WTF is LastPasd doing, handing customer details to a market research company? Any such data should have been fully anonymized: no names, no specific addresses, etc.. For anyone looking for a recommendation: I use KeepassXC with Keepass2Android. Open source, with a local database that you can choose to sync (or not). I sync using Own cloud.
To be fair, I could just sync the db somewhere safe.
Re: LastPass notifies users of yet another data breach
#218Earlier quoted context omitted.
How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.
it's "trivial" in the sense of "I can launch the app in 2 minutes," but "non-trivial" in the sense of "I have a working, synced password manager across my devices with good security practices."
It is a tool that does one thing really well.
It is trivial to sync the password db. You can use whatever you prefer.
> "I have a working, synced password manager across my devices with good security practices."
Well, using Lastpass or any other third party to store your passwords was never good security practice.
Re: LastPass notifies users of yet another data breach
#219Re: LastPass notifies users of yet another data breach
#220Earlier quoted context omitted.
How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.
it's "trivial" in the sense of "I can launch the app in 2 minutes," but "non-trivial" in the sense of "I have a working, synced password manager across my devices with good security practices."
Is that actually something the average person needs? Do they create new accounts ever day or week that they need to have on all device immediately? Merging DBs is like a 2 minute exercise at best.
I would argue the friction is a good thing. "Do I actually need to give yet another website information about myself for an account?" The answer is no more often than not.
Yes I know people don't care but those who don't are not using a password manager.