Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

221–230 of 326 posts

Re: LastPass users warned their master passwords are compromised

#221

This is framed so negatively toward LastPass, which is unfortunate. They stopped all usage of correct passwords they believed were compromised, which is exactly what I'd want them to do in this situation. Them warning users their master passwords are compromised is a good thing! Yet it's framed as though they're admitting to something. "However, users receiving these warnings have stated that their passwords are uniq…

Apparently this just started yesterday. If someone's LastPass account has been successfully compromised since then, we might not hear about it until that person logs into another account and discovers funds missing.

Re: LastPass users warned their master passwords are compromised

#222
Lots of people here recommending to switch to Keepass.

I have both Keepass and Lastpass, but the reason I didn't do away with Lastpass yet is basically that it seems to me that Keepass can't do proper form-filling like Lastpass can? I'm talking about: auto filling custom configurable fields, addresses, credit cards, etc.

Am I missing something, some addon/extension?

My current Keepass setup:

Keepass 2 with Keeweb for filling passwords in Firefox on PC and KeePassDX for filling passwords on Android. All Keepass DB files are synced using Syncthing, which works fine.

Re: LastPass users warned their master passwords are compromised

#223
post #212

Earlier quoted context omitted.

>I saw a few mentions of uBlock origin in yesterday's thread Statistically speaking it's probably because everyone has ublock origin installed, rather than it getting hacked. It's used by 5M+ users on firefox and "10,000,000+" on chrome. If ublock was really compromised you'd expect widespread reports of account compromise, rather than for only one password manager.

That's a good point. I'm happy to delete my message if this way of finding out doesn't make sense.

Because it’s popular makes it an even bigger target.

Re: LastPass users warned their master passwords are compromised

#225
post #71

Earlier quoted context omitted.

What's your personal threat model? I'm always trying to balance the risk of a party focused on security vs the minimal effort I'm likely to put into it. I don't want to be a story about the guy that lost their password to a wallet or anything else important. I used to be able to reliably remember complex passwords reliably but finding that's no longer the case, now only shorter intermittently used ones based on how o…

I’ve decided that besides a password manager, all of my passwords will also have a number at the end, like 8 (simple, easy to append manually in a password field. Now the password manager has to get defeated AND my own small personal salt value will have to be known.

Will it always be 8? Or will it vary?

Re: LastPass users warned their master passwords are compromised

#226
post #128

Algorithmic passwords. Come up with an algorithm a(website, rules) that you can remember and that generates unique passwords per website. Store the rules (length restrictions, special character restrictions, number of times the password has changed, etc) in a google doc or something. Print out your algorithm on a physical piece of paper and put it in a safe place for after you die and people need to access your accou…

Password managers offer plenty of perks. Automatic logins, notes, tokens\OTP and more. Writing passwords each time is so old now. there are plenty of good password managers either local or cloud based.

Not to mention that automatic logins isn't just a perk, it's a security feature. Your password manager will not mistake leg1t-website.com for legit-website.com and type in your password into a phishing site because it just woke up.

Re: LastPass users warned their master passwords are compromised

#227
post #115

To those who are recommending all different password managers, I have a question: why not using Chrome (or Firefox/Edge/ )'s built-in password manager? I have been using it for a couple years and haven't noticed any issue. Even if Google decides to screw me over and terminates my Google account, I can still access the passwords via the local copy in Chrome, so that is not really a concern. (Though, don't take this as…

I do. I treat them as a kind of cache and use pass as my password master.

Re: LastPass users warned their master passwords are compromised

#228

Lots of people here recommending to switch to Keepass. I have both Keepass and Lastpass, but the reason I didn't do away with Lastpass yet is basically that it seems to me that Keepass can't do proper form-filling like Lastpass can? I'm talking about: auto filling custom configurable fields, addresses, credit cards, etc. Am I missing something, some addon/extension? My current Keepass setup: Keepass 2 with Keeweb for…

I used to use Keepass + syncthing. But I switched to Bitwarden and haven't looked back. You can selfhost your own Bitwarden server if you're extra paranoid.

Re: LastPass users warned their master passwords are compromised

#229

Not good news - I use Bitwarden, not LastPass, but if you're using a password manager make sure to use 2 factor authentication and this really wouldn't be an issue in the first place. I have my TOTP codes stored in Bitwarden for other services like Facebook etc, but I use Authy as an independent TOTP provider for Bitwarden. 1.5 factor I guess (2FA tokens in a password manager), but works a treat and is very convenien…

I've considered switching from Authy to Bitwarden for TOTP. But besides the headache of moving all my accounts...I worry about "having all my eggs in one basket". I mean, the purpose of TOTP is to have MULTI factor auth. With both the password and TOTP code in Bitwarden, you actually remove the multi factor part.

Re: LastPass users warned their master passwords are compromised

#230
post #115

To those who are recommending all different password managers, I have a question: why not using Chrome (or Firefox/Edge/ )'s built-in password manager? I have been using it for a couple years and haven't noticed any issue. Even if Google decides to screw me over and terminates my Google account, I can still access the passwords via the local copy in Chrome, so that is not really a concern. (Though, don't take this as…

Because then you're tied to whatever browser you pick. I prefer to stay browser agnostic; Bitwarden for passwords. xBrowserSync for bookmarks.
Post reply on HN