Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

221–230 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#221

Earlier quoted context omitted.

I think the whole LastPass fiasco just shows why everyone wants to get into the SaaS business so bad - subscription revenue is the gift that keeps on giving. LastPass has proven they have no business safekeeping anyone else's credentials. Anyone who cares a modicum about their security will have migrated off. But migrating off is a HUGE pain (people will need hours to update hundreds of passwords), and LastPass's ann…

> But migrating off is a HUGE pain It took less than 10mn to migrate to Bitwarden. What do you mean by migrate?

If you have an business account, migration is non-trivial: It's not uncommon to have hundreds of shared folders of secrets accessible by hundreds of teams.

The meta information (which user account belongs to which team, which team has what kind of access {none,read-only,read-write} to which folder) is not trivial to migrate.

Re: What’s in a PR statement: LastPass breach explained

#222
post #89

Earlier quoted context omitted.

Then you're stuck with Chrome forever. Same with Firefox or Safari. I wish browser vendors would agree on one password sharing protocol that's just some end-to-end encrypted blob that you could download from any browser and unlock with your password. You login to your Firefox or Google account, add passwords, and if you want to use those from the other browser you just get some http link that points to the encrypted…

You can export your passwords as a CSV file and import to other browsers (obviously if one chooses to do this, they should delete this file securely after it's been imported). Firefox, Chrome, and Edge also allow you to import passwords between browsers natively. I'm not saying that I recommend relying on the browser-based password manager (personally I use KeePassX), but I wouldn't advise against it for the reason y…

Adding to this helpful comment:

Firefox doesn’t allow you to import a CSV in its default config. You need to enable it (it’s straightforward) and there is a guide here: https://support.mozilla.org/en-US/questions/1328161

Then you can import to eg Safari to have it all in iCloud Keychain.

Re: What’s in a PR statement: LastPass breach explained

#223

Earlier quoted context omitted.

That's useless if you're migrating away because of security concerns. What you actually have to do is to go to all of the sites and change each of the passwords you have stored in LastPass.

As someone else - you should be doing this even if you're staying on lastpass. It's what I've spent the last few days doing (hundreds of passwords), but then again, I'm also moving to bitwarden.

True, though I think this is a good practice in general if switching your password manager, even for benign reasons (price etc).

Re: What’s in a PR statement: LastPass breach explained

#224
post #19

Earlier quoted context omitted.

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

Excuse me if this seems impolite, but is there a reason you need his passwords? Financial institutions have a very regulated pipeline for access of deceased accounts to relatives. And for personal email and stuff, well I think that should remain private unless the deceased explicitly wanted to share.

One of my parents neighbors died suddenly of Covid. She ran a small business as a vacation planner. Her husband did not have her email password. This was a huge pain and a source of stress when he was arranging the funeral because he was unable to inform people who expected her to be managing their upcoming vacation that she died. Sometimes timely access is valuable.

Re: What’s in a PR statement: LastPass breach explained

#225

Earlier quoted context omitted.

I'm admittedly a hammer seeing everything as a nail, but as a designer, I see so many opportunities in FOSS lost to basic, unnecessary branding and usability oversights. Developers shouldn't expect themselves to be able to do good design work any more than designers should expect themselves to be able to make scalable, reliable, maintainable, production-ready code. It's a specialty for a reason! Incorporating designe…

One of the great difficulty of tackling that problem is often FOSS projects are averse to design decisions like that made by someone relatively fresh to the project - even if the problem is incredibly obvious to the designers and not the core development team. You would have to spend a lot of time gaining trust to then be able to present an idea like switching domains. The duality of putting off design decisions unti…

As a professional designer who's spent more time in my life developing FOSS than designing, I generally see FOSS projects refusing to accept design input, period. I've thought a lot about why and I see two broad problems:

First, developers have a different fundamental perspective on interfaces than most people. They view interfaces as a wrapper that you use to interact with the important part: the application. To regular users, the interface is the application. I can't tell you how many times I've seen things like customizable color themes or ill-conceived typeface changes be the primary product of a developer-initiated "UX review," largely because they didn't know how to identify actual usability problems and wouldn't know how to craft solutions even if they did. If it persists long enough, maintainers don't just see their interfaces and user paths as flawed but good enough: they assume the mitigation techniques they've developed to work around a bad interface are best practices.

Second, art school freshmen subconsciously trying to prove their competence to themselves give the harshest and least useful critique and often take constructive critique as a personal affront. That phenomenon seems generalizable: critique about things we're less confident in makes us feel more insecure than critique of things we're more confident in. If someone proposed replacing a core piece of the architecture with something different, they'd be confident enough to look at it and rationally decide if it's beneficial. Conversely, when developers see redesign proposals about interfaces they were never confident in to begin with, they get defensive, and design proposals get dismissed or bikeshedded to complete buggery.

I think these two things imbue the FOSS development world with indifference to, or even distrust of designers. You only need to briefly look at threads on HN focused on design or interface to see the open disdain many developers have for designers. "Ruined by designers" is a pretty common refrain. Despite our unicorn reputations, I know lots of designers/developers, and every one that I can recall at the moment contribute to FOSS... just never as designers because the process is so irritating. Myself included. It's just not worth the amount of work that goes into a competent design proposal, noting that I would implement it personally, only to have it summarily dismissed by people with false confidence in their analysis.

Re: What’s in a PR statement: LastPass breach explained

#226
post #75

Earlier quoted context omitted.

Oh, I'm sure Vaultwarden is much more resource-friendly, but even then: a user's password list is arguably the most important thing on the device. And I'm not sure you need a "web interface" to something that in the end is nothing more than an encrypted text file, which is why I always recommend pass[0] or using the browser's built-in pw manager for people that don't know ssh and git. [0] passwordstore.org

For whatever it's worth, I think people should be a little careful about using Pass. From their website: > With pass, each password lives inside of a gpg encrypted file whose filename is the title of the website or resource that requires the password. This is the exact problem that LastPass just got hit with (okay, one of multiple problems) -- the vault doesn't encrypt the URLs of the sites you visit. Pass is really…

Yep, I agree, valid criticism. There are things like git-crypt, pass-tomb etc, but those can get messy real fast.

However, git repo != GitHub. Putting the repo on a home server in the LAN has served me well over the years

Re: What’s in a PR statement: LastPass breach explained

#227
post #19
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

Fair question, but since it's not a service, I don't see how that is KeePass' responsibility. But, It's really just a simple as making sure your dependents have a copy of your master password. If I remember correctly, the native Windows version has a step to print of a sheet to share with family members when you create a new database (I could be wrong, it's been a while). Either way it would be trivial to type up a word document to print off. If you use a key file as well, it a little more complicated. Depends on if you're assuming folks have access to your machine or not. As someone else suggested, a thumb drive could be a good solution. Whatever you choose they need to have a copy of the DB file, master pass, and key file and you're good :)

Re: What’s in a PR statement: LastPass breach explained

#228

Earlier quoted context omitted.

That sounds like a huge anti-feature to me. The few services that a next-of-kin should realistically need access to (banking and... that's pretty much it) will already have a process in place for handling this. The rest of my accounts should die when I do.

All of our family pictures and videos are in a place that only I have the password to. If anyone wants anything, they come to me. That is another password I would want passed on. I also pay all the bills. My wife would need access to all of the utility accounts, the mortgage payment account, the credit card accounts, the insurance accounts, the retirement fund accounts, etc. There is way more than just banking.

But those are things that are worth solving _now_, not just once you die.

Re: What’s in a PR statement: LastPass breach explained

#229

Earlier quoted context omitted.

I'm admittedly a hammer seeing everything as a nail, but as a designer, I see so many opportunities in FOSS lost to basic, unnecessary branding and usability oversights. Developers shouldn't expect themselves to be able to do good design work any more than designers should expect themselves to be able to make scalable, reliable, maintainable, production-ready code. It's a specialty for a reason! Incorporating designe…

> Developers shouldn't expect themselves to be able to do good design work Rude. People can learn to do multiple things without being pigeonholed, you know? > I see so many opportunities in FOSS lost to basic, unnecessary branding and usability oversights. It's FOSS. Feel free to contribute.

> It's FOSS. Feel free to contribute.

My hours of dev contributions to FOSS projects over the decades are somewhere in the low 5 figure range. Despite having a formal art school design education, I never contribute as a designer because FOSS projects are usually openly hostile to design input, even by someone like me who can implement it themselves.

> Rude. People can learn to do multiple things without being pigeonholed, you know?

Pigeonholing by not expecting specialists to be competent outside of their specialty? I have considerable professional experience as both a designer and a developer in the past decade-and-a-half, and a couple of other completely unrelated careers in the decade before prior. You're fishing for things to be offended by, and probably misjudging the amount of design understanding required for actual competence.

Re: What’s in a PR statement: LastPass breach explained

#230
post #161

Earlier quoted context omitted.

I initially assumed I would be safe because of 2FA. Sadly it looks like this is not the case, the second factor is used to access the encrypted data, not decrypt the data. As the attacker already has the encrypted data, they have bypassed the stage where 2FA is providing protection. This appears to also be the case for 1password and bitwarden, so not specifically a lastpass failure.

> This appears to also be the case for 1password and bitwarden, so not specifically a lastpass failure. It is currently(?) the case for Bitwarden, yes, but that's incorrect for 1Password, as they have client-only key material that is never transmitted to the cloud: https://blog.1password.com/what-the-secret-key-does/

Yes, a secret key like this could have made this breach much less concerning. Assuming you trust the company to not also lose this data (that they generate and claim to not store). What I was really hoping to find was a paid, cross platform, cloud sync'ed solution that can be setup to require your password and physical key to decrypt. i.e. have 2FA protection from a data breach like this.
Post reply on HN