Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

221–230 of 246 posts

Re: LastPass notifies users of yet another data breach

#221
Why anyone would even consider using an online password manager is beyond me. Keepass works perfectly offline, and it's easy to sync. Just copy one file. I set up syncthing on my pc and phone and I basically just forget about it. For other places I have a particular subdomain (guid) where I serve the current copy of the file, gated by a password. The database itself is protected by both a password and a yubikey.

Re: LastPass notifies users of yet another data breach

#222
post #8
post #3

Using a password manager has 2 main tradeoffs and mistakes: 1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff. 2- Cat and mouse security: There's a class of security decisions that work because they are new and different…

"Password manager" used to mean a program that runs locally on your computer. At some point people started making it into a SaaS, because that's more profitable. I do think there are some cases where an online password manager makes sense, e.g. for businesses, but for individuals it's better to just stick with an offline password manager, at least for the high value accounts.

What if your drive crashes and you lose all your passwords? How do I reach my passwords from multiple devices and keep them synchronized securely?

Sure you can self-host all of it also, but people like to pay for not having to do that.

Re: LastPass notifies users of yet another data breach

#223
post #55

Earlier quoted context omitted.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness Would you be okay will a public dat…

> I, for one, still expect companies to keep my private data private.

better expect companies to never know your private data

Re: LastPass notifies users of yet another data breach

#224
post #83

Earlier quoted context omitted.

> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness Would you be okay will a public dat…

Yes, a public database like this would be acceptable. That way the info isn't paywalled behind some white pages site or similar. And then maybe I could even update my own info to be correct. Contact info is pretty much out there for most people already. Hell, I put it on my resume and send that out to many people and put it on public sites.

it is acceptable to you when you don't expect that someone will abuse this info. But someone will.

Re: LastPass notifies users of yet another data breach

#225

WTF is LastPasd doing, handing customer details to a market research company? Any such data should have been fully anonymized: no names, no specific addresses, etc.. For anyone looking for a recommendation: I use KeepassXC with Keepass2Android. Open source, with a local database that you can choose to sync (or not). I sync using Own cloud.

passwordstore.org also a nice alternative

Re: LastPass notifies users of yet another data breach

#226

Earlier quoted context omitted.

Password managers are entirely a UX problem waiting to be solved better. Every time I hit a UX bug with my password manager, I mutter that I could do fix that, and then know that mine would also be worse in so many ways just to reach parity. What I wish is there was a public bug tracker of UX issues/optimizations that I, and the rest of the world, could log ideas to. Password managers are such a good idea but they al…

Can you give me an example of a UX problem that you attribute to the password manager? That'd help me understand. I often hit problems with 1Password's autofill on particular websites, but by and large I blame the website. Few examples: * one website expects me to type the PIN then a Symantec VIP OTP token into a single field called "password". That's a (possibly deliberately) password manager-hostile design. I final…

These are tiny paper cuts that add up to pain, like the ones you mentioned that affect me/a tiny portion of the user base so they aren't worth fixing. Is the justification I'm sure that's being made. For example, if site auto detection that you're submitting a form fails that you laboriously have to add field elements in and if the editor is on a different workspace on mac you have to go to the application space/desktop than three finger swipe back to the browser space/desktop and then back to the application space/desktop and then back-and-forth to fill in four different security questions. Tiny stuff like that that really adds up, that make password manager usage go down.

Re: LastPass notifies users of yet another data breach

#227
post #21

Lots more companies affected. Some more listed below: >"Klue has not said how many of its hundreds of customers are affected. Several companies have come forward to confirm they had data stolen during the attack, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium." >Cybercrime group Icarus took credit for the breach, saying on its leak site that it will publish the s…

[dead]

Re: LastPass notifies users of yet another data breach

#228

Earlier quoted context omitted.

Can you give me an example of a UX problem that you attribute to the password manager? That'd help me understand. I often hit problems with 1Password's autofill on particular websites, but by and large I blame the website. Few examples: * one website expects me to type the PIN then a Symantec VIP OTP token into a single field called "password". That's a (possibly deliberately) password manager-hostile design. I final…

These are tiny paper cuts that add up to pain, like the ones you mentioned that affect me/a tiny portion of the user base so they aren't worth fixing. Is the justification I'm sure that's being made. For example, if site auto detection that you're submitting a form fails that you laboriously have to add field elements in and if the editor is on a different workspace on mac you have to go to the application space/desk…

I just hit one. Creating a new document in 1Password, the name of the document isn't preselected, so I have to hit delete to name it. Lots of little tiny shit like that.

Re: LastPass notifies users of yet another data breach

#230

WTF is LastPasd doing, handing customer details to a market research company? Any such data should have been fully anonymized: no names, no specific addresses, etc.. For anyone looking for a recommendation: I use KeepassXC with Keepass2Android. Open source, with a local database that you can choose to sync (or not). I sync using Own cloud.

passwordstore.org also a nice alternative

This is what I've been using for a long time now. It's probably too technical for most people, especially if you're talking about syncing across multiple devices, but that's not a problem for me.
Post reply on HN