If this was true, i feel like it would be a little strange for the attacker to use it to steal a small amount of crypto. Once its revealed how bad this is, there would probably be a small window before people change their passwords, i would assume attackers would either go for a big score before revealing this capability, or they would try to hit everything very quickly. Just hitting a tiny amount of crypto seems odd…
That tiny amount of crypto is going to be worth a fortune someday!
The situation at LastPass may be worse than they are letting on
231–240 of 436 posts
Re: The situation at LastPass may be worse than they are letting on
#232Earlier quoted context omitted.
I definitely feel the opposing law works. When I see a project with a massive disclaimer about "this crypto is not audited, I'm a noob never deploy this anywhere" I'm likely to see better crypto than most of the commercial products I work with, including ones with sales people that talk about unbreakable crypto.
And likewise “military grade encryption” usually means “win2k Visual Basic backend”
Military grade when we're talking about a screw is a little different. It means that the screw is made and QC'd to a very specific spec/standard.
My next question might be, "Where can I find you on the FedRamp approved list?". To which, I'm sure they'd respond that anything outside the algorithm is not military grade, which is what most attackers will exploit in the end.
Re: The situation at LastPass may be worse than they are letting on
#233Earlier quoted context omitted.
Additionally, 1Password makes the extra effort to never even send the URLs of your accounts to their servers. Even with their Watchtower service, which notifies you of breached accounts and websites that support 2-factor authentication, your passwords and website URLs are never sent to 1Password servers. https://support.1password.com/watchtower-privacy/
They still require that your vault be hosted by them though. Terrible policy.
For those of us that have been using it for long enough, we can still use the "classic" version stuck at v7, but it means being able to self host. no monthly SaaS fees.
Re: The situation at LastPass may be worse than they are letting on
#234Re: The situation at LastPass may be worse than they are letting on
#235Re: The situation at LastPass may be worse than they are letting on
#236Re: The situation at LastPass may be worse than they are letting on
#237this sort of thing is why I append the name of the website + a unique identifier + password, so that I don't have to bother changing my password during such nonsense, ugh.
Do this instead https://spectre.app/
Re: The situation at LastPass may be worse than they are letting on
#238Earlier quoted context omitted.
You want compensation for rotating your passwords even though there is no evidence other than this random twitter thread that any of them are comprised?
Given the extent of the breach, it's prudent at this point to assume all passwords have been compromised.
Re: The situation at LastPass may be worse than they are letting on
#239Earlier quoted context omitted.
I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.
How hard is it to store encrypted data that needs a locally held master key to decrypt? Pick any industry... You'd have to be willfully ignorant or outright corrupt to fail your core business promise, wouldn't you?
Re: The situation at LastPass may be worse than they are letting on
#240This is quite interesting. A couple of weeks ago, I received an extortion phishing email, but it was directed to a secondary email address that hasn’t been previously compromised. It made it past Gmail’s spam and phishing filters into my inbox. Maybe a coincidence, but I guess every weird thing that happens is going to raise alarm bells. I was suspicious of the LastPass concept (storing passwords in a cloud app) when…