Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

231–240 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#231
post #49

If this was true, i feel like it would be a little strange for the attacker to use it to steal a small amount of crypto. Once its revealed how bad this is, there would probably be a small window before people change their passwords, i would assume attackers would either go for a big score before revealing this capability, or they would try to hit everything very quickly. Just hitting a tiny amount of crypto seems odd…

That tiny amount of crypto is going to be worth a fortune someday!

Unfortunately or fortunately, that day is in the past.

Re: The situation at LastPass may be worse than they are letting on

#232
post #190

Earlier quoted context omitted.

I definitely feel the opposing law works. When I see a project with a massive disclaimer about "this crypto is not audited, I'm a noob never deploy this anywhere" I'm likely to see better crypto than most of the commercial products I work with, including ones with sales people that talk about unbreakable crypto.

And likewise “military grade encryption” usually means “win2k Visual Basic backend”

That's a silly term for that. Commercial businesses have the same access to NIST that the military does. Their guidance is even free!

Military grade when we're talking about a screw is a little different. It means that the screw is made and QC'd to a very specific spec/standard.

My next question might be, "Where can I find you on the FedRamp approved list?". To which, I'm sure they'd respond that anything outside the algorithm is not military grade, which is what most attackers will exploit in the end.

Re: The situation at LastPass may be worse than they are letting on

#233
post #125

Earlier quoted context omitted.

Additionally, 1Password makes the extra effort to never even send the URLs of your accounts to their servers. Even with their Watchtower service, which notifies you of breached accounts and websites that support 2-factor authentication, your passwords and website URLs are never sent to 1Password servers. https://support.1password.com/watchtower-privacy/

They still require that your vault be hosted by them though. Terrible policy.

*for some.

For those of us that have been using it for long enough, we can still use the "classic" version stuck at v7, but it means being able to self host. no monthly SaaS fees.

Re: The situation at LastPass may be worse than they are letting on

#237
post #51

this sort of thing is why I append the name of the website + a unique identifier + password, so that I don't have to bother changing my password during such nonsense, ugh.

Do this instead https://spectre.app/

What do you when a generated password doesn't meet a web site's requirements (on length, character classes etc)?

Re: The situation at LastPass may be worse than they are letting on

#238

Earlier quoted context omitted.

You want compensation for rotating your passwords even though there is no evidence other than this random twitter thread that any of them are comprised?

Given the extent of the breach, it's prudent at this point to assume all passwords have been compromised.

Why is that so? Aren't the passwords encrypted?

Re: The situation at LastPass may be worse than they are letting on

#239
post #36

Earlier quoted context omitted.

I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.

How hard is it to store encrypted data that needs a locally held master key to decrypt? Pick any industry... You'd have to be willfully ignorant or outright corrupt to fail your core business promise, wouldn't you?

The average user that LastPass caters to thinks that a "backup" is the reason they were late for work in the morning. LastPass doesn't want to be in a position where they're telling their users, "Sorry you're SOL," if their device breaks and they don't have a second copy of their locally-stored encryption key.

Re: The situation at LastPass may be worse than they are letting on

#240
post #76

This is quite interesting. A couple of weeks ago, I received an extortion phishing email, but it was directed to a secondary email address that hasn’t been previously compromised. It made it past Gmail’s spam and phishing filters into my inbox. Maybe a coincidence, but I guess every weird thing that happens is going to raise alarm bells. I was suspicious of the LastPass concept (storing passwords in a cloud app) when…

Strike 2? This is strike 3 of the final out of the 9th inning. AKA game over.
Post reply on HN