Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

231–240 of 246 posts

Re: LastPass notifies users of yet another data breach

#231

Earlier quoted context omitted.

> I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. > With something like LastPass it's also much easier to create unique strong passwords for other sites. Sure, but LastPass, in addition to being the least secure option, doesn't even have a good user interface, and it's expensive. There are dozens of other pass…

Doing the research takes time and energy. Switching takes time and energy. Changing all your passwords after you switch so they aren't potentially exposed in the next LastPass break takes time and energy. People have a lot of things going on and have to make a decision about whether the risk justifies the effort. Then there's feature gaps. LastPass is available on all platforms, has convenient sharing, a good story f…

Security Best Practices change all the time. Failing to implement MFA because "it takes time and energy" and "besides we implemented 12 character, complex passwords years ago" will not be valid excuses for government regulators when they come knocking.

Re: LastPass notifies users of yet another data breach

#232

Earlier quoted context omitted.

Can you give me an example of a UX problem that you attribute to the password manager? That'd help me understand. I often hit problems with 1Password's autofill on particular websites, but by and large I blame the website. Few examples: * one website expects me to type the PIN then a Symantec VIP OTP token into a single field called "password". That's a (possibly deliberately) password manager-hostile design. I final…

These are tiny paper cuts that add up to pain, like the ones you mentioned that affect me/a tiny portion of the user base so they aren't worth fixing. Is the justification I'm sure that's being made. For example, if site auto detection that you're submitting a form fails that you laboriously have to add field elements in and if the editor is on a different workspace on mac you have to go to the application space/desk…

> These are tiny paper cuts that add up to pain, like the ones you mentioned that affect me/a tiny portion of the user base so they aren't worth fixing. Is the justification I'm sure that's being made.

I think it's not only that but also that making site-specific changes (as I did with a TamperMonkey script) is fragile and could get them into trouble if their changes do the wrong thing (immediately for everyone, for some users, or after some site change). Might be better from their perspective to honor the site's stated intent even if that intent is questionable. In my top example, the "password" field actually is a password if the user hasn't enabled 2FA, so the changes I made wouldn't work for 1Password to apply to everyone. They could detect the label "PIN + Token" to gate it, but what if that text changes in a redesign or is sometimes localized into another language? and so on.

In the broadest sense, I agree there are big UX problems, but how much should we expect the password manager to do unilaterally? fwiw even when a bunch of players got together to make broader changes, we ended up with passkeys, which are far from perfect in many ways. (The flows about scanning a QR code from one device to another, without necessarily even knowing which device has a working passkey for that site... the simultaneous confusing offers of different ways of signing in... try talking your vision-impaired father through that over the phone.)

> if the editor is on a different workspace on mac you have to go to the application space/desktop than three finger swipe back to the browser space/desktop and then back to the application space/desktop and then back-and-forth to fill in four different security questions.

Yeah, that sounds similar to my own complaint about quick access opening on the wrong Space, just applied to the main window instead. And of course when you have to use the security questions something else has gone really wrong, like the main password having changed on the site without having changed in your password manager.

* One way I've seen this is when people have overlapped usage in two different password managers (1Password vs either Google Passwords or Apple Passwords). They have import and export (except for passkeys), but it'd be nice if they had an incremental version to help you get out of this mess if you weren't disciplined in switching over all at once.

* Another is that when you change the site's password even while using the password manager, the actual site change and recording it in the password manager's database is hardly transactional. You can click the password manager's update pop-up even if it failed, or not notice it even if it succeeded. Again not really sure how they would address this unilaterally.

> I just hit one. Creating a new document in 1Password, the name of the document isn't preselected, so I have to hit delete to name it. Lots of little tiny shit like that.

Yeah, that's 100% on them.

Re: LastPass notifies users of yet another data breach

#235

Earlier quoted context omitted.

1Password checks all these boxes and hasn't yet had a data breach. Their biggest security hole is probably somewhere in the operational pipeline between 1P browser client developers and the static file servers hosting them.

Unfortunately it's one of the most bug-ridden and unreliable pieces of software I've ever used. I encounter issues with it on a daily basis, but the burden of switching and a lack of superior options keeps me locked in.

Used it for years and never encountered a single bug, and I'm quite a power user with hundreds of items stored in it, shared vaults, and access multiple times per day. It's one of the few softwares I happily pay for. Maybe it differs from platform to platform, otherwise I can't explain your comment.

Re: LastPass notifies users of yet another data breach

#236

Earlier quoted context omitted.

These are tiny paper cuts that add up to pain, like the ones you mentioned that affect me/a tiny portion of the user base so they aren't worth fixing. Is the justification I'm sure that's being made. For example, if site auto detection that you're submitting a form fails that you laboriously have to add field elements in and if the editor is on a different workspace on mac you have to go to the application space/desk…

> These are tiny paper cuts that add up to pain, like the ones you mentioned that affect me/a tiny portion of the user base so they aren't worth fixing. Is the justification I'm sure that's being made. I think it's not only that but also that making site-specific changes (as I did with a TamperMonkey script) is fragile and could get them into trouble if their changes do the wrong thing (immediately for everyone, for…

I can't expect them to serve every website on the Internet, but a button on 1Password that was in the context menu for the extension that was "report this site is not working 100% perfectly", and they had a team to come in and check up on the site and extract way to improve their software.

I remember another stupid annoyance. There was one site where passwords were limited to eight characters but the way they password manager entered the passwords. It passed more than the characters along as the password so the password would fail if it auto filled, but if I copy and pasted or typed it manually it would work because the JavaScript had a chance to truncate. The fact that this site was limited to eight character passwords all other conversation, but that was super annoying until I figured it out.

Anyway. I have a love/hate relationship with my password manager.

Re: LastPass notifies users of yet another data breach

#238
post #111

I've been an Enpass user for years because I got a lifetime purchase for a good deal. They don't host the cloud services for syncing passwords. Instead you just auth your cloud storage (I use Google Drive) and it syncs to that. This approach seems better to me. For one thing, I'd already be screwed if someone malicious got into my Google account, probably worse than if they got into my password manager. And additiona…

> No one's gonna hack Enpass of all their passwords because that would require hacking all of Google Drive, Dropbox, iCloud, etc. and looking for the files manually.

Or they compromise their self-update system if that exists.

Re: LastPass notifies users of yet another data breach

#239

Earlier quoted context omitted.

1Password checks all these boxes and hasn't yet had a data breach. Their biggest security hole is probably somewhere in the operational pipeline between 1P browser client developers and the static file servers hosting them.

Unfortunately it's one of the most bug-ridden and unreliable pieces of software I've ever used. I encounter issues with it on a daily basis, but the burden of switching and a lack of superior options keeps me locked in.

It was a fantastic, fast, reliable piece of software until they sold out for VC funding and went the Electron rebuild route.

I was a paying customer for 15 years and migrated away with the last price increases due to "AI-powered functionalities" and the new features making the product worse on top of already being salty over when they stopped the one-time licenses in favor of subscription.

Re: LastPass notifies users of yet another data breach

#240

Earlier quoted context omitted.

Any example bugs that you've encountered in the last week?

Their flow for regaining access after somehow "disauthorised" laptop, she there's an installed but unused for months plugin is one of the most infuriating. It won't ask me for my secret key, which I have an can provide immediately, no, it won't allow me to authenticate myself with the phone, because our enterprise vault logs off quickly, I must however do a some absurdly obscure dance because FY, that's why.

Ugh, the enterprise authentication is dumb
Post reply on HN