Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

241–250 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#241
A lot of people argue that a cloud provider has more expertise in a given domain than a customer for whom IT isn't a core competency. I reject this argument. What we have here is the classic principal-agent problem in economics. Your data is (or should be) sacred to you. LastPass's regard for your data is only proportional to the profit they think they can extract from you. Beyond that, they only answer to Citrix's shareholders. (Citrix, or Shitrix as I call them, is ultimately the parent company.)

I swim against the prevailing current in believing that the cloud should only serve as a backup, never as the primary solution.

Re: What’s in a PR statement: LastPass breach explained

#242
post #159

Earlier quoted context omitted.

That's literally the option though if you've managed to convince someone to use a password manager. I convinced a family member and their response to the breach was "okay, who should I use instead? Or do I go back to using one password for everything?"

"okay, who should I use instead? Or do I go back to using one password for everything?" Given that the "using one password for everything" is such a terrible idea that we can discount as probably worse than storing your passwords in a cloud-based vault then you land on what your family member has given you as the other option "what should I use instead". Ultimately if* there are no password managers available that wi…

I'm not concerned for me, I'm concerned with what less sophisticated people are willing to put up with.

Our options are convenience of device sync or one password.

Or some other mechanism, because I have been told in no uncertain terms that's as far as it goes.

I can't even convince this family member to rotate their passwords. What makes you think they'll be willing to put up with more inconvenience?

Again, the problem is the unsophisticated user who only has so much brain space for this shit.

Re: What’s in a PR statement: LastPass breach explained

#243

Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality. not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastP…

You're not being vindictive. If anything, you're being overly gracious.

Re: What’s in a PR statement: LastPass breach explained

#244

A (perhaps) unconventional approach to password management, which I recommend to anyone. If you enjoy complexity, this is too simple for you. No one can steal something that's not written down Just like the Navajo code talkers in WW II had a system that was memorized, so even if the Japanese captured another Navajo and tortured him (which they did), he couldn't reveal the code. Have some hints to yourself, and store…

This used to be my main approach, but now I only use it for some key sites and rely on a password manager for the other 90%. Why the change? Watching the mental deterioration of aging on friends and family, and noting the beginnings of such things in myself. My mind is so much slower than it used to be, including recall. It's not only aging. A friend had a concussion from a lousy picture frame falling off the wall. It wasn't even that big or heavy. 3 years later still slowly rebuilding mental and language function.

Re: What’s in a PR statement: LastPass breach explained

#245

Earlier quoted context omitted.

One of the great difficulty of tackling that problem is often FOSS projects are averse to design decisions like that made by someone relatively fresh to the project - even if the problem is incredibly obvious to the designers and not the core development team. You would have to spend a lot of time gaining trust to then be able to present an idea like switching domains. The duality of putting off design decisions unti…

As a professional designer who's spent more time in my life developing FOSS than designing, I generally see FOSS projects refusing to accept design input, period. I've thought a lot about why and I see two broad problems: First, developers have a different fundamental perspective on interfaces than most people. They view interfaces as a wrapper that you use to interact with the important part: the application. To reg…

Let me respond as a developer with admittedly no taste at all, who both committed and fixed plenty of atrocities:

Just like security, design is one of these things where snake oil salesmen are everywhere, to the point that finding a good one without becoming a designer yourself is hard. I also notice you identify as an artist, not a psychologist, which seems the wrong approach to me.

So what will happen if I let designers loose on my program? They might have real insight and improve things a lot. Or maybe they'll go all artsy and put lipstick on the pig, leaving me with an even worse program in lovely pastels? Or maybe they'll dumb down an interface in an attempt to create a granny-safe rocket launch pad, leaving the actual rocket engineers frustrated? Or they'll just move stuff around for the sake of moving stuff around, creating a lot of busywork and forcing user retraining without any upside. I've seen all these things happen.

So what is your advise to this dev? How do I get designers that actually improve the design?

Re: What’s in a PR statement: LastPass breach explained

#246

A (perhaps) unconventional approach to password management, which I recommend to anyone. If you enjoy complexity, this is too simple for you. No one can steal something that's not written down Just like the Navajo code talkers in WW II had a system that was memorized, so even if the Japanese captured another Navajo and tortured him (which they did), he couldn't reveal the code. Have some hints to yourself, and store…

I forgot the other part of my reasoning: my hints only work for me. If I am incapacitated in a way that affects my password recall the hints won't mean shit to my family.

Re: What’s in a PR statement: LastPass breach explained

#247

Earlier quoted context omitted.

Two questions: 1) How's it do at syncing / conflicts? 2) In the Android app, do you know if there's a way to use the fingerprint feature without storing your master password or an encrypted derivative of it to non-volatile memory? For those scratching their heads at #2, it's motivated by my lukewarm trust of vendor-implemented components of Android Keystore. Some competing apps address it by making you authenticate w…

Which apps handle this better? I'm not supremely concerned about my password being pulled from memory, from an attack surface perspective, but I am curious which apps address this best and how.

Not saying it's the best out there (and the UI is a little clunky as it often flashes a pin input screen that gets skipped over when using your fingerprint), but I like how Keypass2Android can be configured to do it. When you select "Enable Biometric Unlock for Quick Unlock" (and don't disable the PIN feature) you can use your fingerprint as long as the app is still in memory, without it storing your master password.

I know the Android Lastpass client would often prompt for a Master Password if it hadn't been used in a while, then let Fingerprints unlock it. I assumed it did something similar but haven't deep-dived the implementation.

Re: What’s in a PR statement: LastPass breach explained

#248
post #19

Earlier quoted context omitted.

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

That sounds like a huge anti-feature to me. The few services that a next-of-kin should realistically need access to (banking and... that's pretty much it) will already have a process in place for handling this. The rest of my accounts should die when I do.

I used to think that, but then reality struck.

For the financial companies, the process varied greatly by company. Some were OK, others were terrible, some flat out didn't work. The bottom line is that this isn't a super common business flow for them and its not something they make money on, so it gets very little attention. When you actually need to go through it you realize its a very difficult process.

Oh and it always takes a LONG time, even with the better companies. Easily months to get everything fully done.

Re: What’s in a PR statement: LastPass breach explained

#249
post #19

Earlier quoted context omitted.

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

Excuse me if this seems impolite, but is there a reason you need his passwords? Financial institutions have a very regulated pipeline for access of deceased accounts to relatives. And for personal email and stuff, well I think that should remain private unless the deceased explicitly wanted to share.

Transferring financial accounts I found out to be a very difficult and time consuming process. In some cases it was just flat out not possible even though I had everything I needed. I was shocked by how bad it was.

Other things were also required. E.g. my father had a small business. It was big enough that it had real income and we wanted to keep it going, but not big enough that there was tons of redundancy for this type of event. Without having his passwords the business would have ground to a halt in 2 weeks (payroll). Add to that all sorts of business accounts (domains, mail, accounting, etc, etc) and having this emergency access turned out to be the key to keeping things going.

Even his personal email - he would have wanted us to have access, but how does he give access without just giving us his PW? Turned out that emergency access was the perfect solution.

Re: What’s in a PR statement: LastPass breach explained

#250
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

I always struggled to find a decent Keepass implementation for my friend who uses Macs. Any recommendations?

KeePassXC is excellent on macOS: https://keepassxc.org/download/#mac
Post reply on HN