I swim against the prevailing current in believing that the cloud should only serve as a backup, never as the primary solution.
What’s in a PR statement: LastPass breach explained
241–250 of 292 posts
Re: What’s in a PR statement: LastPass breach explained
#242Earlier quoted context omitted.
That's literally the option though if you've managed to convince someone to use a password manager. I convinced a family member and their response to the breach was "okay, who should I use instead? Or do I go back to using one password for everything?"
"okay, who should I use instead? Or do I go back to using one password for everything?" Given that the "using one password for everything" is such a terrible idea that we can discount as probably worse than storing your passwords in a cloud-based vault then you land on what your family member has given you as the other option "what should I use instead". Ultimately if* there are no password managers available that wi…
Our options are convenience of device sync or one password.
Or some other mechanism, because I have been told in no uncertain terms that's as far as it goes.
I can't even convince this family member to rotate their passwords. What makes you think they'll be willing to put up with more inconvenience?
Again, the problem is the unsophisticated user who only has so much brain space for this shit.
Re: What’s in a PR statement: LastPass breach explained
#243Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality. not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastP…
Re: What’s in a PR statement: LastPass breach explained
#244A (perhaps) unconventional approach to password management, which I recommend to anyone. If you enjoy complexity, this is too simple for you. No one can steal something that's not written down Just like the Navajo code talkers in WW II had a system that was memorized, so even if the Japanese captured another Navajo and tortured him (which they did), he couldn't reveal the code. Have some hints to yourself, and store…
Re: What’s in a PR statement: LastPass breach explained
#245Earlier quoted context omitted.
One of the great difficulty of tackling that problem is often FOSS projects are averse to design decisions like that made by someone relatively fresh to the project - even if the problem is incredibly obvious to the designers and not the core development team. You would have to spend a lot of time gaining trust to then be able to present an idea like switching domains. The duality of putting off design decisions unti…
As a professional designer who's spent more time in my life developing FOSS than designing, I generally see FOSS projects refusing to accept design input, period. I've thought a lot about why and I see two broad problems: First, developers have a different fundamental perspective on interfaces than most people. They view interfaces as a wrapper that you use to interact with the important part: the application. To reg…
Just like security, design is one of these things where snake oil salesmen are everywhere, to the point that finding a good one without becoming a designer yourself is hard. I also notice you identify as an artist, not a psychologist, which seems the wrong approach to me.
So what will happen if I let designers loose on my program? They might have real insight and improve things a lot. Or maybe they'll go all artsy and put lipstick on the pig, leaving me with an even worse program in lovely pastels? Or maybe they'll dumb down an interface in an attempt to create a granny-safe rocket launch pad, leaving the actual rocket engineers frustrated? Or they'll just move stuff around for the sake of moving stuff around, creating a lot of busywork and forcing user retraining without any upside. I've seen all these things happen.
So what is your advise to this dev? How do I get designers that actually improve the design?
Re: What’s in a PR statement: LastPass breach explained
#246A (perhaps) unconventional approach to password management, which I recommend to anyone. If you enjoy complexity, this is too simple for you. No one can steal something that's not written down Just like the Navajo code talkers in WW II had a system that was memorized, so even if the Japanese captured another Navajo and tortured him (which they did), he couldn't reveal the code. Have some hints to yourself, and store…
Re: What’s in a PR statement: LastPass breach explained
#247Earlier quoted context omitted.
Two questions: 1) How's it do at syncing / conflicts? 2) In the Android app, do you know if there's a way to use the fingerprint feature without storing your master password or an encrypted derivative of it to non-volatile memory? For those scratching their heads at #2, it's motivated by my lukewarm trust of vendor-implemented components of Android Keystore. Some competing apps address it by making you authenticate w…
Which apps handle this better? I'm not supremely concerned about my password being pulled from memory, from an attack surface perspective, but I am curious which apps address this best and how.
I know the Android Lastpass client would often prompt for a Master Password if it hadn't been used in a while, then let Fingerprints unlock it. I assumed it did something similar but haven't deep-dived the implementation.
Re: What’s in a PR statement: LastPass breach explained
#248Earlier quoted context omitted.
Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…
That sounds like a huge anti-feature to me. The few services that a next-of-kin should realistically need access to (banking and... that's pretty much it) will already have a process in place for handling this. The rest of my accounts should die when I do.
For the financial companies, the process varied greatly by company. Some were OK, others were terrible, some flat out didn't work. The bottom line is that this isn't a super common business flow for them and its not something they make money on, so it gets very little attention. When you actually need to go through it you realize its a very difficult process.
Oh and it always takes a LONG time, even with the better companies. Easily months to get everything fully done.
Re: What’s in a PR statement: LastPass breach explained
#249Earlier quoted context omitted.
Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…
Excuse me if this seems impolite, but is there a reason you need his passwords? Financial institutions have a very regulated pipeline for access of deceased accounts to relatives. And for personal email and stuff, well I think that should remain private unless the deceased explicitly wanted to share.
Other things were also required. E.g. my father had a small business. It was big enough that it had real income and we wanted to keep it going, but not big enough that there was tons of redundancy for this type of event. Without having his passwords the business would have ground to a halt in 2 weeks (payroll). Add to that all sorts of business accounts (domains, mail, accounting, etc, etc) and having this emergency access turned out to be the key to keeping things going.
Even his personal email - he would have wanted us to have access, but how does he give access without just giving us his PW? Turned out that emergency access was the perfect solution.
Re: What’s in a PR statement: LastPass breach explained
#250I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…
I always struggled to find a decent Keepass implementation for my friend who uses Macs. Any recommendations?