Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

251–260 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#251

Earlier quoted context omitted.

I see a lot of people mentioning bitwarden around here; is their actually a technical reason to believe they are better than Lastpass or any of their competition (have they like open sourced all their stuff?). There’s very little room for failure and learning in the online password safe field, so I generally assume these companies are in one of two states: * has unknown bugs waiting to be revealed * out of business

> is their actually a technical reason to believe they are better than Lastpass or any of their competition (have they like open sourced all their stuff?). You can see their server and client code here: https://github.com/bitwarden I choose to use their clients unmodified, along with an instance of the server formerly known as "bitwarden_rs" running in my basement as the sync backend. https://github.com/dani-garcia/v…

Do you expose your server to the internet or is it ok to sync devices only when you’re at home? Is every device a replica, if you lose your server can you redeploy it from the data on your device?

Re: The situation at LastPass may be worse than they are letting on

#252
post #248

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

Quite obviously there isn't anything and the handle indicating a crypto hack it's as non-credible as anything can be but some folks on HN still fall for the crypto hype. This is your regular reminder that all crypto is scam , this is a simple mathematical fact.

[flagged]

Re: The situation at LastPass may be worse than they are letting on

#253
I have no conclusions on this but kind of like in court, not the best idea to investigate your own personal breach but I get there is little choice for OP.

In my experience "I didn't click on any suspicious link" and similar user denials are exactly why you don't ask them that during incident response, instead you get them to give you all their browsing/download history/content so you can verify that.

It could be cookie theft (physical 2fa can't stop that) or consent phishing if they use oauth for their main lastpass login. As soon as this was noticed, disk/memory images should be taken of all devices with lastpass ideally so they can be investigated. I don't know if the victim here uses laspass on their phone for example or by new apps they include new browser extensions or updates to existing apps (supply chain compromise).

Re: The situation at LastPass may be worse than they are letting on

#254
post #186

Earlier quoted context omitted.

I have and it's fantastic: https://apps.apple.com/us/app/pass-password-store/id12058205...

Maybe this is terrible logic but I would never trust an app that had 120 reviews and what appears to be a single person as the app owner with all my passwords.

[dead]

Re: The situation at LastPass may be worse than they are letting on

#256

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

Verified account, blue checkmark, must be legit!

Re: The situation at LastPass may be worse than they are letting on

#257

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

It seems like a reasonably well written anecdote by someone who has some idea what they're talking about. It could obviously be false, but the consequences if he's right are potentially serious for a lot of HN users who might use LastPass. The consequences if he's wrong are a little extra reputational damage for LastPass, but that seems like a worthwhile tradeoff here.

Not everything posted on HN has to be verified true. The decision calculus here seems strongly in favor of signal boosting it, so that people who need to can take defensive action, even if it turns out to be wrong.

Re: The situation at LastPass may be worse than they are letting on

#258
post #256

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

Verified account, blue checkmark, must be legit!

[deleted]

Re: The situation at LastPass may be worse than they are letting on

#259

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

If you prefer an article: https://www.engadget.com/the-lastpass-hack-was-worse-than-th...

Re: The situation at LastPass may be worse than they are letting on

#260
post #125

Earlier quoted context omitted.

They still require that your vault be hosted by them though. Terrible policy.

I had been a very happy customer for years before they started moving to that policy. It's what finally made me set up a vaultwarden instance and migrate all my stuff over. I didn't like the move to a subscription model, but I'd have sucked that up if I could've continued to bring my own sync.

My exact situation as well. I moved from 1P7 to Bitwarden, along with my entire company.
Post reply on HN