This vaguely reminds me of Rackspace's catastrophic failure a few weeks ago. Both companies were owned by private equity firms.
What’s in a PR statement: LastPass breach explained
251–260 of 292 posts
Re: What’s in a PR statement: LastPass breach explained
#252Shows the need for true multi factor. We should not have a bunch of virtual MFAs and passwords in one service even if said service make it convenient. Password managers should be held to a high standard but we should also never depend just on a password for protection of anything of value.
Maybe before I die multiple YubiKey support can be considered a standard. Even AWS doesn’t support it which is just unfathomable. They support one, so you can’t have a backup, so they may as well not have the feature.
https://aws.amazon.com/blogs/security/you-can-now-assign-mul...
Re: What’s in a PR statement: LastPass breach explained
#253A (perhaps) unconventional approach to password management, which I recommend to anyone. If you enjoy complexity, this is too simple for you. No one can steal something that's not written down Just like the Navajo code talkers in WW II had a system that was memorized, so even if the Japanese captured another Navajo and tortured him (which they did), he couldn't reveal the code. Have some hints to yourself, and store…
I forgot the other part of my reasoning: my hints only work for me. If I am incapacitated in a way that affects my password recall the hints won't mean shit to my family.
The big advantage is, the hints are only meaningful to you.
The big disadvantage is, the hints are only meaningful to you.
Re: What’s in a PR statement: LastPass breach explained
#254Earlier quoted context omitted.
> Developers shouldn't expect themselves to be able to do good design work Rude. People can learn to do multiple things without being pigeonholed, you know? > I see so many opportunities in FOSS lost to basic, unnecessary branding and usability oversights. It's FOSS. Feel free to contribute.
> It's FOSS. Feel free to contribute. My hours of dev contributions to FOSS projects over the decades are somewhere in the low 5 figure range. Despite having a formal art school design education, I never contribute as a designer because FOSS projects are usually openly hostile to design input, even by someone like me who can implement it themselves. > Rude. People can learn to do multiple things without being pigeonh…
Re: What’s in a PR statement: LastPass breach explained
#255It would be interesting to hear people’s life philosophy in this area. For me, lastpass always seemed like a bad idea as passwords are very important to me and giving someone else a copy of my passwords seems like a bad idea. Similarly, I don’t let any services know my bank passwords even if they super promise to protect them and not misuse them. Another similar seeming task that I can’t delegate is to read my bank s…
I would never put financial passwords in a cloud based password manager. Even if they do everything perfectly encryption-wise, no one can guarantee an attacker wouldn't alter the client-side code to leak your master password. Having said that, it is still useful for less important logins like this website for example, where it isn't a big deal if someone manages to use the account. However it is a huge privacy issue…
At this point any financial institution has 2FA, I think. That still leaves say credit cards, but they are exposed enough that you’re not exactly making it worse even with a terrible custodian like LastPass.
Re: What’s in a PR statement: LastPass breach explained
#256Earlier quoted context omitted.
Clicking on a 'phishing' link can't hurt, and it's not like this person's website is ever going to be presented to you in a sensitive context (e.g. "download/install software from this site"). You should trust that your browser is secure enough to render random webpages. Excuse the self-promotion, but I take it that you're also too wary to click on this link to read my blog: https://dangerous.link/virus.exe
Any URL on the web could host a browser exploit that requires no interaction beyond visiting, but if I had to guess which one were most likely to, I'd put phishing links up there. > You should trust that your browser is secure enough to render random webpages. I honestly don't. Is dangerous.link/virus.exe any more dangerous than nytimes.com? Probably not. However if some 0-day, no interaction browser exploit does exi…
If you read through stuff like the security updates for new iOS version it becomes clear that this does exist at all times. Usually most of them are likely not even not found by attackers before they're fixed, but you can never be sure. Every browser has innumerable undiscovered vulnerabilities that at any time could be discovered and exploited by an attacker. Discovering this is hard and they don't show up all that often, but you never know, even some random ad could pwn you.
Re: What’s in a PR statement: LastPass breach explained
#257Earlier quoted context omitted.
One of the great difficulty of tackling that problem is often FOSS projects are averse to design decisions like that made by someone relatively fresh to the project - even if the problem is incredibly obvious to the designers and not the core development team. You would have to spend a lot of time gaining trust to then be able to present an idea like switching domains. The duality of putting off design decisions unti…
As a professional designer who's spent more time in my life developing FOSS than designing, I generally see FOSS projects refusing to accept design input, period. I've thought a lot about why and I see two broad problems: First, developers have a different fundamental perspective on interfaces than most people. They view interfaces as a wrapper that you use to interact with the important part: the application. To reg…
You have the same problem when trying to show an early mockup to a paying client, they keep picking at things that aren't going to be that way in the final, so you wind up rarely involving them until you have a really solid draft ready. It's a tradeoff you actively make because you're getting paid to make those micro-decisions for them.
It's unfortunate because I feel FOSS could work wonderfully with design, so much of what makes design great also makes FOSS amazing, but the bridge just isn't there.
Re: What’s in a PR statement: LastPass breach explained
#258A (perhaps) unconventional approach to password management, which I recommend to anyone. If you enjoy complexity, this is too simple for you. No one can steal something that's not written down Just like the Navajo code talkers in WW II had a system that was memorized, so even if the Japanese captured another Navajo and tortured him (which they did), he couldn't reveal the code. Have some hints to yourself, and store…
I didn't write it down, so no one can steal it. Simple indeed, thanks!
Re: What’s in a PR statement: LastPass breach explained
#259Earlier quoted context omitted.
No idea what you're talking about. I manage LastPass for 200 not very tech savvy users and no one has any problems using it.
The login text input button overlay is often obscured by other elements with click triggers, in some cases making it unusable. Many sites don’t populate with the input button so you have to get the password using context menus. I’ve trained 3-4 non-technical users on LastPass and none of them found it intuitive or easy. I’ve managed it in a corporate environment for dozens of users who were younger and more tech savv…
Re: What’s in a PR statement: LastPass breach explained
#260Earlier quoted context omitted.
> It's FOSS. Feel free to contribute. My hours of dev contributions to FOSS projects over the decades are somewhere in the low 5 figure range. Despite having a formal art school design education, I never contribute as a designer because FOSS projects are usually openly hostile to design input, even by someone like me who can implement it themselves. > Rude. People can learn to do multiple things without being pigeonh…
If you believe that developers can't do design, then why do you think you can develop?
Suggesting that being a software developer doesn't also qualify you to be a designer seems to have really bothered you for some reason. I don't think saying so is any more controversial than saying automotive engineers aren't automatically car interior designers or that being a civil engineer doesn't automatically make you an architect. If you feel like you're a great designer, fantastic. Enjoy your broad skillset, as I enjoy mine. If you feel like my comment somehow challenged that, weird but sorry?