Live data from Hacker News

Feds Link Cyberheist to 2022 LastPass Hacks

krebsonsecurity.com

261–266 of 266 posts

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#261

Earlier quoted context omitted.

I don’t have amazon or steam so don’t know how any of that works. But for a password manager, family sharing is extremely useful. Bitwarden doesn’t have families per se, it’s got “organisations”. You can setup unlimited number of organisations and users can get invited and join them. Which is very handy for example my wife and I can login and order our groceries from the supermarket using the same account. Or that we…

I have nothing against sharing per se. My issue is with the family nomenclature. In your case it might align perfectly, but for myself and most people I know, it's not the case. That is, the set of people to share a Netflix subscription with, share Steam library with, share Kindle library with, share passwords to various web services, including utility companies, are only partially overlapping, and do not align perfe…

This seems pedantic. I am trying to wrap my head around why "family sharing" is an issue here. You want to share with someone, use family sharing I don't see what the issue is.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#263

Earlier quoted context omitted.

> Bitwarden truly doesn’t get enough credit for being completely open source It’s their No. 1 selling point. > In 50 years time, who knows if any of these companies will be around 1Password has local clients. If you have the password, you should be able to unlock the vault locally.

Since I’m talking about reliable long term archival of critical encrypted data here, let me again ask: in your opinion, what is the likelihood that in 50 years time, with 1Password long gone, my grand children would be able to run that local 1Password client and successfully decrypt the data? Because I feel pretty confident that gpg will still be around (though hopefully long deprecated), that gzipped files would sti…

I'd be extremely surprised if any of those creds are still valid in 50 years, assuming you don't use 1Password to store other assorted information.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#265
post #72

Earlier quoted context omitted.

is that not enough? It's also inexpensive and works very well on all platforms.

Their comment made me laugh, agreed, open source is really is that big of a perk. IMO especially for something security-related (though 0day is always possible)

I think the assumption something is open source being a perk is naïve - in the end I still have to trust so many elements that actually bring me the platform that BW’s openness doesnt matter.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#266

Earlier quoted context omitted.

I have been using 1Password for the last several years and am quite happy with them, except for the fact that they basically forced users to use their cloud offering with subscription as opposed to free iCloud storage after 1Password version 7.

Highly recommend Strongbox. The underlying DBs are KeePass DBs and can be stored anywhere as well as opened with any KeePass client, with a UI even better than 1Password (you can have columns for every field) as well as passkey support + export/import (even before the official method came out because they believe in you owning your own data). I love it because Strongbox also has its own cloud feature (optional) that…

Note that they’ve been acquired by Applause…
Post reply on HN