Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

281–290 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#281

Earlier quoted context omitted.

Something to be aware of regarding safe deposit boxes: possession of the key does not automatically grant access to the box. The bank I use maintains a list of people I allow to access my box along with their physical signature. When I needed to access my box, I had to sign in with a pen, on paper and show my ID. They compared that signature with the one I gave when I first obtained the box. I was granted access if t…

To add to this: if someone is not on that access list but is instead listed in a will, my understanding is that the will has to go through probate before access to the box is granted. It's quite likely that people would want/need access to passwords before that.

It depends on the scenario. Which is why planning eventualities is so important. If I suddenly die, then my wife has knowledge and signatures on file necessary to keep going. Also a three ring binder book to look up since that is not the time to be making decisions. If both my wife and I die together, and our minor kids are the ones remaining than immediate password access is a good deal less important compared to the keeps being fed and housed and things being worked out. Of course the will will come into impact, guardianship, life insurance, social security survivors benefits, when they will live, where they will go to school. Winding down this business I have and other matters would be secondary.

I am not saying we do this right. I certain have to "sharpen the pencil right" but the point is this should not be an afterthought.

Re: What’s in a PR statement: LastPass breach explained

#282
post #29

Earlier quoted context omitted.

Have to plan ahead and have the keypass password in an envelope in the safe deposit box.

What else is in your self deposit box? I thought only rich people with gold and jewels and spies with fake passports and ready currency used safe deposit boxes.

They are really handy for storing backup hard drives too. Short of having your own armed guards and razor wire it is good physical security for free or cheap.

Re: What’s in a PR statement: LastPass breach explained

#283
post #146

Earlier quoted context omitted.

I still have my first 128MB thumb drive, bought in 2001 or so. Works fine. Holds a kdbx file fine :)

I'm not really sure how this anecdote is relevant. Are you denying that flash drives fail? Are you endorsing not having a backup plan? Just to offer a counter anecdote, I had a flash drive fail with my kdbx file on it and it was a monumental pain in the ass to recover from because I didn't have backups. Have backups. Especially for critical passwords that lock you out of everything. Flash drives do fail. Statistical…

I have backups, thank you. My kdbx is in my Nextcloud, synchronised across my 4 PCs and Mac and my phone. So I have 6 copies (one on Nextcloud, and one on each device) at any time. Then I have backups on secondary storage (like external drives).

I only have very low end flash drives (like the free ones you get at trade shows) fail on me. None of the decent ones I've bought (Kingston, generally) ever failed. I still have my various 4G, 8G, 16G, 32G drives I've bought along the years, all still work fine.

The only one that failed were used continuously plugged, or to write a lot (like recording audio), and very low-end with that.

Re: What’s in a PR statement: LastPass breach explained

#284
post #77
post #61

Earlier quoted context omitted.

Because there needs to be a baseline level of convenience in order to get less-technical people to even consider using a password manager at all. If the alternative is using the same handful of weak passwords for every site, the risk of your password manager suffering a security breach doesn't look so bad in comparison.

There is a pretty large gap between "cloud based password storage" and "using the same password for each site". 1Password for /years/ worked with a local vault (and no remote sign-in requirement), and had relatively simple syncing to iOS via wifi (no idea on other OSes, that's what I use). I've shared my password vault between these two places with no issues and it didn't need a cloud account and I wasn't re-using pa…

"Relatively simple" for you or me maybe; for my 70-year-old parent, not so much. The bar is high.

Re: What’s in a PR statement: LastPass breach explained

#285
post #92

Earlier quoted context omitted.

At least Bitwarden encrypts the whole vault as a blob. I don't bother self-hosting because I figure I know less about hosting a Bitwarden vault than they do so it's not much more secure. If I had a local server on my LAN I might consider it, because then at least I have a few firewalls between me and the internet. I've been a happy paying Bitwarden user for several years now, since just before the first "minor" Lastp…

Yeah, I’m definitely not trained in security like the password manager engineers are. But I keep wondering if being distributed offsets that risk. That is, I can spin up Bitwarden in my Unraid machine in like five minutes and behind a reverse proxy, nobody even knows it’s there to attack. Maybe I have some security vulnerability, but it seems significantly less likely to be tested than a centralized commercial servic…

Yea this is exactly where I am. I have an Unraid box at home, currently mostly using it as a NAS, Plex server and for some home automations.

I realize that "security through obscurity" is not a best practice but even if I trust SaaS Bitwarden to be more hardened than I will ever be, I can't help but think that any centralized password manager will have a target on their back so much larger than mine that it may even out.

The biggest risk I see with self-hosting is accidentally borking the whole thing and locking myself out of my vault. But I'll probably gain enough confidence to mitigate that somewhat soon.

Re: What’s in a PR statement: LastPass breach explained

#286

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

What's with "MacOS" vs "macOS" in the toggle features ?!?

Just a typo, my original work on this was to merge two forks of this, and that slipped through. I have pushed a fix now.

Re: What’s in a PR statement: LastPass breach explained

#287

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

Cool stupfh. Minor bug: I unchecked “CLI,” and still got this row: > CLI export includes attachments

Fixed: https://github.com/Soft-wa-re/password-manager-comparer/comm...

Re: What’s in a PR statement: LastPass breach explained

#288

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

you should add apple keychain

https://github.com/Soft-wa-re/password-manager-comparer/issu...

Re: What’s in a PR statement: LastPass breach explained

#289

Earlier quoted context omitted.

Taken in isolation they might have a ton of entropy, just not taken across leaked password databases.

If my password is hunter2#gmaildotcom for gmail what could my reddit password be? It doesn’t take many leaks to crack the formula.

Yes but is someone specifically looking at your passwords across all the accounts I'm trying to crack them or are they just taking the easy road and trying those same passwords and every other site. One requires a lot more effort than the other while still being relatively easy.

Generally people do not have specific attackers going after them they are going after broad spectrum attackers you don't have to be faster than the bear you just have to be faster than the other person running from the bear.

And yes I'm not saying that's actually secure I'm just pointing out a consideration. Also there are different classes of passwords out there email and password for marketing site I'm never going to use again but I'm forced to sign up for versus something that actually is protecting something I care about like my credit card or worse my financials.

Re: What’s in a PR statement: LastPass breach explained

#290
post #283

Earlier quoted context omitted.

I'm not really sure how this anecdote is relevant. Are you denying that flash drives fail? Are you endorsing not having a backup plan? Just to offer a counter anecdote, I had a flash drive fail with my kdbx file on it and it was a monumental pain in the ass to recover from because I didn't have backups. Have backups. Especially for critical passwords that lock you out of everything. Flash drives do fail. Statistical…

I have backups, thank you. My kdbx is in my Nextcloud, synchronised across my 4 PCs and Mac and my phone. So I have 6 copies (one on Nextcloud, and one on each device) at any time. Then I have backups on secondary storage (like external drives). I only have very low end flash drives (like the free ones you get at trade shows) fail on me. None of the decent ones I've bought (Kingston, generally) ever failed. I still h…

The one I had fail was a kingston data traveller, so YMMV. https://www.amazon.com/Kingston-Digital-128GB-Traveler-DTSE9...

It likely failed due to the nature of its transit (in my pocket, with my keys) but that's kinda the point. I think it's worth pointing out to those who haven't really investigated your "always plugged in" is the known failure of flash drives. Flash storage does has a fairly well documented write/erase cycles in the realm of like 10k-100k cycles. While the data should still be readable, its pretty easy for bad controllers and bad filesystems (most flash drives use fat32 which is a bad filesystem) to fail a write and corrupt data.

I think the main issue I have with a "do it yourself because you can't trust the cloud" mentality is that this advice usually comes from people who have done their homework as you have. It'd be dangerous to apply "just do x" advice without those conditions as it's a bit more nuanced and it can really put people in bad situations. I've seen this same thing with people who use a NAS over cloud storage and then it fails and they discover just what the monthly cost of cloud storage actually paid for. It'd be like telling home owners "just don't have a fire" and instead of paying for insurance, but not talking about the money you set aside and fire mitigation systems you invested in.

Post reply on HN