Wouldn't have happened with Bitwarden ;)
LastPass: Notice of Security Incident
31–40 of 141 posts
Re: LastPass: Notice of Security Incident
#32For all of its warts, at least crypto has managed to come up with a clever little motto that correctly states the issue, in the form of "not your keys, not your crypto." Putting your passwords in the hands of a third party drastically increases your threat surface and no amount of hand-wavy "but it's not as convenient" will change this fact. Now, it may be true that the convenience factor is very strong right now, bu…
I find the saying very trite, but it's self evidently true - the cloud is just someone else's computer.
I literally have this posted on my office door at the university where I teach.
Re: LastPass: Notice of Security Incident
#33For all of its warts, at least crypto has managed to come up with a clever little motto that correctly states the issue, in the form of "not your keys, not your crypto." Putting your passwords in the hands of a third party drastically increases your threat surface and no amount of hand-wavy "but it's not as convenient" will change this fact. Now, it may be true that the convenience factor is very strong right now, bu…
Even on this point I have to disagree because that's precisely what 2FA is for. Even if LastPass (or Bitwarden in my case) stole my vault's password and posted my credentials on pastebin, no one could log into any of my 2FA protected accounts. (Ironically this account on HN is one of the few that doesn't support 2FA. Oh no my internet points!)
"not your keys, not your coins" may apply in the cutthroat 2FA-less decentralized world of cryptocurrencies, but most of the rest of the world has much more nuanced threat models.
Re: LastPass: Notice of Security Incident
#34Earlier quoted context omitted.
You've picked a strange subset of 'most' for the people you're imagining. They are savy enough to know what a password manager is, but not savy enough to deal with an offline one. Are you sure its not just a few people like you?
> They are savy enough to know what a password manager is, but not savy enough to deal with an offline one. Not the person you responded to, but: I think that most people are savvy enough to know what a password manager is, and most people are not savvy enough to be interested in the work necessary to setup, personalize, and maintaining an offline password manager that functions well across multiple devices. That doe…
Re: LastPass: Notice of Security Incident
#35Earlier quoted context omitted.
My problem is that as an unskilled person - will I be any better at securing my own system?
No, but there are easy-to-use, reliable and secure solutions, such as Bitwarden.
Re: LastPass: Notice of Security Incident
#36Suppose that LastPass is compromised. What can an attacker do? Passwords are encrypted, with keys on users’ side. Short of serving customers malicious JS code or an app to steal passwords, the production environment referred in the article can be made totally public, without secrets in vaults bring revealed, no?
Re: LastPass: Notice of Security Incident
#37Re: LastPass: Notice of Security Incident
#38Earlier quoted context omitted.
Yeah, again: all of this is great for you, but it doesn't change the fact that you are a very, very niche case. You can't just dismiss cloud syncing of passwords because you are the edge case who doesn't need it. > I keep a password database on the company network with all my work passwords and I have no need to keep a copy of those credentials on a bunch of my personal devices or cloud servers. That doesn't work for…
You've picked a strange subset of 'most' for the people you're imagining. They are savy enough to know what a password manager is, but not savy enough to deal with an offline one. Are you sure its not just a few people like you?
Re: LastPass: Notice of Security Incident
#39All your data is kept separate from the company, and if you depart you just need to add a credit card.
Re: LastPass: Notice of Security Incident
#40Huge huge potential loss here for people until they affirm this didn't happen.