Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

31–40 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#31
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

I wonder what 1password does

1password’s security design whitepaper can be found here:

https://1passwordstatic.com/files/security/1password-white-p...

It’s quite good.

Re: The situation at LastPass may be worse than they are letting on

#32

Earlier quoted context omitted.

Append it where?

e.g. password to facebook would be: facebook.com$293MyPasswordYouKnowIt!!123 password to gmail would be mail.google.com$113MyPasswordYouKnowIt!!123 only annoying thing is that the passwords are long. I guess it's secure, though. edit: see child post for clarification. I do something above for spammy sites, but for something like gmail I probably wouldn't do that.

How do you remember the unique identifier?

Re: The situation at LastPass may be worse than they are letting on

#33
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

I wonder what 1password does

Wonder no more: https://blog.1password.com/what-we-dont-know-about-you/

Re: The situation at LastPass may be worse than they are letting on

#34

Earlier quoted context omitted.

e.g. password to facebook would be: facebook.com$293MyPasswordYouKnowIt!!123 password to gmail would be mail.google.com$113MyPasswordYouKnowIt!!123 only annoying thing is that the passwords are long. I guess it's secure, though. edit: see child post for clarification. I do something above for spammy sites, but for something like gmail I probably wouldn't do that.

How do you remember the unique identifier?

it's deterministic, but obviously I can't tell you the secret ;)

that being said there are a lot of things you could use. you could use information in the whois, you could use the birthdate of the founder of the site, etc.

personally I believe people should use the same password for all sites and then something similar to what I described. though I use a password manager, I do always feel nervous about the implementation leaking out details

Re: The situation at LastPass may be worse than they are letting on

#35

Reminder that in 2015 LastPass was acquired by LogMeIn, who then in 2021 announced it was spinning off back into its own thing, though whether that has happened yet is unclear. If you look into what LogMeIn (now renamed to “GoTo”) makes… this doesn’t make me feel good about GoToMeetings, GoToMyPC, or join.me.

That's an interesting take, because for many of us, prior knowledge about the insecurity of GoTo products (not so branded then) were evidence that the security of LastPass was at risk.

Re: The situation at LastPass may be worse than they are letting on

#36
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable.

It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.

Re: The situation at LastPass may be worse than they are letting on

#37

Earlier quoted context omitted.

I wonder what 1password does

1password’s security design whitepaper can be found here: https://1passwordstatic.com/files/security/1password-white-p... It’s quite good.

Thanks! They seem to encrypt everything too.

Items contain overviews and details which are encrypted separately by the vault key. We encrypt these separate so that we can quickly decrypt the information needed to list, sort, and find items without having to first decrypt everything in the vault.

Item overviews include the item fields needed to list items and to quickly match items to websites, such as Title, URLs, password strength indicator, and tags.

Re: The situation at LastPass may be worse than they are letting on

#38

If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?

Why would you store your private key on a cloud storage service? This is what hard wallets are for.

Re: The situation at LastPass may be worse than they are letting on

#39

Earlier quoted context omitted.

Append it where?

e.g. password to facebook would be: facebook.com$293MyPasswordYouKnowIt!!123 password to gmail would be mail.google.com$113MyPasswordYouKnowIt!!123 only annoying thing is that the passwords are long. I guess it's secure, though. edit: see child post for clarification. I do something above for spammy sites, but for something like gmail I probably wouldn't do that.

That’s not secure at all.

Eventually, some website you use is going to get hacked. They’ll have stored passwords as plaintext. From there, anyone who wants to hack any of your accounts knows your password format. It’s going to be obvious to them that they just need to replace the domain.

Post reply on HN