Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

301–310 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#301
post #256

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

Verified account, blue checkmark, must be legit!

Or the $8 one.

Re: The situation at LastPass may be worse than they are letting on

#302
post #76

This is quite interesting. A couple of weeks ago, I received an extortion phishing email, but it was directed to a secondary email address that hasn’t been previously compromised. It made it past Gmail’s spam and phishing filters into my inbox. Maybe a coincidence, but I guess every weird thing that happens is going to raise alarm bells. I was suspicious of the LastPass concept (storing passwords in a cloud app) when…

Same thing for me with sudden spam emails. But the receive address did not have the customization for me to track it, instead my first name. Not sure if lastpass related but maybe.

BTW one client of mine runs a heavy security operation and they use KeePass.

Re: The situation at LastPass may be worse than they are letting on

#303
post #36

Earlier quoted context omitted.

I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.

I definitely feel the opposing law works. When I see a project with a massive disclaimer about "this crypto is not audited, I'm a noob never deploy this anywhere" I'm likely to see better crypto than most of the commercial products I work with, including ones with sales people that talk about unbreakable crypto.

Humility is underrated.

Re: The situation at LastPass may be worse than they are letting on

#304

Earlier quoted context omitted.

This is less secure than using keepassxc, 1password, or another application with a 1st party well maintained browser extension. With keepassxc, 1password, or even chrome's password manager, if a phisher links you to "gmail.scammersite.info", even if it looks exactly like the real gmail login page, browser-integration will not fill in the password field. With pass, the default flow is to copy the password to your clip…

There is a really good browser extension for pass, called BrowserPass. It has auto fill with phishing protection. There is also a good Android app, called Android Password Store, which does the same for all of my apps. Both use GPG keys stored on my Yubikey.

how do you use yubikey with android?

Re: The situation at LastPass may be worse than they are letting on

#305

What I find concerning is PKDBF was used, even https://en.wikipedia.org/wiki/PBKDF2 quotes PKDBF1 and PKDBF2,and that is recommended to use PKDBF2. Is there any evidence to show that they indeed rolled their own encryption rather than use a de-facto standard AES algorithm? Or is there something that is missing.

PKDBF is just the password derivation function to better protect the vault against dictionary attacks. The vaults are still encrypted with AES-256.

Re: The situation at LastPass may be worse than they are letting on

#306
post #36
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.

No.

Security is the area where fast and fuzzy heuristics get you into problems.

Examine each option critically and reach independent conclusions.

Re: The situation at LastPass may be worse than they are letting on

#307
post #264

Earlier quoted context omitted.

>It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak. ehh. I store my passwords online but its on a file I encrypted offline with strong password (over 20+ characters) and key. I use keepass which is a locally encrypted and stored password manger, and I store the DB on Dropbox and download it to any o…

> I don't trust password wallet services ass they all seem to want to do the enryption server side with a reset-able password which really means they have the master password not you None of the popular password managers work this way.

1password for teams works exactly this way

so does the family pack

Re: The situation at LastPass may be worse than they are letting on

#308

This is ultimately a predictable outcome for any password manager that stores your credentials on someone else's server. Just like they say in crypto "not your keys, not your crypto" - it applies here too. Not your storage, not your passwords. KeePass on an airgapped box, or an encrypted hardware password manager with no network interfaces is best, though frankly, I'd even be more comfortable writing down passwords o…

though frankly, I'd even be more comfortable writing down passwords on paper (at home) than I would be storing them on someone else's server.

100% agreed. Physical access is not something than an attacker, especially one likely to be in an entirely different country or even continent, can easily achieve.

Re: The situation at LastPass may be worse than they are letting on

#310
post #275
post #270

Earlier quoted context omitted.

Why not? I have a security background. I see nothing wrong with that statement. Although what he actually said was: "Initially I imagined I was targeted by a 0day or rootkit" which actually does not make sense, because it implies he thinks those two things are fungible. He's obviously not a security expert, but he's also obviously not totally technically incompetent.

It's quite unlikely someone would risk burning a viable 0day without either going wide (and then we would've heard from a few more people) or going after a well outlined target that would be guaranteed to be worth more than the 0day itself.

The person in question is very wealthy. I know at one point his portfolio was 9 figures. That may have been at the peak of the bull market but I imagine path is still very rich. Is it worth a 0day, still not sure.
Post reply on HN