Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

311–320 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#311
post #36

Earlier quoted context omitted.

I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.

I definitely feel the opposing law works. When I see a project with a massive disclaimer about "this crypto is not audited, I'm a noob never deploy this anywhere" I'm likely to see better crypto than most of the commercial products I work with, including ones with sales people that talk about unbreakable crypto.

> When I see a project with a massive disclaimer about "this crypto is not audited, I'm a noob never deploy this anywhere" I'm likely to see better crypto than most of the commercial products I work with, including ones with sales people that talk about unbreakable crypto.

I'm working on an opensource project for Linux users that needs crypto. Needless to say, I'm not an expert in that domain. I was planning to ask experts for help in reviewing the crypto. Your statement makes me slightly nervous. What is the standard procedure to ensure crypto safety in a software project?

Re: The situation at LastPass may be worse than they are letting on

#312

Earlier quoted context omitted.

How hard is it to store encrypted data that needs a locally held master key to decrypt? Pick any industry... You'd have to be willfully ignorant or outright corrupt to fail your core business promise, wouldn't you?

The average user that LastPass caters to thinks that a "backup" is the reason they were late for work in the morning. LastPass doesn't want to be in a position where they're telling their users, "Sorry you're SOL," if their device breaks and they don't have a second copy of their locally-stored encryption key.

[edit] I guess that's true. I'm not sure who their users are, but obviously not people overly concerned about security. [/edit]

Just because I think it's funny - every time I visit my dad (who's in his 80s) he regales me with his startup ideas. "Why don't you build something that I can put on my glasses so when I lose them I can find them? Whoever invents that would be a billionaire." I say, "Yeah dad, they have that."

"Why don't they make it so I don't have to remember passwords for all these different websites? I could just have one password and it would remember it for everything."

I think I've explained at least a dozen times why I think third party trust is a bad idea; I've had to really refine it down to the level of explaining this to a six year old.

But the salient point here is that even my dad never signed up for LastPass. So who the fuck is signing up for LastPass?

Re: The situation at LastPass may be worse than they are letting on

#313

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

This. Why would we be critical of LastPass being secretive and/or wrong and then take a tweet at face value? From one of the tweets: > I did not download anything. My machines are clean, and I have physical 2fa on everything. None of the links or contracts I interacted with were malicious. Nobody else had physical access to my PC. Yeah sure. Sounds like my aunt when she messed up her PC and loudly claims "but I didn'…

> Why would we be critical of LastPass being secretive and/or wrong and then take a tweet at face value?

One entity has something to lose, the other doesn't?

Re: The situation at LastPass may be worse than they are letting on

#314

Earlier quoted context omitted.

This. Why would we be critical of LastPass being secretive and/or wrong and then take a tweet at face value? From one of the tweets: > I did not download anything. My machines are clean, and I have physical 2fa on everything. None of the links or contracts I interacted with were malicious. Nobody else had physical access to my PC. Yeah sure. Sounds like my aunt when she messed up her PC and loudly claims "but I didn'…

> Why would we be critical of LastPass being secretive and/or wrong and then take a tweet at face value? One entity has something to lose, the other doesn't?

That exactly what flat earthers claim.

1. You don't know if this person has nothing to lose

2. Even if they have nothing to lose that doesn't mean they are being honest.

Re: The situation at LastPass may be worse than they are letting on

#315

Earlier quoted context omitted.

This is less secure than using keepassxc, 1password, or another application with a 1st party well maintained browser extension. With keepassxc, 1password, or even chrome's password manager, if a phisher links you to "gmail.scammersite.info", even if it looks exactly like the real gmail login page, browser-integration will not fill in the password field. With pass, the default flow is to copy the password to your clip…

There is a really good browser extension for pass, called BrowserPass. It has auto fill with phishing protection. There is also a good Android app, called Android Password Store, which does the same for all of my apps. Both use GPG keys stored on my Yubikey.

I wrote a little tool to sync my passwords on pass with Firefox passwords which enables that (differently).

https://github.com/NilsIrl/pass-fxa/

Re: The situation at LastPass may be worse than they are letting on

#316
post #264

Earlier quoted context omitted.

> I don't trust password wallet services ass they all seem to want to do the enryption server side with a reset-able password which really means they have the master password not you None of the popular password managers work this way.

1password for teams works exactly this way so does the family pack

So you’re saying 1Password for families / teams differs significantly from their zero knowledge architecture?

Have a look at [0] - recovery works without 1Password having the master password.

[0] https://1passwordstatic.com/files/security/1password-white-p...

Re: The situation at LastPass may be worse than they are letting on

#317
post #257

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

It seems like a reasonably well written anecdote by someone who has some idea what they're talking about. It could obviously be false, but the consequences if he's right are potentially serious for a lot of HN users who might use LastPass. The consequences if he's wrong are a little extra reputational damage for LastPass, but that seems like a worthwhile tradeoff here. Not everything posted on HN has to be verified t…

"Well written"

That's subjective and has no value in determining whether the post is true.

"Not everything posted on HN has to be verified true. The decision calculus here seems strongly in favor of signal boosting it, so that people who need to can take defensive action, even if it turns out to be wrong."

What? Proven true, no, any sort of evidence, yes. As for taking actions, there's a cost.

Re: The situation at LastPass may be worse than they are letting on

#318

Earlier quoted context omitted.

https://en.m.wikipedia.org/wiki/List_of_password_managers As far as I can tell BitWarden and Google are the two good ones. I use BitWarden. My reasoning is anything new and experimental is scary, I want something with tons of users that's well established. If the community isn't all over it, it's probably not reviewed enough. Open source makes stuff a little more trustworthy, but by itself isn't enough. I also don't…

What do you mean by Google? I looked at the Wikipedia article, but didn’t see Google listed.

They're not listed, but Chrome and Android can manage passwords

Re: The situation at LastPass may be worse than they are letting on

#319
post #292

Earlier quoted context omitted.

That is way too much work. Doing work means stuff is happening and stuff means sidechannel attacks that someone else hasn't audited, because it's not an integrated product anyone would bother auditing. In particular, I don't see how 2FA is possible with this, so shoulder surfing is a bigger issue. I definitely trust Google or BitWarden more than a password I can memorize plus my own constant vigilance.

> In particular, I don't see how 2FA is possible with this Umm, why not? First, you can use a different app (like aegis) to generate OTPs. Second, pass has an extension ( https://github.com/tadfisher/pass-otp ) that can be used to generate OTPs. Third, you can use something like oathtool to generate your otp using your totp secret oathtool -b --totp "your-totp-secret"

I'm not quite sure I understand this. It seems like a way to generate OTPs, but it doesn't solve requiring a second factor to access the vault.

Re: The situation at LastPass may be worse than they are letting on

#320
post #203

Earlier quoted context omitted.

That is way too much work. Doing work means stuff is happening and stuff means sidechannel attacks that someone else hasn't audited, because it's not an integrated product anyone would bother auditing. In particular, I don't see how 2FA is possible with this, so shoulder surfing is a bigger issue. I definitely trust Google or BitWarden more than a password I can memorize plus my own constant vigilance.

> In particular, I don't see how 2FA is possible with this You can use anything that integrates with GPG ... eg: you can do it with a Yubikey [0] [0] https://support.yubico.com/hc/en-us/articles/360013790259-Us...

Ah, I stand corrected, I forgot about trusted hardware based 2FA.

Still, it doesn't allow SMS or email based 2FA as far as I can tell, since that involves a trusted server and doesn't mean anything in a trustless model where the server owner could just add a bypass.

Post reply on HN