Earlier quoted context omitted.
When it comes to password management, trust should not even be a thing. https://www.lesspass.com/
I may be wrong, the idea is interesting but looks more like a password generator and a terrible password manager to me. You still need to store somewhere informations like url, username, counter, etc. right ? Can you change the master password without changing all your accounts password ? If one happens to find your master password, he's basically able to get/generate all your passwords just like a normal pw manager…
The situation at LastPass may be worse than they are letting on
371–380 of 436 posts
Re: The situation at LastPass may be worse than they are letting on
#372Earlier quoted context omitted.
It seems like a reasonably well written anecdote by someone who has some idea what they're talking about. It could obviously be false, but the consequences if he's right are potentially serious for a lot of HN users who might use LastPass. The consequences if he's wrong are a little extra reputational damage for LastPass, but that seems like a worthwhile tradeoff here. Not everything posted on HN has to be verified t…
It's like a novice programmer blaming the compiler for a bug in their application. It's very unlikely to be true. What would you have the people who are using LastPass do, stop using it? Because some crypto dude stored their highly valuable keys in a system that literally copies their keys to any system they log into, to systems that are notorious for having very leaky abstractions and vast vulnerability surfaces?
Yes. After their last major breach I exported all my data and deleted all my credentials and account with LastPass. Seeing the details of this breach, I'm super happy I did.
Re: The situation at LastPass may be worse than they are letting on
#373Earlier quoted context omitted.
> someone who has some idea what they're talking about "I suspected someone used a 0day on me" is not exactly inspiring confidence
Why not? I have a security background. I see nothing wrong with that statement. Although what he actually said was: "Initially I imagined I was targeted by a 0day or rootkit" which actually does not make sense, because it implies he thinks those two things are fungible. He's obviously not a security expert, but he's also obviously not totally technically incompetent.
Also the people talking about “burning zero days”… every time you use an exploit (ignoring the exact meaning of 0 days) it doesn’t become burned by the first person. The hacker could use it on hundreds of people before it’s discovered and patched by whatever software it targets. That could take months.
Re: The situation at LastPass may be worse than they are letting on
#374Earlier quoted context omitted.
It's like a novice programmer blaming the compiler for a bug in their application. It's very unlikely to be true. What would you have the people who are using LastPass do, stop using it? Because some crypto dude stored their highly valuable keys in a system that literally copies their keys to any system they log into, to systems that are notorious for having very leaky abstractions and vast vulnerability surfaces?
> What would you have the people who are using LastPass do, stop using it? Yes. After their last major breach I exported all my data and deleted all my credentials and account with LastPass. Seeing the details of this breach, I'm super happy I did.
Re: The situation at LastPass may be worse than they are letting on
#375Re: The situation at LastPass may be worse than they are letting on
#376Re: The situation at LastPass may be worse than they are letting on
#377And when I say that I will stop using 1password when the local vault no longer works, people look at me like I'm paranoid and crazy. I've looked at the white paper https://1passwordstatic.com/files/security/1password-white-p... , I think 1password has a decent security posture for their cloud offering but then there's always the risk of a breach where the attacker controls the site and can intercept your master passw…
Re: The situation at LastPass may be worse than they are letting on
#378So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…
I would wait until more stories like this pop up before jumping to conclusions.
So feel free to go ahead and jump to conclusions :)
Re: The situation at LastPass may be worse than they are letting on
#379Earlier quoted context omitted.
Quick tip: if you have Bitwarden's browser extension installed, you can use Cmd + Shift + 9 (I'm assuming it's Ctrl + Shift + 9 for Windows) to load your clipboard with a randomly generated password: h4!E49vFcGEE%c#$HZ%z*3^5B
Thanks! Would you mind generating a few more for me, though?
&^Q@w7rC#F!%V%swarZ4@pss#
4nKR7ReAG^ghezg%yD6CF79b!
aH8MPi5NoKv4Hzdfec7Q*c4XT
hwD!LktbF5&Wxy^wh^Uq7%&%^
CYQ9%5^vXAiz&4fPp%fWfa%rq
Re: The situation at LastPass may be worse than they are letting on
#380Too many people who should know better on this site itself kept recommending things like Lastpass... Incredible.