Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

371–380 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#371
post #219

Earlier quoted context omitted.

When it comes to password management, trust should not even be a thing. https://www.lesspass.com/

I may be wrong, the idea is interesting but looks more like a password generator and a terrible password manager to me. You still need to store somewhere informations like url, username, counter, etc. right ? Can you change the master password without changing all your accounts password ? If one happens to find your master password, he's basically able to get/generate all your passwords just like a normal pw manager…

You have it right. This master password derived passwords idea is nothing new. Few people actually use it because it's not actually a great idea for the reasons you listed.

Re: The situation at LastPass may be worse than they are letting on

#372
post #283
post #257

Earlier quoted context omitted.

It seems like a reasonably well written anecdote by someone who has some idea what they're talking about. It could obviously be false, but the consequences if he's right are potentially serious for a lot of HN users who might use LastPass. The consequences if he's wrong are a little extra reputational damage for LastPass, but that seems like a worthwhile tradeoff here. Not everything posted on HN has to be verified t…

It's like a novice programmer blaming the compiler for a bug in their application. It's very unlikely to be true. What would you have the people who are using LastPass do, stop using it? Because some crypto dude stored their highly valuable keys in a system that literally copies their keys to any system they log into, to systems that are notorious for having very leaky abstractions and vast vulnerability surfaces?

> What would you have the people who are using LastPass do, stop using it?

Yes. After their last major breach I exported all my data and deleted all my credentials and account with LastPass. Seeing the details of this breach, I'm super happy I did.

Re: The situation at LastPass may be worse than they are letting on

#373
post #270
post #265

Earlier quoted context omitted.

> someone who has some idea what they're talking about "I suspected someone used a 0day on me" is not exactly inspiring confidence

Why not? I have a security background. I see nothing wrong with that statement. Although what he actually said was: "Initially I imagined I was targeted by a 0day or rootkit" which actually does not make sense, because it implies he thinks those two things are fungible. He's obviously not a security expert, but he's also obviously not totally technically incompetent.

To explain your comment a bit: It should be 0 day AND a rootkit, not OR. Plus the rootkit is not always needed or possible.

Also the people talking about “burning zero days”… every time you use an exploit (ignoring the exact meaning of 0 days) it doesn’t become burned by the first person. The hacker could use it on hundreds of people before it’s discovered and patched by whatever software it targets. That could take months.

Re: The situation at LastPass may be worse than they are letting on

#374
post #372
post #283

Earlier quoted context omitted.

It's like a novice programmer blaming the compiler for a bug in their application. It's very unlikely to be true. What would you have the people who are using LastPass do, stop using it? Because some crypto dude stored their highly valuable keys in a system that literally copies their keys to any system they log into, to systems that are notorious for having very leaky abstractions and vast vulnerability surfaces?

> What would you have the people who are using LastPass do, stop using it? Yes. After their last major breach I exported all my data and deleted all my credentials and account with LastPass. Seeing the details of this breach, I'm super happy I did.

I eh.. was not up to date, I blame our office Christmas party. I guess I'm moving our organization over next year..

Re: The situation at LastPass may be worse than they are letting on

#376

Earlier quoted context omitted.

Nitpick: "weary" == "tired", "wary" == cautious

I can read the sentence with both versions and it still makes sense…

It should be “weary of” not “weary about”

Re: The situation at LastPass may be worse than they are letting on

#377

And when I say that I will stop using 1password when the local vault no longer works, people look at me like I'm paranoid and crazy. I've looked at the white paper https://1passwordstatic.com/files/security/1password-white-p... , I think 1password has a decent security posture for their cloud offering but then there's always the risk of a breach where the attacker controls the site and can intercept your master passw…

Or controls one of the many apps. Every time I install the Firefox extension I wonder if I’m really able to be sure that I haven’t been directed to a compromised version or lookalike.

Re: The situation at LastPass may be worse than they are letting on

#378

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

I would wait until more stories like this pop up before jumping to conclusions.

This is one of those “more stories like this” - this isn’t the first LastPass breach by any measure.

So feel free to go ahead and jump to conclusions :)

Re: The situation at LastPass may be worse than they are letting on

#379
post #229

Earlier quoted context omitted.

Quick tip: if you have Bitwarden's browser extension installed, you can use Cmd + Shift + 9 (I'm assuming it's Ctrl + Shift + 9 for Windows) to load your clipboard with a randomly generated password: h4!E49vFcGEE%c#$HZ%z*3^5B

Thanks! Would you mind generating a few more for me, though?

Merry Christmas!

&^Q@w7rC#F!%V%swarZ4@pss#

4nKR7ReAG^ghezg%yD6CF79b!

aH8MPi5NoKv4Hzdfec7Q*c4XT

hwD!LktbF5&Wxy^wh^Uq7%&%^

CYQ9%5^vXAiz&4fPp%fWfa%rq

Re: The situation at LastPass may be worse than they are letting on

#380
hah. For years I've been telling people I know to NEVER trust all their security to one-password services. Given so many tech companies penchant for playing stupid and loose with internal security without customers even being aware of it, this kind of thing was bound to happen. All the worse to trust a password vault service under the circumstances.

Too many people who should know better on this site itself kept recommending things like Lastpass... Incredible.

Post reply on HN