Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

41–50 of 326 posts

Re: LastPass users warned their master passwords are compromised

#41

Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

Ah yes, the $5 wrench method.

Also known as the "So you think you can escape the FBI [/CIA/FSB]?" fallacy.

Re: LastPass users warned their master passwords are compromised

#42
post #7

> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after c…

Just tried deleting my account--got exactly that error. That's not reassuring

Re: LastPass users warned their master passwords are compromised

#43

Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

Ah yes, the $5 wrench method.

I mean, if your threat model is such that you need to consider kidnapping and being hit with a wrench, as opposed to just a drive by breach, then you should in fact account for that appropriately.

Re: LastPass users warned their master passwords are compromised

#44
post #26

Earlier quoted context omitted.

You can add multiple keys to the account.

So is the recommendation to get something like 3 keys and keep them in different safe places and bring one when you travel? I’ve been considering getting a Yubikey. Do they work on mobile? Edit: Looks like some Yubikey work via nfc for mobile.

Yes, you should always have at least two and keep one in a reasonably fire resistant safe. You may want to enroll multiple and keep them in other places too, but you can't enroll a key you don't have so things like a safe deposit box are not useful for the average case.

Re: LastPass users warned their master passwords are compromised

#45
I jumped ship from LastPass when they changed their subscription model so that I'd be paying for features that had previously been free. I'm now using Bitwarden for personal use and 1Password for work and I'm a fan.

I previously tried offline password managers but syncing the files between devices and such was a huge pain.

Re: LastPass users warned their master passwords are compromised

#47
This has to be a security issue with LastPass, right? Something like an as-yet unidentified usage of Log4j.

> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed.

This sounds to me like either a widely-compromised browser extension (LP itself?) or LP infrastructure.

Re: LastPass users warned their master passwords are compromised

#48
Several years ago, I chose LastPass, bought it, and did all the set up. Then they were acquired by someone I didn't trust, so I immediately switched to 1Password, and never regretted it for a second. If 1Password sold out, I'd switch again, in a second.

Re: LastPass users warned their master passwords are compromised

#49

This is framed so negatively toward LastPass, which is unfortunate. They stopped all usage of correct passwords they believed were compromised, which is exactly what I'd want them to do in this situation. Them warning users their master passwords are compromised is a good thing! Yet it's framed as though they're admitting to something. "However, users receiving these warnings have stated that their passwords are uniq…

LastPass has had enough other security issues that I am doubtful of them to this day.

https://www.mcafee.com/blogs/enterprise/cloud-security/lastp...

Unfortunately the only password solutions I would recommend at this point are 1Password for something turn key, and BitWarden if you want to self host.

Re: LastPass users warned their master passwords are compromised

#50

Earlier quoted context omitted.

So is the recommendation to get something like 3 keys and keep them in different safe places and bring one when you travel? I’ve been considering getting a Yubikey. Do they work on mobile? Edit: Looks like some Yubikey work via nfc for mobile.

Yes, you should always have at least two and keep one in a reasonably fire resistant safe. You may want to enroll multiple and keep them in other places too, but you can't enroll a key you don't have so things like a safe deposit box are not useful for the average case.

I guess try to follow 3-2-1 backups as closely as possible:

3 copies of your 2-factor, 2 different mediums (a Yubikey and recovery tokens printed on paper), at least 1 in a different location (safety deposit box, trusted family members house, etc).

Post reply on HN