Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.
Ah yes, the $5 wrench method.
LastPass users warned their master passwords are compromised
41–50 of 326 posts
Re: LastPass users warned their master passwords are compromised
#42> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after c…
Re: LastPass users warned their master passwords are compromised
#43Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.
Ah yes, the $5 wrench method.
Re: LastPass users warned their master passwords are compromised
#44Earlier quoted context omitted.
You can add multiple keys to the account.
So is the recommendation to get something like 3 keys and keep them in different safe places and bring one when you travel? I’ve been considering getting a Yubikey. Do they work on mobile? Edit: Looks like some Yubikey work via nfc for mobile.
Re: LastPass users warned their master passwords are compromised
#45I previously tried offline password managers but syncing the files between devices and such was a huge pain.
Re: LastPass users warned their master passwords are compromised
#46Let this be your Last non-selfhosted Pass solution.
Re: LastPass users warned their master passwords are compromised
#47> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed.
This sounds to me like either a widely-compromised browser extension (LP itself?) or LP infrastructure.
Re: LastPass users warned their master passwords are compromised
#48Re: LastPass users warned their master passwords are compromised
#49This is framed so negatively toward LastPass, which is unfortunate. They stopped all usage of correct passwords they believed were compromised, which is exactly what I'd want them to do in this situation. Them warning users their master passwords are compromised is a good thing! Yet it's framed as though they're admitting to something. "However, users receiving these warnings have stated that their passwords are uniq…
https://www.mcafee.com/blogs/enterprise/cloud-security/lastp...
Unfortunately the only password solutions I would recommend at this point are 1Password for something turn key, and BitWarden if you want to self host.
Re: LastPass users warned their master passwords are compromised
#50Earlier quoted context omitted.
So is the recommendation to get something like 3 keys and keep them in different safe places and bring one when you travel? I’ve been considering getting a Yubikey. Do they work on mobile? Edit: Looks like some Yubikey work via nfc for mobile.
Yes, you should always have at least two and keep one in a reasonably fire resistant safe. You may want to enroll multiple and keep them in other places too, but you can't enroll a key you don't have so things like a safe deposit box are not useful for the average case.
3 copies of your 2-factor, 2 different mediums (a Yubikey and recovery tokens printed on paper), at least 1 in a different location (safety deposit box, trusted family members house, etc).