Live data from Hacker News

I Lost All Faith in LastPass

infosec.exchange

51–60 of 322 posts

Re: I Lost All Faith in LastPass

#51
post #3

Has LastPass always been this bad and nobody noticed or did the new owners change it?

For at least a few years yes, I dropped them 3-4 years ago but as others have mention the red flags go back further. GoTo acquisition was the last straw for me.

Re: I Lost All Faith in LastPass

#52

Earlier quoted context omitted.

There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.

Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.

Appeal to authority is not a fallacy, it's basically a necessity to function in the world.

Re: I Lost All Faith in LastPass

#53

Earlier quoted context omitted.

Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.

An appeal to authority is not a logical fallacy if the person in question is actually an authority in the domain .

I wish more people would remember this.

Re: I Lost All Faith in LastPass

#54

How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…

I don't buy the "if it's open source we can see/audit/trust the service" argument.

1. Bugs get missed all of the time in OSS. There is no guarantee that the more eyes the better, and in fact there may be a negative correlation due to the bystander effect [citation needed].

2. A software service is a complex interaction between many pieces of software. Two perfectly secure, audited pieces of software could interact in an exploitable way.

3. Just because the service provider tells you "this is the code, this is how we keep you secure, etc." doesn't mean it's true in practice. A bad actor could modify the code in production before the next version of "audited, trusted, OSS" is vetted.

4. Security practices outside of the code also matter (arguably more so), and even an organization with good policies can fail to follow them at times.

Ultimately, we're trusting the people behind the services we use to be honest and do their best. It seems that LastPass has demonstrated they aren't as deserving of that trust lately, but THE SAME THING COULD HAPPEN AT ANY ORGANIZATION.

Footnote: LP/1P could push an update that grabs everything necessary to decrypt your password vault the next time you log in.

Re: I Lost All Faith in LastPass

#55
post #30

Earlier quoted context omitted.

There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.

Which people? I've been very reluctant to use their cloud solution as I trust Dropbox more for security. So I still fight 1password to keep the vault stored in Dropbox. I figure there are maybe 4 organizations who are active enough to prevent a full download of all their user's data. Google, Dropbox, Amazon, and Facebook. (Maybe Apple, but they seem lethargic.) Because they store all the passwords to all of our servi…

You trust Dropbox? The company that infamously invited to their board a former government official responsible for authorizing warrantless mass surveillance?

Re: I Lost All Faith in LastPass

#56

Earlier quoted context omitted.

Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.

Appeal to authority is not a fallacy, it's basically a necessity to function in the world.

Trust is a necessity, not authority. Those with authority are often not trustworthy.

Re: I Lost All Faith in LastPass

#57

How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…

I don't buy the "if it's open source we can see/audit/trust the service" argument. 1. Bugs get missed all of the time in OSS. There is no guarantee that the more eyes the better, and in fact there may be a negative correlation due to the bystander effect [citation needed]. 2. A software service is a complex interaction between many pieces of software. Two perfectly secure, audited pieces of software could interact in…

Source code is necessary for trust, but not sufficient.

Re: I Lost All Faith in LastPass

#58
Leaning strongly towards self-hosting. Name brand cloud managers just make too juicy a target for sophisticated attackers regardless of their competence/care of the pass manager co.

I know it's got a bit of security via obscurity vibes, but I've concluded the combo of residential IP, wireguard, firewall and dedicated VM is probably more secure. That would require someone with decent skill targeting me specifically...in which case they're probably better off with a wrench attack anyway.

The big unknown is uptime.

Re: I Lost All Faith in LastPass

#59
post #58

Leaning strongly towards self-hosting. Name brand cloud managers just make too juicy a target for sophisticated attackers regardless of their competence/care of the pass manager co. I know it's got a bit of security via obscurity vibes, but I've concluded the combo of residential IP, wireguard, firewall and dedicated VM is probably more secure. That would require someone with decent skill targeting me specifically...…

You can always self-host BitWarden!

NB: Not affiliated with the company, just a very happy customer.

Re: I Lost All Faith in LastPass

#60
post #31

Use of 3rd party password trackers has been a periodic concern for our organization. We do B2B business with banks , so the temperature is increased somewhat. There are kinds of credentials we have access to that genuinely terrify me. I've been debating building an in-house solution for managing secrets, if for no other reason than to get all of this information off of 3rd party computers. No serious proposals have b…

If I were a bank customer, I would not want to hear your second paragraph…
Post reply on HN