Live data from Hacker News

LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

krebsonsecurity.com

51–60 of 77 posts

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#51

The first paragraph very nearly lost me – irrational, rage bait, directly contradicts later stated facts – but there’s some good content later. The chief complaint seems to be that LastPass is not forcing this upgrade, they are just blast emailing unaffected people that they “forced” it while not actually doing so. And they’ve pulled similar stunts in the past, and in current communication seem to clearly be blaming…

> Everybody with a clue knows LastPass is a lost cause, Yeah at this point, I have to wonder how there are still lastpass users to worry about whatever the latest lastpass scandal is.

My employer has a contract with LastPass, yeah..

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#52
post #50

>>> KrebsOnSecurity last month interviewed a victim who recently saw more than three million dollars worth of cryptocurrency siphoned from his account. That user signed up with LastPass nearly a decade ago, stored their cryptocurrency seed phrase there, and yet never changed his master password — which was just eight characters. Nor was he ever forced to improve his master password. This does fascinate me. How many p…

I still hold ~1M US worth of crypto all together, which is roughly the majority of my net worth. Been in since early days. If I'd guess I've probably "realized" (sold/used for payment for non-crypto goods or services) ~20~30k$ or so over the years? I still donate here and there and use it for payment for goods and services when I can. I probably lost at least another ~1M$ worth (not projected: at the time. it sucks b…

Add: Realized I def sold more than $30k when I consider I basically lived off cash I got through localbitcoins and similar for a few years. Meeting up random people at coffee shops etc.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#53

Earlier quoted context omitted.

I'm too lazy to change.

Take the 10 minutes to migrate to Bitwarden or 1Password or such and be done with it.

Yeah, if you have no attachments, otherwise it takes days and a lot of programming knowledge

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#54
post #9

Earlier quoted context omitted.

If you are complaining about the idea of iterating a hash multiple times, this is actually a fairly standard construction to increase the cpu cost of brute forcing hashes.

Asking a question isn’t complaining.

The post i was responding to was edited since i replied. Regardless my bad if i came off sounding harsh, that wasn't my intention.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#55

The whole approach that LastPass uses of only encrypting the vault with the master password is just bad security - it really doesn't matter how many rounds of a key derivation algorithm they use. The 1Password approach provides much better security. The vault is protected with the master password together with a long randomly generated string. That random string is saved on device on first login, so subsequent decryp…

Serious question - I've never used 1Password - what happens if you only ever use one device and that device becomes permanently unavailable for some reason (stolen, destroyed, etc)?

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#56

The first paragraph very nearly lost me – irrational, rage bait, directly contradicts later stated facts – but there’s some good content later. The chief complaint seems to be that LastPass is not forcing this upgrade, they are just blast emailing unaffected people that they “forced” it while not actually doing so. And they’ve pulled similar stunts in the past, and in current communication seem to clearly be blaming…

Can someone explain to me what is the advantage of using something like LastPass over simply the in-built password manager that Firefox or other browsers have? I know that LastPass can be used for desktop applications too, but if you are only using a password for the web, is LastPass offering anything more than the in-built browser password manager?

Who only logs in on websites? So many apps also require logging in.

I'm also not sure if those built-in password managers sync to other devices and if you want to trust them with it.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#57

The whole approach that LastPass uses of only encrypting the vault with the master password is just bad security - it really doesn't matter how many rounds of a key derivation algorithm they use. The 1Password approach provides much better security. The vault is protected with the master password together with a long randomly generated string. That random string is saved on device on first login, so subsequent decryp…

Serious question - I've never used 1Password - what happens if you only ever use one device and that device becomes permanently unavailable for some reason (stolen, destroyed, etc)?

As part of the setup process 1Password has you print out an "Emergency Kit" that contains your secret key, https://support.1password.com/secret-key-security/.

But you are absolutely correct, if you lose your device and the Emergency Kit you're SOL. It reality, though, that is mitigated by the fact that:

1. I think it's probably pretty rare to install 1P on only a single device, as the biggest benefit of any hosted password manager is syncing. I think the vast majority of people will install it at least on their phone and a laptop/PC.

2. I think the user experience for setting up the Emergency Kit is done well and most people are likely to do it.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#58
post #56

Earlier quoted context omitted.

Can someone explain to me what is the advantage of using something like LastPass over simply the in-built password manager that Firefox or other browsers have? I know that LastPass can be used for desktop applications too, but if you are only using a password for the web, is LastPass offering anything more than the in-built browser password manager?

Who only logs in on websites? So many apps also require logging in. I'm also not sure if those built-in password managers sync to other devices and if you want to trust them with it.

Downside of Firefox Sync for password management is indeed its lack of iOS app integration. Sadly, I suspect it is Apple making it impossible to compete.

Upside is that it also syncs to my Firefox on Linux, which Apple’s doesn’t.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#59

Earlier quoted context omitted.

Can someone explain to me what is the advantage of using something like LastPass over simply the in-built password manager that Firefox or other browsers have? I know that LastPass can be used for desktop applications too, but if you are only using a password for the web, is LastPass offering anything more than the in-built browser password manager?

credentials/certificates/keys/data storage, secure sharing etc. Pretty much anything that's more complex than single user username + password doesn't seem to be served by the current built-in managers.

A lot of these require deeper system integration, and this is not, in my experience, cross-platform. I’d rather have to drag my SSH/VPN keys and certs around manually, and have basic password management working across iOS, MacOS and Linux.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#60

Earlier quoted context omitted.

Can someone explain to me what is the advantage of using something like LastPass over simply the in-built password manager that Firefox or other browsers have? I know that LastPass can be used for desktop applications too, but if you are only using a password for the web, is LastPass offering anything more than the in-built browser password manager?

Safari's built-in pw manager: - until recently, didn't have 2fa - doesn't support multiple domains under the same account (e.g., the stackexchange network is considered one site per subdomain) - doesn't support generating complex passwords (it'll generate passwords but I'd hardly call them complex…) - doesn't support credentials not associated with websites (e.g., an SSH login, a bank pin…)

Also doesn’t support recovery questions. As someone who generally enjoys safari, the password manager could use some love. Integration across devices is good though.
Post reply on HN