Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

501–510 of 587 posts

Re: Lastpass Security Incident

#501
post #74

If you're a lastpass user, might be wise to avoid logging into lastpass until they update with a resolution - if the attackers got into the build server they could craft attacks that would exfiltrate passwords after user decrypts

Fuck. If you're a lastpass user, you kind of don't have a choice. I can't log into accounts I use for socializing, work, banking, etc. without lastpass

I just spent a couple of hours resetting my most important passwords and writing them down on paper.

Won’t be touching LastPass again except offline, while I figure out where to go from here. I had been putting off finding a better password manager, but this is the last straw.

Re: Lastpass Security Incident

#502

Earlier quoted context omitted.

free for personal use, open source, cloud synced, no device limits. and as OP mentioned different server implementations if you want to host it yourself. No idea why people stick to any of the proprietary solutions.

You have no idea why people don’t want to self-host a service? Or don’t have the knowledge to do it (securely)?

You don't need to with Bitwarden, you can if you want to. Like Lastpass by default Bitwarden store and syncs your passwords online.

Re: Lastpass Security Incident

#503

Earlier quoted context omitted.

You're missing the point entirely. When you're on prem you only have to worry about your own employees opening sketchy PDFs. When you're not, you have to worry about everyone in your supply chain opening sketchy PDFs. Nevermind the fact that the next time a major world conflict occurs, the big 4 cloud providers will probably be destroyed, taking about 90% of the western economy with it.

> When you're not, you have to worry about everyone in your supply chain opening sketchy PDFs. That's absolutely not correct. Besides, I have more respect for the security and operations procedures for AWS, GCP and Azure than I do for 99% of startups running their own infrastructure. But my primary point is that you seem to be arguing that being on prem is inherently more secure, and more importantly, being in the cl…

It doesn't matter how secure 4 providers are. There are only 4. OpSec won't stop a submarine from bombing underwater fiber. OpSec won't stop a missile heading for the data center. The strategic importance of our consolidated infrastructure WILL be a paramount target for any enemy of the west.

On-prem business is a diversified attack vector. Cloud storage is a consolidated attack vector. Would russia rather attack 100,000 small diverse targets, or one enormous target with 1,000,000s of customers?

Re: Lastpass Security Incident

#504

Earlier quoted context omitted.

I want to as well, but annoyingly there are many sites that insist on a "special" character because their strength measure says "low" for the 20 character alphanumeric string I generated %-}

My favorite is when they actually limit what special characters you can use. Must include 1 of x special characters. Why? I always just assume they baked their own password storage and couldn't figure out how to handle the whole set of special characters

Multiple times I've found that this is caused by a web application firewall that is intended to mitigate SQL injection attacks. So they disallow the characters that would commonly be used in those attacks.

Re: Lastpass Security Incident

#505
post #496

I've been looking to migrate off LastPass to Bitwarden or KeePassXC, but can't decide: 1. First off, who's to say LastPass will actually delete my data when I delete my account? Could I in practice be increasing my exposure by starting to use something different? 2. Bitwarden: They look cool but "In September 2022, the company announced $100M series B financing". In my experience, usually, financing = bad. 3. KeePass…

I've been very happy with Bitwarden. If things go south because of getting funding there are some good forks of the server you can self-host (vaultwarden).

Re: Lastpass Security Incident

#506

Earlier quoted context omitted.

I'm currently doing interviews for a senior firmware dev position and was stunned by this. Today I talked to a guy who couldn't tell me what an interrupt was in any technical detail. His coding was worse than a first year college students. 5 of the 6 people I've talked to so far bombed the coding portion.

This isn't intended as a rebuttal, but I've learned to stay away from deeply technical questions in embedded. As long as the interviewee is sufficiently paranoid about C, is recognizably experienced via conversation, and knows the basic concepts I don't press too hard on their specific skillset. There are just too many niches where the knowledge we each consider necessary simply isn't. I had one particularly bad inte…

Im pretty new to interviewing so I appreciate the feedback. I think I'm dong OK with respect to that but I'll make sure not to assume my own expertise are trivial.

Re: Lastpass Security Incident

#508

Earlier quoted context omitted.

I just exported my own vault with the latest version, it was ok for me. I have plenty of passwords with all kinds of special characters. Still, be sure to review the CSV file. If anything looks weird, double check that the password is the same in your LastPass vault. As with all backups/exports, you should always do a sanity check of the data. One issue I ran into: the CSV file that "downloaded" in the browser didn't…

I had a problem not with the password data but with the content of some notes (or whatever it is called in LastPass) I have been a paying customer of Lastpass for about 15 years. I moved to Bitwarden for all sorts of reasons. I work in technical information security so it was also for that teason (but not only)

We were considering self-hosting but sadly Bitwarden is still stuck on MS SQL ;/

There was some apparently compatible rust implmementation in PostgreSQL tho...

Re: Lastpass Security Incident

#509
post #496

I've been looking to migrate off LastPass to Bitwarden or KeePassXC, but can't decide: 1. First off, who's to say LastPass will actually delete my data when I delete my account? Could I in practice be increasing my exposure by starting to use something different? 2. Bitwarden: They look cool but "In September 2022, the company announced $100M series B financing". In my experience, usually, financing = bad. 3. KeePass…

Why no 1Password on your list?

+1 for 1Password and Bitwarden. One is good at UI, one is simply yet more affordable.

Re: Lastpass Security Incident

#510
post #496

I've been looking to migrate off LastPass to Bitwarden or KeePassXC, but can't decide: 1. First off, who's to say LastPass will actually delete my data when I delete my account? Could I in practice be increasing my exposure by starting to use something different? 2. Bitwarden: They look cool but "In September 2022, the company announced $100M series B financing". In my experience, usually, financing = bad. 3. KeePass…

Why no 1Password on your list?

I just looked at the two that seemed to be the most mentioned in my circles (that'd be HN, I'm afraid...)
Post reply on HN