Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

531–540 of 587 posts

Re: Lastpass Security Incident

#531

Earlier quoted context omitted.

I can never recommend 1Password enough. When it comes to hosted options, they are hands down the best. Worth pointing out that they also have integrated 2FA, if you're satisfied with first and second factor living in the same spot. https://1password.com

What about 1password is inherently safer though?

I'd suggest reading their security page[0] and write ups others like Troy Hunt has done[1][2].

[0] https://1password.com/security/

[1] https://www.troyhunt.com/have-i-been-pwned-is-now-partnering...

[2] https://haveibeenpwned.com/1Password

Re: Lastpass Security Incident

#532

> was able to gain access to certain elements of our customers’ information This is frustratingly vague. This incident started 4 months ago, and you can't provide any details? If it wasn't such a PITA to move off LastPass, I would do so. They got me.

How is it a PITA to move off lastpass? I switched to Bitwarden and it was a piece of cake. Exported all passwords. Imported all passwords. Pretty much all password managers can import/export as a CSV or similar.

You can't export all the passwords, some extra fields are not exported by LastPass, so there is your PITA when some site asks a security question you had an answer to in that unexported field

Re: Lastpass Security Incident

#533

Earlier quoted context omitted.

I can never recommend 1Password enough. When it comes to hosted options, they are hands down the best. Worth pointing out that they also have integrated 2FA, if you're satisfied with first and second factor living in the same spot. https://1password.com

What exactly about 1Password is safer, including their cloud hosted options? Curious as I may look at multiple options.

https://news.ycombinator.com/item?id=33820779

Re: Lastpass Security Incident

#534

Earlier quoted context omitted.

I can never recommend 1Password enough. When it comes to hosted options, they are hands down the best. Worth pointing out that they also have integrated 2FA, if you're satisfied with first and second factor living in the same spot. https://1password.com

What exactly about 1Password is safer, including their cloud hosted options? Curious as I may switch.

[deleted]

Re: Lastpass Security Incident

#535

Earlier quoted context omitted.

I ask a lot of questions that I preface with: I hope you are slightly insulted by the questions I'm about to ask. They get progressively more complex as we go, but the candidate is fully aware they are filter questions that I hope they clear with zero effort.

Why not just start with the questions you consider the minimum level to clear?

[deleted]

Re: Lastpass Security Incident

#536

Earlier quoted context omitted.

Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.

When I was studying we had to use the computers in uni when presenting homework. It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells). Unfortunately google requires either their app or SMS. They dropp…

> for some reason

Google plainly dropped totp wherever possible in order to confirm everyone's identity.

Totp was an open standard that didn't help them spy on anyone, and they regret releasing it bigtime.

Re: Lastpass Security Incident

#537
post #496

I've been looking to migrate off LastPass to Bitwarden or KeePassXC, but can't decide: 1. First off, who's to say LastPass will actually delete my data when I delete my account? Could I in practice be increasing my exposure by starting to use something different? 2. Bitwarden: They look cool but "In September 2022, the company announced $100M series B financing". In my experience, usually, financing = bad. 3. KeePass…

Just use keepassxc and be master of your keys. You have to move forward. Every 6 months I hear about a breach at lastpass. I assumed only clueless normies were left on it, but I guess their efforts to blockade data exports were effective.

Re: Lastpass Security Incident

#538
They gave no information on what was hacked. Although they're saying no passwords were compromised because of their encryption and architecture.

For a layperson, what's the best tips for what to do. Are passwords in Lastpass still safe or should we change all the passwords? Or simply change the master? Or should we migrate to something else?

I've thought about migrating before but frankly any password manager will have breaches...

Re: Lastpass Security Incident

#539
post #508

Earlier quoted context omitted.

I had a problem not with the password data but with the content of some notes (or whatever it is called in LastPass) I have been a paying customer of Lastpass for about 15 years. I moved to Bitwarden for all sorts of reasons. I work in technical information security so it was also for that teason (but not only)

We were considering self-hosting but sadly Bitwarden is still stuck on MS SQL ;/ There was some apparently compatible rust implmementation in PostgreSQL tho...

Have you tried Vaultwarden? (Ex bitwarden_rs). It is in Rust and it's absolutely fantastic.

I self host it for a year or two and it is a single container. The BW officer docker distribution is a nightmare.

Add to that a proxy with caddy and you get a great solution.

Re: Lastpass Security Incident

#540

Earlier quoted context omitted.

No one who uses unique passwords can remember them forever. It's a compromise of post-it notes vs managers. Either that or do account recovery every time you need to do your taxes (SOL for encrypted files though). I sadly write passwords down, but dream of a better option.

Post-It notes are a safer option than password managers. And it's absolutely outrageous to say this: But not every single account you have needs a unique password. Just ones which can actually allow someone to impersonate you meaningfully, cost you money, or gather sensitive data about you. Response to @palata because of rate-limiting: The problem is people tend not to only put unimportant accounts in their password…

> People have started storing their TOTP tokens in their password managers, which effectively reimplements single-factor authentication!

The thing is that many services are now requiring TOTP in places where I don't want it, since I was already using a strong/unique password, and the TOTP requirement is effectively just to protect the service from having to deal with users who get their passwords stolen. If you're going to make me use TOTP where I don't want it, I'm going to automate its input.

Post reply on HN