Live data from Hacker News

LastPass requesting password reset after facing unknown anomaly

blog.lastpass.com

61–66 of 66 posts

Re: LastPass requesting password reset after facing unknown anomaly

#61
post #27
post #15

Earlier quoted context omitted.

The there's somebody how can key log hardware you (think you can) trust, you're hosed whatever security you're relying on.

Negative, LastPass can generate one-time passwords which you can then use on computers you suspect to be insecure.

But most of the damage from keyloggers happens to people who do NOT suspect they are using an insecure system (their own).

Re: LastPass requesting password reset after facing unknown anomaly

#62
post #56

IMHO everyone who is using such a service is a moron.

This is an irresponsible position to take and akin to telling people to "make stronger passwords." It simply isn't realistic. LastPass allows creation of randomly generated passwords very easily and encrypts and stores them so you can use them anywhere. The alternative for most normal users is to create one or two passwords and use them everywhere, compromising the security of all of their accounts. Obviously your response to this would be that they shouldn't do that but the fact is, without something like LastPass, they have little other choice.

This freakout reminds me of the radiation poison bullshit from a few months back. Bananas have radiation therefore bananas are dangerous. Practicality dictates that you are plain wrong.

Re: LastPass requesting password reset after facing unknown anomaly

#63
post #59
post #55

Earlier quoted context omitted.

End users don't need to memorize any passwords. They don't know them and they do not care what the passwords are (nor should they). They only need to know how to generate them when needed. Read about SHA1_Pass and try it out. I use it (and wrote it) to deal with hundreds of passwords that change frequently. I tried to make traditional password managers work for a number of years, before realizing that the traditional…

I've looked at SHA1_Pass when it was posted here on HN a while back, and I'm not impressed. You have to memorize a passphrase, which is only marginally easier than remembering a master password, but you also have to remember an individual word for each account/website. Yes this is easier than remembering individual passwords but not as easy as just remembering one master password that unlocks an encrypted database (l…

"You have to memorize a passphrase"

This is an inaccurate statement. You remember a sentence. Sentences are naturally and easy to recall. The fat, green stick. for example. And then a word for each site you visit. That's it. You can use it anyway you like and take my samples for what they are... samples.

What's the big deal?

Controlling your passwords on your devices and not relying on others. Passwords are IT Security 101, if you get them wrong you fail.

Re: LastPass requesting password reset after facing unknown anomaly

#64

That's the final straw for me. Just exported my login details, emptied out my lastpass vault and uninstalled the addon. Will stick to storing my login details in a Dropbox distributed GnuPG protected flat file. Less convenient, but at least I'm not reliant on a third party.

You still rely on Dropbox.

That was my initial thought, but no. All dropbox files are local. You only rely on Dropbox for synchronizing across your designated machines and backing up on Dropbox, but Dropbox going down does not restrict access to any local Dropbox folder.

Re: LastPass requesting password reset after facing unknown anomaly

#65

Earlier quoted context omitted.

You still rely on Dropbox.

In what way do I rely on Dropbox for securing or accessing my login details? My passwords are encrypted and accessible at all times, even if Dropbox is down or I lack Internet access...

So is LastPass, you just click the 'log in locally' checkbox.

Re: LastPass requesting password reset after facing unknown anomaly

#66

Earlier quoted context omitted.

In what way do I rely on Dropbox for securing or accessing my login details? My passwords are encrypted and accessible at all times, even if Dropbox is down or I lack Internet access...

So is LastPass, you just click the 'log in locally' checkbox.

I never claimed anything different...

However, to be more accurate:

"So is LastPass, unless you disable offline login, or enable the use of a Yubikey"

Post reply on HN