Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

61–70 of 587 posts

Re: Lastpass Security Incident

#61
post #25

it's so baffling to me that people give ALL their password to a third party, commercial, organization...

What's the alternative?

1. Have people manage their own secrets storage? Most people don't have the time or ability do this securely either. I'd rather pay someone else to secure infra, code, distribution, encryption, backups, etc. for me.

2. Reuse the same password on every site? One site gets hacked and now you're screwed.

3. Memorize a unique, long password for every site? Not feasible.

Third-party/commercial password managers are the best solution for most people, practically speaking.

Re: Lastpass Security Incident

#62
post #25

it's so baffling to me that people give ALL their password to a third party, commercial, organization...

Then what should folks do? The alternative is having to "run your own encryption" by running your own Password manager on your own infra or re-using passwords

Re: Lastpass Security Incident

#63
post #53

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.

Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.

Re: Lastpass Security Incident

#64

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

memorable symbols and the site name

!%!%example.com%!%!

Re: Lastpass Security Incident

#66

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

i use diceware. my mothers maiden name is sternness-ardently, and i am a proud graduate of blade-purge-satin-dash elementary! …apparently.

blade-purge sounds like a good name for a metal band

Re: Lastpass Security Incident

#67
post #60

Earlier quoted context omitted.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

I generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.

I hate password managers. They sign you out way too often and god forbid you’re on another PC.

Re: Lastpass Security Incident

#70
I’m disappointed, but I can’t say I’m surprised. I once tried to contact their support team after getting effectively locked out of my account, only to have the support form return a 5XX error upon submission. I dropped them right then and there.
Post reply on HN