Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

61–70 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#61
post #36
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.

It all depends on how the data are encrypted. With a sensible design capturing the encrypted storage will only reveal the number of encrypted records, rough estimates on their size, and time stamps.

Re: The situation at LastPass may be worse than they are letting on

#63
post #55

Earlier quoted context omitted.

I agree: LastPass has been hot garbage for many years but it still has a significant presence, some guy’s low-value crypto wallets would not be the first we hear about a compromise of LastPass vaults. There are entire companies using LastPass for critical systems. I absolutely believe it’s possible that LastPass has been compromised more than they’ve let on and I won’t be surprised if we eventually find out vaults ar…

But if you had a ton of credentials from people, scanning for crypto credentials and trying to use those may be easier/faster/safer to turn into money than system credentials to some random company network.

If the hack of LastPass happened yesterday, sure, but it happened months ago. There are a variety of different attacks that could be executed in that time, and the sooner the attacks are executed, the better — because less time for credentials to be rotated.

I find it implausible that the first hint of vault compromise comes 4 months after the hack and is against a low value cryptocurrency wallet. Especially considering that when LastPass first had issues, there were dozens of people reporting personal experiences of it here on HN — if LastPass vaults are compromised, the internet would be flooded with reports.

Re: The situation at LastPass may be worse than they are letting on

#65

I've been using LastPass for years. Looks like I'm going to have to export everything from my LP vault and import it into Bitwarden. Any downsides to Bitwarden that anyone knows of? I'm asking more about convenience, i.e. how well the browser extensions and Android app work and less about security.

I use LastPass at work and Bitwarden (technically Vaultwarden but same clients) at home.

I find that Bitwarden's UI is much less quirky, for lack of a better term. LastPass finds ways to consistently annoy me.

The commonly clicked secrets move to the top, I can see more than two items in the list, it doesn't forget me periodically, and when prompted for credentials I can't cancel it and get in anyway.

You can add multiple sites to the secret, not in some hidden menu in Bitwarden. That's handy for things like AD/LDAP credentials.

Re: The situation at LastPass may be worse than they are letting on

#66
post #60

I've been using LastPass for years. Looks like I'm going to have to export everything from my LP vault and import it into Bitwarden. Any downsides to Bitwarden that anyone knows of? I'm asking more about convenience, i.e. how well the browser extensions and Android app work and less about security.

Switched from LastPass to Bitwarden some time ago. The only issue I had thus far was exporting the contents out of LastPass. Some of the special characters in some passwords did not export properly. I had to add those items by hand. As for Bitwarden, I like the UI (iPad, Mac, iPhone) but routinely forget how to generate a new password - the function is buried inside one of the menu options. Other than that, I really…

Thanks very much. I wanted to hear from others who've made the same switch, so this is really helpful. LP has been pretty seamless for across devices so I wanted to know what to expect with BW.

Re: The situation at LastPass may be worse than they are letting on

#68
post #49

If this was true, i feel like it would be a little strange for the attacker to use it to steal a small amount of crypto. Once its revealed how bad this is, there would probably be a small window before people change their passwords, i would assume attackers would either go for a big score before revealing this capability, or they would try to hit everything very quickly. Just hitting a tiny amount of crypto seems odd…

Perhaps the crypto passwords were stored in the unencrypted URL field, or could be understood from data in there.

https://twitter.com/SwiftOnSecurity/status/16060717986671738...

Re: The situation at LastPass may be worse than they are letting on

#69
post #45

Earlier quoted context omitted.

you're putting a lot of confidence in an effective password length of 3

you're thinking too much about the specific example and not the general point, but I edited the parent comment with an actual example edit: oh, I did say append so I see why you'd think that. that's my bad. what I meant was include

By your example, your passwords are a set of fixed or knowable data, plus a unique identifier that in your examples is three characters long. Therefore knowing one of your passwords gives all except three characters of every other password, thus making your effective password length three characters (substitute the actual length of your unique identifier if it's more than three).

Re: The situation at LastPass may be worse than they are letting on

#70
post #60

I've been using LastPass for years. Looks like I'm going to have to export everything from my LP vault and import it into Bitwarden. Any downsides to Bitwarden that anyone knows of? I'm asking more about convenience, i.e. how well the browser extensions and Android app work and less about security.

Switched from LastPass to Bitwarden some time ago. The only issue I had thus far was exporting the contents out of LastPass. Some of the special characters in some passwords did not export properly. I had to add those items by hand. As for Bitwarden, I like the UI (iPad, Mac, iPhone) but routinely forget how to generate a new password - the function is buried inside one of the menu options. Other than that, I really…

Quick tip: if you have Bitwarden's browser extension installed, you can use Cmd + Shift + 9 (I'm assuming it's Ctrl + Shift + 9 for Windows) to load your clipboard with a randomly generated password: h4!E49vFcGEE%c#$HZ%z*3^5B
Post reply on HN