Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

71–80 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#71

Is there any reason to use these cloud based solutions when open source alternatives like KeepassXC is available?

I used KeePass + Dropbox/Syncthing for years, but eventually gave up. At some point I saved my KeePass db with a newer version (of the software and the DB format), and later found out that the newer software version will not run on an older version of MacOS that I still use on one machine.

I mean, I could maybe update the OS on that machine (not sure--it's over 10 years old) but at that point it was less work and less risk to switch to BitWarden. And the user experience is much better as well.

Re: The situation at LastPass may be worse than they are letting on

#72

Earlier quoted context omitted.

you're thinking too much about the specific example and not the general point, but I edited the parent comment with an actual example edit: oh, I did say append so I see why you'd think that. that's my bad. what I meant was include

By your example, your passwords are a set of fixed or knowable data, plus a unique identifier that in your examples is three characters long. Therefore knowing one of your passwords gives all except three characters of every other password, thus making your effective password length three characters (substitute the actual length of your unique identifier if it's more than three).

you're right - i have clarified what I actually do. however I do something similar with a different password for sites I deem unsafe, or spammy.

Re: The situation at LastPass may be worse than they are letting on

#73
post #51

this sort of thing is why I append the name of the website + a unique identifier + password, so that I don't have to bother changing my password during such nonsense, ugh.

Do this instead https://spectre.app/

How does one handle password rotation requirements?

Re: The situation at LastPass may be worse than they are letting on

#74
post #58

If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?

Passwordless might be the way to go. We (as a society) have been trying to do 2FA now wherever we can. 2FA can involve an authenticator app but it is easier with a physical key. That physical key by itself can obsolete the password for many uses. The more numerous the places where we can abandon passwords, the fewer the secrets that we need to keep.

This is the answer. The only advantage of passwords is that they’re cheap and universally compatible. PKI based solutions are more secure and more convenient. They cost a few dollars and there are too many standard, though.

Ultimately, I expect the biggest barrier to be mental. People have had mantra about passwords banged into their heads for decades that they have become synonymous with a secure system and people are suspicious when their device just lets them in with little to no friction.

Re: The situation at LastPass may be worse than they are letting on

#75
post #20
post #16

Earlier quoted context omitted.

he said his seed phrases were in lastpass. There is no 2fa protection for private keys if the assets are in his crypto wallet and he's custodying them.

Right, should've remembered reading that. Am I the only one who thinks that's a crazy thing to put in LP?

Kind of?

I can see it both ways. It is putting all your eggs in one basket. The flip side is your vault is supposed to be protected enough that shouldn't be an issue.

Re: The situation at LastPass may be worse than they are letting on

#76
This is quite interesting. A couple of weeks ago, I received an extortion phishing email, but it was directed to a secondary email address that hasn’t been previously compromised. It made it past Gmail’s spam and phishing filters into my inbox.

Maybe a coincidence, but I guess every weird thing that happens is going to raise alarm bells.

I was suspicious of the LastPass concept (storing passwords in a cloud app) when a former employer introduced it some years ago, but they had a strong IT and security culture so I trusted them to make the right choices and adopted it for my personal use.

A few months ago I hsd an issue with my LastPass 2FA device and a policy set by my former employer blocked me from resetting it for my personal account. It was resolved by LastPass, but that was the first strike, and I had spent most of the night extracting my personal account passwords manually from the mobile app, which remained logged in. That was strike 1. This is strike 2.

Re: The situation at LastPass may be worse than they are letting on

#77

If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?

This seems like an aside, but I'd love to see smart contract wallets with velocity send limits, or time locked whitelists as well as social recovery

Re: The situation at LastPass may be worse than they are letting on

#78
post #20
post #16

Earlier quoted context omitted.

he said his seed phrases were in lastpass. There is no 2fa protection for private keys if the assets are in his crypto wallet and he's custodying them.

Right, should've remembered reading that. Am I the only one who thinks that's a crazy thing to put in LP?

He said there wasn't much value in the wallets. Doesn't strike me as crazy to keep a small amount in something convenient. You see a similar convenience/security trade off made by big players, with immediate transactional needs satisfied by online/hot wallets and reserves held in offline/cold wallets.

Re: The situation at LastPass may be worse than they are letting on

#79
post #64

Having all your keys/passwords on a 3rd party server is something that I've never been willing to accept from a security standpoint. That's what always kept me from using a `hosted` solution. I do get the allure from a multi-user management aspect though.

I used to use KeePass and synced the database (but not the keys or password) with Dropbox. Very secure and mostly convenient.
Post reply on HN