Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

71–80 of 246 posts

Re: LastPass notifies users of yet another data breach

#71
post #69

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.

This. KeePassXC plus Google Drive client is all you need.

Re: LastPass notifies users of yet another data breach

#72

Earlier quoted context omitted.

Password managers (whether it's Lastpass or your browser's built-in password store) also protect against phishing since they tie passwords to domain names. I don't think password managers which store encrypted vaults are less safe than trying to have and juggle strong unique-per-domain passwords, even if you think that the password manager is becoming a target.

When they work… I finally gave up on 1Password as it has been getting worse and worse about actually autofilling for a few years. After all the Avengers turned into investors and the price increase was announced, I jumped ship. It felt like they were more worried about their ROI than the product. After 18 years of use, this was pretty disappointing.

For personal use, Bitwarden + a Raspberry PI should work perfectly fine. Your devices will sync when you are home. If they get out of sync, your fallback is to password reset. Or use your browser's built-in password manager which also syncs in most cases. I prefer to be browser-agnostic since it gives an easy solution to handle non-web passwords.

Re: LastPass notifies users of yet another data breach

#73
post #16

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

It is inertia. Customers are sticky, they do not switch unless they have to. If you're an enterprise, you have to go through establishing a new vendor relationship, onboarding a new password vault with your IT team, communicate it across the org, migrate data from the old password vault to the new password vault, etc. There is a real cost in time and resources to do this, and so, many avoid it until they have no other choice.

Lastpass is owned by PE. Why? Because Francisco Partners and Elliott Management bought a cashflow that is sticky. Its why most software companies were acquired by PE prior to the Cambrian explosion of generative AI.

Re: LastPass notifies users of yet another data breach

#74
post #14
post #4

Earlier quoted context omitted.

>“On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,” The specific dependency that gets companies infected, and the optics that result, are so important. There have been sillier examples, but you can see how in this case, the priority of sales and pr…

“ the priority of sales and profits has resulted in the sacrifice of the main quality measure of their main and only product” What do you mean exactly here What do you think LastPass could have done to prevent this specific issue?

Not installing the infected package of course.

It's worth noting that this is not 'their marketing provider' what they do is load 30 different providers for some reason, to maximize the reach of their data sharing and advertising network. Well, their network reached too far and touched an infected node.

Re: LastPass notifies users of yet another data breach

#75
Lol. Again.

Private company third party password managers are bad. Across the board. They're a bad idea.

Deeply localized actual best practices can help solve this. Private companies can also help, but only if it isn't in the form of "you can't have this unless you pay for it." The point is, it's like fighting fires, you can't isolate it.

It's a complete dead-end and the sooner the industry realizes this the better.

Re: LastPass notifies users of yet another data breach

#76
post #11
post #3

Using a password manager has 2 main tradeoffs and mistakes: 1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff. 2- Cat and mouse security: There's a class of security decisions that work because they are new and different…

The article is about a marketing data breach, not passwords.

I understand, just making a general comment.

And it's not unheard of that infections metastize, whether into developer accounts, product code... Probabilistically, this was a shot on goal.

I apologize for the mixed metaphors.

Re: LastPass notifies users of yet another data breach

#77
post #50

Earlier quoted context omitted.

The one that amazes me is Okta. OK their Mac UX is great, but given their rate of incidents how can you trust it? Clearly this stuff is not actually bought based on track record.

Funny I used to work in an org with Okta. Having your own auth workflow was instant fail with the well architected framework committee. Using Okta was instant pass. I don't necessarily disagree with that policy but given that Okta was breached several times while I was working there, it was interesting the extent to which our CSO had blinders about it.

Liability is the answer! If you build an auth system and it fails, it's your backside. If Okta fails, it's theirs. Enterprises buy products as much as they buy protection from problems.

Re: LastPass notifies users of yet another data breach

#78

This isn't great but it's not that big of a deal either. A lot of companies got bit by the Klue breach but it's not like your vaults are being accessed.

The vaults were accessed years ago

Yes, in a separate breach.

Re: LastPass notifies users of yet another data breach

#79
post #55
post #16

Earlier quoted context omitted.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh.

Yeah but wanting a product like LastPass doesn't require that you use LastPass. There are many good alternatives.

Re: LastPass notifies users of yet another data breach

#80
post #55
post #16

Earlier quoted context omitted.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness

Would you be okay will a public database of all people's names, emails, addresses, phone numbers, and other contact details? After all, most people's data have already been leaked somewhere. Credit reporting agencies have leaked more sensitive data. I, for one, still expect companies to keep my private data private. Especially companies who's started purpose is to keep my secrets secret. It's a bad look for them and if I trusted them this would make me lose my trust in them. But, they already lost my trust two or three (I lost count) breeches ago.

Post reply on HN