How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.
LastPass notifies users of yet another data breach
71–80 of 246 posts
Re: LastPass notifies users of yet another data breach
#72Earlier quoted context omitted.
Password managers (whether it's Lastpass or your browser's built-in password store) also protect against phishing since they tie passwords to domain names. I don't think password managers which store encrypted vaults are less safe than trying to have and juggle strong unique-per-domain passwords, even if you think that the password manager is becoming a target.
When they work… I finally gave up on 1Password as it has been getting worse and worse about actually autofilling for a few years. After all the Avengers turned into investors and the price increase was announced, I jumped ship. It felt like they were more worried about their ROI than the product. After 18 years of use, this was pretty disappointing.
Re: LastPass notifies users of yet another data breach
#73How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.
Lastpass is owned by PE. Why? Because Francisco Partners and Elliott Management bought a cashflow that is sticky. Its why most software companies were acquired by PE prior to the Cambrian explosion of generative AI.
Re: LastPass notifies users of yet another data breach
#74Earlier quoted context omitted.
>“On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,” The specific dependency that gets companies infected, and the optics that result, are so important. There have been sillier examples, but you can see how in this case, the priority of sales and pr…
“ the priority of sales and profits has resulted in the sacrifice of the main quality measure of their main and only product” What do you mean exactly here What do you think LastPass could have done to prevent this specific issue?
It's worth noting that this is not 'their marketing provider' what they do is load 30 different providers for some reason, to maximize the reach of their data sharing and advertising network. Well, their network reached too far and touched an infected node.
Re: LastPass notifies users of yet another data breach
#75Private company third party password managers are bad. Across the board. They're a bad idea.
Deeply localized actual best practices can help solve this. Private companies can also help, but only if it isn't in the form of "you can't have this unless you pay for it." The point is, it's like fighting fires, you can't isolate it.
It's a complete dead-end and the sooner the industry realizes this the better.
Re: LastPass notifies users of yet another data breach
#76Using a password manager has 2 main tradeoffs and mistakes: 1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff. 2- Cat and mouse security: There's a class of security decisions that work because they are new and different…
The article is about a marketing data breach, not passwords.
And it's not unheard of that infections metastize, whether into developer accounts, product code... Probabilistically, this was a shot on goal.
I apologize for the mixed metaphors.
Re: LastPass notifies users of yet another data breach
#77Earlier quoted context omitted.
The one that amazes me is Okta. OK their Mac UX is great, but given their rate of incidents how can you trust it? Clearly this stuff is not actually bought based on track record.
Funny I used to work in an org with Okta. Having your own auth workflow was instant fail with the well architected framework committee. Using Okta was instant pass. I don't necessarily disagree with that policy but given that Okta was breached several times while I was working there, it was interesting the extent to which our CSO had blinders about it.
Re: LastPass notifies users of yet another data breach
#78Re: LastPass notifies users of yet another data breach
#79Earlier quoted context omitted.
A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.
I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…
Yeah but wanting a product like LastPass doesn't require that you use LastPass. There are many good alternatives.
Re: LastPass notifies users of yet another data breach
#80Earlier quoted context omitted.
A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.
I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…
Would you be okay will a public database of all people's names, emails, addresses, phone numbers, and other contact details? After all, most people's data have already been leaked somewhere. Credit reporting agencies have leaked more sensitive data. I, for one, still expect companies to keep my private data private. Especially companies who's started purpose is to keep my secrets secret. It's a bad look for them and if I trusted them this would make me lose my trust in them. But, they already lost my trust two or three (I lost count) breeches ago.