Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

81–90 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#81
post #76

This is quite interesting. A couple of weeks ago, I received an extortion phishing email, but it was directed to a secondary email address that hasn’t been previously compromised. It made it past Gmail’s spam and phishing filters into my inbox. Maybe a coincidence, but I guess every weird thing that happens is going to raise alarm bells. I was suspicious of the LastPass concept (storing passwords in a cloud app) when…

I’d love to hear the story about bypassing/resetting that 2FA setting? Sounds suspiciously like something that could be social engineered around by a sufficiently skilled attacker?

I am very much of the opinion that if I fuck up my side of 2FA protection, the resources/accounts they’re protecting should be lost forever. (Or at the very least, a co-account holder might be able to reset some things, like my AWS IAM creds or GSuite admin account). If I can ring up and whine at enough support people to get them to hand over my account, so can a sufficiently persistent skilled social engineer…

Re: The situation at LastPass may be worse than they are letting on

#82
post #39

Earlier quoted context omitted.

That’s not secure at all. Eventually, some website you use is going to get hacked. They’ll have stored passwords as plaintext. From there, anyone who wants to hack any of your accounts knows your password format. It’s going to be obvious to them that they just need to replace the domain.

how would they figure out the unique identifier? couldn't you say the same thing about using an arbitrarily unique password and then a password manager. if your password manager is hacked then they'd get the encrypted passwords for all sites you use along with all the personal information. of course, you'll say, don't use a crappy password manager. and that's correct. same reason I use a separate format for sketchy s…

Pro tip: don’t boast about your password strategy with ~10 bits of entropy online. If I were to target you, you just gave me an edge for free.

Re: The situation at LastPass may be worse than they are letting on

#83

Is there any reason to use these cloud based solutions when open source alternatives like KeepassXC is available?

Is there any reason to give someone else your password to store when you can just remember it or write it down somewhere safe?

Re: The situation at LastPass may be worse than they are letting on

#84
And when I say that I will stop using 1password when the local vault no longer works, people look at me like I'm paranoid and crazy.

I've looked at the white paper https://1passwordstatic.com/files/security/1password-white-p..., I think 1password has a decent security posture for their cloud offering but then there's always the risk of a breach where the attacker controls the site and can intercept your master password through it. Same as what happened with British Airways or Lavabit.

Re: The situation at LastPass may be worse than they are letting on

#85
post #79
post #64

Having all your keys/passwords on a 3rd party server is something that I've never been willing to accept from a security standpoint. That's what always kept me from using a `hosted` solution. I do get the allure from a multi-user management aspect though.

I used to use KeePass and synced the database (but not the keys or password) with Dropbox. Very secure and mostly convenient.

I loved a similar setup when 1Password used to make that easy. I am very grumpy about them bait and switching me to a cloud/subscription model. (But not quite grumpy enough to have done anything about it yet.)

Re: The situation at LastPass may be worse than they are letting on

#86
post #75
post #20

Earlier quoted context omitted.

Right, should've remembered reading that. Am I the only one who thinks that's a crazy thing to put in LP?

Kind of? I can see it both ways. It is putting all your eggs in one basket. The flip side is your vault is supposed to be protected enough that shouldn't be an issue.

Another comment rightfully points out that the vault itself is only protected by a password. I don't think that's protected enough if it's on cloud storage.

Re: The situation at LastPass may be worse than they are letting on

#87
Please stop commenting whether you are a LastPass user or not. Some of your profiles on HN have an email address and in general all your comments are public so can be mined, plus "rich techies" could be prime targets for more direct and elaborate phishing campaigns.

Re: The situation at LastPass may be worse than they are letting on

#88

If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?

This seems like an aside, but I'd love to see smart contract wallets with velocity send limits, or time locked whitelists as well as social recovery

Here we see the crypto world continuing their speed run of reinventing the banking system, and discovering daily atm withdrawal limits.

Re: The situation at LastPass may be worse than they are letting on

#89

LastPass-the-company doesn't need to die over this incident, but I can't help but wonder if a kind of corporate panic will stop them from doing what they need to survive it.

They are owned by LogMeIn, which is a pretty shady company in my book (not malicious necessarily, but not transparent).
Post reply on HN