Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

81–90 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#81
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

What about just using chrome’s saved passwords and syncing?

It would be great if someone can succinctly destroy that idea :D

Re: What’s in a PR statement: LastPass breach explained

#82
post #13

The know it all tone of this article is kind of annoying. Security professionals seem to have a common trait of thinking they know better. Some good points in there, but limited pragmatism.

I completely disagree. The article makes an extremely strong case that the press release was designed to mislead people into downplaying both the severity of the situation, and the depth of incompetence at LastPass (both of which are matters of considerable importance for all current and prospective LastPass customers.) Attempting to mislead people is considerably more serious than mere incompetence.

The best (if not only) way to make these points is to analyze the PR statement itself. Any paraphrasing or generalization would just give LastPass an opportunity to reply with more non-sequiturs.

Dissembling circumlocution and omission is a feature of PR communication, designed to mislead anyone who is not intimately familiar with all the details. I would like to se more analysis of this sort.

> Security professionals seem to have a common trait of thinking they know better.

The author here does know better than the people running LastPass.

Re: What’s in a PR statement: LastPass breach explained

#83
post #13

The know it all tone of this article is kind of annoying. Security professionals seem to have a common trait of thinking they know better. Some good points in there, but limited pragmatism.

I read it as frustration that they had been warned over and over again and could have prevented this.

Re: What’s in a PR statement: LastPass breach explained

#84
post #19
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

That sounds like a huge anti-feature to me. The few services that a next-of-kin should realistically need access to (banking and... that's pretty much it) will already have a process in place for handling this.

The rest of my accounts should die when I do.

Re: What’s in a PR statement: LastPass breach explained

#85

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

What's with "MacOS" vs "macOS" in the toggle features ?!?

Re: What’s in a PR statement: LastPass breach explained

#86
post #58
post #28

Earlier quoted context omitted.

Disclaimer : I am the author of this article. What kind of pragmatism would you prefer? LastPass messed up way more than they are willing to admit. And it’s not like nobody warned them before, quite a few of the issues which turn out to be very problematic now aren’t news – I brought them up years ago as did others. LastPass should be warning users now and suggesting mitigation steps, instead they claim that nobody h…

This is a compelling article, I feel more motivated now to reconsider my options. FWIW, my $0.02 feedback on pragmatism: as a user, it would be nice to have more what-to-do-about-it for non-security-experts. Also I didn’t love the parts of the article where you speculated about LastPass’ motivations and process (even if they turn out to be true!) The opening paragraph is making assumptions about the timing, which cou…

> which could backfire pretty badly if you're wrong

That's an odd take. Who could it backfire on? LastPass has already fumbled their own response to this crisis. If not him, others would speak up. If he's wrong, then he loses credibility. The upside is that, if he's right, we're even more aware that LastPass is not a company worth dealing with.

Re: What’s in a PR statement: LastPass breach explained

#87
post #55

It would be interesting to hear people’s life philosophy in this area. For me, lastpass always seemed like a bad idea as passwords are very important to me and giving someone else a copy of my passwords seems like a bad idea. Similarly, I don’t let any services know my bank passwords even if they super promise to protect them and not misuse them. Another similar seeming task that I can’t delegate is to read my bank s…

It's a tradeoff based on convenience. I use Linux, Windows, Android, and iOS on a daily basis; using some combination of SyncThing, OneDrive, Google Workspaces, and iCloud. Getting an offline-first PW manager to work correctly and consistently across those devices, operating systems, and services is no easy feat. Doubly so if you actually want proper integration with the OS & browser keychain.

At some point the closest you'll get is a self-hosted BitWarden instance, in which case you are basically running LastPass/1Password/et al. yourself anyways. Then you have to ask yourself (a) can you host it cheaper than a monthly subscription of a competing service, and (b) can you maintain that instance better _in your free time_ than some engineers that get paid to do it every day?

The answer to (a) for me is definitely not, my colo bill is much larger than a 1pass subscription, and (b) is also probably a big fat no considering there were concerns in this article I hadn't even thought of. So ultimately I'm happy paying a nominal fee for someone to keep up w/ the ever changing landscape of OS/browser integrations & minefield of security pitfalls regarding credential storage.

I wish there was some elegant way to magically kept all my devices in sync, that was portable & standardized, but the reality is modern vendors seem more interested in creating silos than standards.

---

However there are things I don't put in my 1pass, despite it having great support for them, because I consider the alternatives more convenient or secure:

(1) My PGP/SSH keys are on a YubiKey

(2) My 2FA TOTP codes are on that YubiKey or some other authenticator

(3) My 2FA backup codes are on an encrypted volume. That secret is not stored in 1pass.

(4) My critical services (DNS, e-mail) require hardware backed 2FA.

The theory being even if you steal my PW vault you can't own my DNS, without my DNS you can't own my MX, and without my MX you can't truly own my online identity.

Re: What’s in a PR statement: LastPass breach explained

#88

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

I don’t see an issues tab so I can’t open a bug report. There are two redundant checkboxes for MacOS (differing by capitalization).

Re: What’s in a PR statement: LastPass breach explained

#89
post #81
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

What about just using chrome’s saved passwords and syncing? It would be great if someone can succinctly destroy that idea :D

Then you're stuck with Chrome forever. Same with Firefox or Safari. I wish browser vendors would agree on one password sharing protocol that's just some end-to-end encrypted blob that you could download from any browser and unlock with your password. You login to your Firefox or Google account, add passwords, and if you want to use those from the other browser you just get some http link that points to the encrypted blob and then the other browser downloads the blob and you unlock it with a password.

Re: What’s in a PR statement: LastPass breach explained

#90

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

Never seen a url like that for such a project. FYI
Post reply on HN