Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

81–90 of 246 posts

Re: LastPass notifies users of yet another data breach

#82

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

I remember ten years ago telling our so-called leaders that the data will get leaked from LastPass. They were all gung-ho about it being secure blah de blah. Luckily most of us don't work there anymore.

Re: LastPass notifies users of yet another data breach

#83
post #55

Earlier quoted context omitted.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness Would you be okay will a public dat…

Yes, a public database like this would be acceptable. That way the info isn't paywalled behind some white pages site or similar. And then maybe I could even update my own info to be correct. Contact info is pretty much out there for most people already. Hell, I put it on my resume and send that out to many people and put it on public sites.

Re: LastPass notifies users of yet another data breach

#84

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

I’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were the ones that had been breached in the past. Until the execs and board see the dollar impact themself and not just read about it, the security program never gets the funds it needs. I’m not saying I recommend LastPass for that reason, but I wouldn’t write them…

What happened to the old days of only getting one chance to f-up? Once chance and they should be gone permanently.

Re: LastPass notifies users of yet another data breach

#85
post #53
post #45

Earlier quoted context omitted.

I got caught out as I had no longer access to the old phone number that was now used to send 2FA text.

oh dang that's not good. I've had the same phone number since 2006 so I didn't really think about it

But the phone number you have is not 100% in your control. I had AT&T flub something and I lost my number and they assigned me a new one (I was chanting my plan just after they did some merging with someone). Granted its unlikely but I would still use defense in depth and not have password reset be my only login method.

Re: LastPass notifies users of yet another data breach

#86
post #55

Earlier quoted context omitted.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness Would you be okay will a public dat…

Of course it's not okay. But this is pissing in the ocean. This is throwing buckets of water on the Titanic.

The damage is already done. Your private information was already leaked long ago. You can't make a sunk boat more wet.

Re: LastPass notifies users of yet another data breach

#87
post #55

Earlier quoted context omitted.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness Would you be okay will a public dat…

Where I’m from there actually were guides like this of the whole country, published once a year, I think even into the early 2000s. They stopped doing it for cost savings, but this type of information being public is considered fairly normal by many, as long as you have the ability to unsubscribe.

Re: LastPass notifies users of yet another data breach

#88
post #69

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.

Passbolt and Bitwarden can be self-hosted on top of offering the usuals pros like MFA, an API incl. integrations (e.g. https://external-secrets.io/latest/provider/passbolt/) and a better UX that does not involve syncing files between team members

Re: LastPass notifies users of yet another data breach

#89
post #55

Earlier quoted context omitted.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness Would you be okay will a public dat…

Only if we also add Social Security numbers, since it was supposed to be a unique Identitifier (like an email) and not a secret.

Re: LastPass notifies users of yet another data breach

#90

Earlier quoted context omitted.

Syncing isn't a KeePassXC problem. The database is just a file. That may or may not make your life easier. There are a few decent Android and iOS apps that work well. I use Nextcloud and WebDAV for access. Not a setup I can recommend to just anybody though.

One of the security advantages of KeePass being just a file is that you can sync it in the way that makes sense to you. The need to have an opinion on how you’d like to sync a file does, as you suggest, eliminate some portion of the population who need a fully baked answer in one step. I used to use Google Drive, but now I use Syncthing, further reducing my exposure. Paired with Synctrain and KeePassium on iOS. One t…

And if you use an untrusted sync like Google Drive, you can enable a keyfile and never let that file lane on Google Drive.
Post reply on HN