LastPass notifies users of yet another data breach
91–100 of 246 posts
Re: LastPass notifies users of yet another data breach
#92Re: LastPass notifies users of yet another data breach
#93Any detailed info on why Klue had this data, apart from being their partner? How does it serve LastPass customers to give that data to Klue?
Re: LastPass notifies users of yet another data breach
#94Lots more companies affected. Some more listed below: >"Klue has not said how many of its hundreds of customers are affected. Several companies have come forward to confirm they had data stolen during the attack, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium." >Cybercrime group Icarus took credit for the breach, saying on its leak site that it will publish the s…
Re: LastPass notifies users of yet another data breach
#95How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.
Re: LastPass notifies users of yet another data breach
#96Earlier quoted context omitted.
What's the risk, and does that change by moving to an alternative? Companies deal with leaked secrets a lot. A company already using a password manager is ahead of the game. Suppose they move to a competitor. That's a migration and training that someone has to drive. What do they gain? Another company that can also have exploits? Or they self-host, and now have to fund that, and still potentially get exploits? Ultima…
Compare https://hn.algolia.com/?q=lastpass to basically any other password manager, like https://hn.algolia.com/?q=1password or https://hn.algolia.com/?q=bitwarden Those companies do not have the same number and severity of security incidents. lastpass is truly in a category of its own
but there is a non-trivial switching cost to migrate several people (with varying technical aptitudes) that each use several platforms.
if 1password had a one-click migration flow they'd be able to win over a lot of converts.
Re: LastPass notifies users of yet another data breach
#97Re: LastPass notifies users of yet another data breach
#98Re: LastPass notifies users of yet another data breach
#99Earlier quoted context omitted.
"Password manager" used to mean a program that runs locally on your computer. At some point people started making it into a SaaS, because that's more profitable. I do think there are some cases where an online password manager makes sense, e.g. for businesses, but for individuals it's better to just stick with an offline password manager, at least for the high value accounts.
>At some point people started making it into a SaaS, because Wait. That's a thing? Like, there are drooling, mouth-breathing stooges out there that would trust not just one of their passwords to such a thing, but all their passwords to it?
Re: LastPass notifies users of yet another data breach
#100Using a password manager has 2 main tradeoffs and mistakes: 1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff. 2- Cat and mouse security: There's a class of security decisions that work because they are new and different…
For backup, the hardware security key let's you download a file from it with all of your passwords encrypted, and the decryption password it's shown on it's screen (something like 12 random words)