Live data from Hacker News

LastPass says hackers had internal access for four days

bleepingcomputer.com

1–8 of 8 posts

Re: LastPass says hackers had internal access for four days

#3
post #2

This isn't the first time this company has been breached. I'd stay far away from this company. If you really need a centralized password repo, use 1password. But if you can, I'd recommend self-hosting (VaultWarden) over any online service provider.

I am still amazed anyone would use a proprietary password manager which stores in someone else's computer. That's the opposite of good password management.

Re: LastPass says hackers had internal access for four days

#4
post #2

This isn't the first time this company has been breached. I'd stay far away from this company. If you really need a centralized password repo, use 1password. But if you can, I'd recommend self-hosting (VaultWarden) over any online service provider.

Did you mean BitWarden? Or really VaultWarden?

Re: LastPass says hackers had internal access for four days

#5
post #3
post #2

This isn't the first time this company has been breached. I'd stay far away from this company. If you really need a centralized password repo, use 1password. But if you can, I'd recommend self-hosting (VaultWarden) over any online service provider.

I am still amazed anyone would use a proprietary password manager which stores in someone else's computer. That's the opposite of good password management.

Which is why LastPass doesn't store your passwords on its servers, just a one-way hash.

Re: LastPass says hackers had internal access for four days

#6
post #3

Earlier quoted context omitted.

I am still amazed anyone would use a proprietary password manager which stores in someone else's computer. That's the opposite of good password management.

Which is why LastPass doesn't store your passwords on its servers, just a one-way hash.

I don't think that's correct. They state that passwords are decrypted in the browser. They are stored encrypted on their servers but not decrypted on their servers AFAIK

Re: LastPass says hackers had internal access for four days

#7
post #3

Earlier quoted context omitted.

I am still amazed anyone would use a proprietary password manager which stores in someone else's computer. That's the opposite of good password management.

Which is why LastPass doesn't store your passwords on its servers, just a one-way hash.

That wouldn’t be very helpful if the point is for the service to remember your passwords.

Re: LastPass says hackers had internal access for four days

#8
post #4
post #2

This isn't the first time this company has been breached. I'd stay far away from this company. If you really need a centralized password repo, use 1password. But if you can, I'd recommend self-hosting (VaultWarden) over any online service provider.

Did you mean BitWarden? Or really VaultWarden?

Based on the context of self-hosting, I assume the parent wrote correctly.