Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

1–10 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#2
These appear to be the main previous threads:

See what is unencrypted in your LastPass vault - https://news.ycombinator.com/item?id=34105368 - Dec 2022 (9 comments)

LastPass breach is worse than you think because URLs were unencrypted - https://news.ycombinator.com/item?id=34102982 - Dec 2022 (81 comments)

LastPass users: Your info and vault data is now in hackers’ hands - https://news.ycombinator.com/item?id=34100087 - Dec 2022 (19 comments)

LastPass says hackers stole customers' password vaults - https://news.ycombinator.com/item?id=34099647 - Dec 2022 (15 comments)

LastPass user vaults stolen in recent hack - https://news.ycombinator.com/item?id=34097142 - Dec 2022 (276 comments)

Lastpass Security Incident - https://news.ycombinator.com/item?id=33806803 - Nov 2022 (560 comments)

LastPass confirms hackers had access to internal systems for several days - https://news.ycombinator.com/item?id=32912350 - Sept 2022 (21 comments)

LastPass says hackers had internal access for four days - https://news.ycombinator.com/item?id=32871051 - Sept 2022 (7 comments)

Last Pass Hacked - https://news.ycombinator.com/item?id=32612645 - Aug 2022 (35 comments)

LastPass: Notice of Security Incident - https://news.ycombinator.com/item?id=32598587 - Aug 2022 (130 comments)

Re: The situation at LastPass may be worse than they are letting on

#4
post #2

These appear to be the main previous threads: See what is unencrypted in your LastPass vault - https://news.ycombinator.com/item?id=34105368 - Dec 2022 (9 comments) LastPass breach is worse than you think because URLs were unencrypted - https://news.ycombinator.com/item?id=34102982 - Dec 2022 (81 comments) LastPass users: Your info and vault data is now in hackers’ hands - https://news.ycombinator.com/item?id=3410008…

[deleted]

Re: The situation at LastPass may be worse than they are letting on

#5
For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault:

> At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1]

I haven't used LastPass in years, but the recent news made me wonder how Bitwarden was handling URLs.

[1] https://bitwarden.com/resources/zero-knowledge-encryption-wh...

Re: The situation at LastPass may be worse than they are letting on

#7
post #3

It is difficult for me to believe that this could be true unless their web application has also been hacked. And if that were the case then this is really getting into criminal negligence territory (especially the way they've been disclosing it).

When I read their most recent email updating about the situation today or yesterday, I did get a definite chill down my spine. I've not used LP for a year or so, but my data (much of it now old) is still stored there, mainly left as a backup as I'd heard some people had some weird issues migrating to other password managers.

I had made a mental note some months back when this first happened I should really go through everything important in my vault and update all passwords to sleep more peacefully at night. I had also made a mental note at the time that if this situation were going erupt into something much worse, it would almost certainly be over the Christmas period when many people are not at work or their computers and it would be the perfect moment for causing maximum chaos and destruction. Looks like I now really need to prioritise that tomorrow. Really not what I wanted to be doing on Christmas Eve...

Re: The situation at LastPass may be worse than they are letting on

#10

Is there any reason to use these cloud based solutions when open source alternatives like KeepassXC is available?

Yeah: they’re cloud based. Your passwords get synced to all your devices automatically. That’s kinda the entire draw.
Post reply on HN