Live data from Hacker News

Lastpass setting the delete account div to display: none

infosec.exchange

1–10 of 210 posts

Re: Lastpass setting the delete account div to display: none

#3

The title would make more sense with quotes around the CSS keywords: I'm sure LastPass setting the delete account to "display: none" was coincidental

Took me a while to understand. OP, you're encouraged to kindly make the CSS terminology stand out a little more obviously in the title.

Re: Lastpass setting the delete account div to display: none

#4
I work at a large company and against the opinion of many engineers and infosec folks, lastpass was picked as our preferred corporate password storage. I'm just waiting for a call from infosec asking me to log on and to rotate a bunch of creds. Happy Holidays.

Re: Lastpass setting the delete account div to display: none

#6

I work at a large company and against the opinion of many engineers and infosec folks, lastpass was picked as our preferred corporate password storage. I'm just waiting for a call from infosec asking me to log on and to rotate a bunch of creds. Happy Holidays.

Our new parent company -- that works in a security-sensitive industry -- rolled out LastPass over the last few months.

I sent a warning letter to the CISO listing the previous hacks and vulnerabilities in LastPass.

Then this new hack happened, and the CISO sent out a letter saying that there is nothing to be concerned about and that all is well.

When the news broke that the breach was worse than predicted, I sent another letter to the CISO highlighting the concern.

So far, I've had zero responses to any of my emails. Just radio silence. The cold shoulder treatment. Dogs barking in the distance. Etc...

I'm starting to suspect that the CISO is getting some sort of kickback from LastPass, because he's doubling down with every breach on a bad decision.

Has anyone else had any experience with LastPass offering outright bribes to senior staff to get sales? If I can point to a precedent, that would be helpful.

Re: Lastpass setting the delete account div to display: none

#9

I work at a large company and against the opinion of many engineers and infosec folks, lastpass was picked as our preferred corporate password storage. I'm just waiting for a call from infosec asking me to log on and to rotate a bunch of creds. Happy Holidays.

Our new parent company -- that works in a security-sensitive industry -- rolled out LastPass over the last few months. I sent a warning letter to the CISO listing the previous hacks and vulnerabilities in LastPass. Then this new hack happened, and the CISO sent out a letter saying that there is nothing to be concerned about and that all is well. When the news broke that the breach was worse than predicted, I sent ano…

He doesn’t need to be getting a kickback. He probably just wants to spin as hard as he can that his poor choice cost did not cost the company a bunch of money.

Re: Lastpass setting the delete account div to display: none

#10

I work at a large company and against the opinion of many engineers and infosec folks, lastpass was picked as our preferred corporate password storage. I'm just waiting for a call from infosec asking me to log on and to rotate a bunch of creds. Happy Holidays.

Our new parent company -- that works in a security-sensitive industry -- rolled out LastPass over the last few months. I sent a warning letter to the CISO listing the previous hacks and vulnerabilities in LastPass. Then this new hack happened, and the CISO sent out a letter saying that there is nothing to be concerned about and that all is well. When the news broke that the breach was worse than predicted, I sent ano…

I wouldn't suspect kickbacks immediately, simply trying to avoid blame for the initial decision seems motive enough.
Post reply on HN