23 ms·
LastPass users warned their master passwords are compromised
- JadoJodo 5y agoI left after the 2011 incident. Amazing, they've had so many since. https://en.wikipedia.org/wiki/LastPass#Security_issues https://en.wikipedia.org/wiki/LastPass#Security_issues
- fxtentacle 5y agoI use keepassxc.org in Dropbox It's encrypted on my computer by Open Source software that I can trust. I used to use LastPass, but it was clearly a sinking ship ever since it was bought by LogMeIn.
- jooz 5y agoWhen using my password manager, I often provide only the password, not the user. In case of data breach they can not be exploited.
- askvictor 5y agoWouldn't your username generally (or at least, quite often) be your email, which would be recoverable? Might slow an attacker down a little I suppose, or prevent automated attacks.
- jooz 5y agoIm thinking on txt files shared with leaked user and password. On those cases my credentials would not appear. If somebody focus on hacking _me_, they already have my email, so this measure is not very effective.
- smegsicle 5y agorelated: Ask HN: How did my LastPass master password get leaked? https://news.ycombinator.com/item?id=29705957 https://news.ycombinator.com/item?id=29705957
- Barrin92 5y agoall the speculation in that thread about how the password could have been leaked reminded me of a post earlier this year that drastically changed my view on password managers. (also generated a lot of discussion here) https://news.ycombinator.com/item?id=27407603 https://news.ycombinator.com/item?id=27407603
- gruez 5y agoSeems like the lesson there is to use a standalone password manager, rather than one that's a browser extension?
- tim333 5y agoSome guy did an long analysis and figured for most purposes you are as well to use the built in ones in Chrome or Firefox. Personally I kind of like Bitwarden.
- denton-scratch 5y agoI'm not inclined to run anything that's remotely related to password security in a browser extension (I do use the Firefox built-in password manager to simplify logging in to sites like this one, where I have no money at stake and nothing much to lose but my pride). For high-value logins, I use Passwordsafe. It's annoying; the scroll behaviour is annoying, and it's Windows-only, which is sad. But it's resolutely local and un-networked, and I'm confident that my secrets are well-protected by my (complex, long, memorized) master password.
- mbordenet 5y agoAssuming you're talking about pwsafe 3, it's not Windows-only. I am actively using a Java implementation on MacOS and rely on my Android app for frequent use. Password file is synced across devices via a cloud drive provider. Works great, and I'm in control. (I also rotate my password file + master password every few months.)
- 5y ago
- Krasnol 5y agoLet this be your Last non-selfhosted Pass solution.
- simpleguitar 5y agoSelf hosting sucks for an average user, and terrible for a mobile user. It is possible to have hosted password solution that is secure, so why not use it? This is basically the same "cloud" vs "on-prem" debate. Cloud won, I think.
- jimsi 5y agoI use KeePassDX on Android and KeePassXC on a laptop, and they are synced with Syncthing. I have no issues with this setup
- Isthatablackgsd 5y agoThat is not selfhosting. Selfhosting means web/cloud applications maintained by the users. Technically Syncthing is selfhosting but Keepass variants are not. So your setup is not really selfhosting because you are not hosting Keepass in the webserver.
- qzx_pierri 5y agoMy setup: - Windows Desktop - Macbook Air I installed Keepass on my windows desktop along with iCloud drive sync. I keep my Keepass database in my iCloud directory. I can now use this Keepass database on my iPhone (via Files app), on my Macbook (iCloud Drive). Any changes made are automatically synced daily. Is that really too difficult? And yes, it does "just work". Bonus: Any passwords stored in my iCloud Keychain are also synced to my Windows Chrome instance via Apple's 'iCloud Passwords'[1] plugin. [1] https://chrome.google.com/webstore/detail/icloud-passwords/pejdijmoenmkgeppbflobdenhhabjlaj https://chrome.google.com/webstore/detail/icloud-passwords/p...
- blondin 5y agolove this setup. are you able to sync your keepass database to your windows machine? i need to add this one drawback for people to keep in mind. and also because it happened recently and made hn frontpage. apple can decide to suspend your account for one reason or another. it is very rare but can definitely happen.
- simpleguitar 5y agoLastPass's statement via HowToGeek: https://www.howtogeek.com/776450/lastpass-says-it-didnt-leak-your-master-password/ https://www.howtogeek.com/776450/lastpass-says-it-didnt-leak...
- shireboy 5y agoSo original article is down, but this sounds like people who used the same password as their master and in some _other_ service that has been leaked. ie a user who's lastpass master pass is same as their facebook. Very different from having LastPass leak master pass. Is this the same issue or a case of LastPass not getting the situation?
- moneywoes 5y agoThis article mentions that there were users with unique LastPass passwords who had this occur. Also, I guess they have no incentive to admit a breach
- pelorat 5y agoLastPass doesn't store passwords on their servers, so it's not some magical breach.
- gruez 5y agoRight, but from an earlier HN thread people were saying their support forums prompted for their master password to log in?
- SV_BubbleTime 5y agoHow is this different from “enter your password and we’ll deliver your blob” and “enter your password and we’ll deliver you a login cookie”? Neither way “must” they have stored your master password.
- tgsovlerkhgsel 5y ago
- sdan 5y agoobligatory: I use passwordstore.org by Jason A. Donenfeld and its local, relatively easy to use, works with git, and free. Too niche for hackers to take interest I hope.
- Kwpolska 5y agoI used to use pass, and while it’s fine if you’re primarily a terminal user, it’s much less convenient if you’re dealing with Windows or mobile devices. Instead of fiddling with git and gpg (which is super painful on Android), I just use KeePassXC on desktop (Windows/Linux/Mac), Keepass2Android on Android, and sync my database via OneDrive. KeePass gives me search, storage of metadata and even attachments, simple copying, and auto-type. Much friendlier than pass ever could be.
- zaik 5y agoIf you're careful to not cause any merge conflicts (ie only pull never push) Password Store for Android [0] never caused me any problems. [0] https://f-droid.org/packages/dev.msfjarvis.aps https://f-droid.org/packages/dev.msfjarvis.aps
- bryan0 5y ago> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after clicking the "Delete" button. Is there anything more infuriating than this type of error message?
- iso1631 5y agoOnes which say "something went wrong" with a "funny" gif of someone scratching his head?
- hetspookjee 5y agoAdd a recaptcha that barrely solves in the mix before being able to click on continue, or after logging in.
- mNovak 5y agoJust tried deleting my account--got exactly that error. That's not reassuring
- scrapcode 5y agoSame here. It appears(?) that my account got deleted.
- vinnymac 5y agoConfirmed. I deleted my account, received the error above. Then when attempting to login again, I was told my email was mistyped. I stopped using LastPass a long time ago, but this has definitely put them on thin ice for me, I won't be recommending them going forward.
- 5y ago
- afrcnc 5y agodupe: https://news.ycombinator.com/item?id=29705957 https://news.ycombinator.com/item?id=29705957
- tuwtuwtuwtuw 5y agoIt's not a dupe.
- dang 5y agoIt's substantially the same story, no? and even reports on the big HN thread that took place about this.
- circa 5y agoHate to hear this, but I'm glad I bailed when LogMeIn bought them years ago.
- mrweasel 5y agoThe whole service pretty much started to deteriorate after being bought. We have daily issues with initial logins taking maybe five minutes. I've also experience being told that my account was a "Free user" and I had zero password. Not something you want to see when working for a company that has 1000+ passwords in Lastpass.
- ricardonunez 5y agoI did the same. They had some issues before that and I was considering leaving them. After LogMeIn bought them I left them.
- SV_BubbleTime 5y agoFor what it’s worth they are moving away from LogMeIn to be their own company again… almost certainly to be bought again later.
- twostorytower 5y agoHighly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.
- nathancahill 5y agoAh yes, the $5 wrench method.
- 1001101 5y agoA simple rubber hose would do. https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis
- cgb223 5y agoCome on, this is hacker news. Some of our skulls are so thick you’d need at least a $10 wrench
- echelon 5y agoAlso known as the "So you think you can escape the FBI [/CIA/FSB]?" fallacy.
- vorpalhex 5y agoI mean, if your threat model is such that you need to consider kidnapping and being hit with a wrench, as opposed to just a drive by breach, then you should in fact account for that appropriately.
- ohyeshedid 5y agoAre you aiming for perfect or have you stopped at good enough?
- kobalsky 5y agoThe xkcd author did a disservice to online security with that comic. You can be forced to disclose your secrets but you will know they were compromised, that's encryption doing its job. There's a world of difference in knowing.
- cgb223 5y ago> However, users receiving these warnings have stated that their passwords are unique to LastPass and not used elsewhere. So it’s not just bots trying passwords from other database leaks The whole premise of LastPass is that they can’t even decrypt your master password. It’s pretty concerning that this is happening. If hackers can get your master password, then _all_ of your passwords are at risk
- grouphugs 5y ago
- wepple 5y agoLastPass has had a history of security incidents (no company can completely avoid incidents, but if security is literally a primary part of your value, you shouldn’t be having so many). Even worse, they have a history of doing hand-wavy corporate non-explanations for what actually happened in these incidents. The antithesis of being responsible and respecting users in the modern day.
- benbristow 5y agoTo be fair to LastPass/LogMeIn, they're a company handling a lot of valuable information (passwords/form-fill data/card numbers/notes etc.) - and they're one of the biggest out there. You'd expect them to be one of the more targeted companies just because of the 'treasure' they hold - hence the more security breaches.
- 40four 5y agoAn “Ask HN” was just trending about this yesterday (https://news.ycombinator.com/item?id=29705957 https://news.ycombinator.com/item?id=29705957). Sounds like a good reason not to trust any third party service with my password database to me. I’ve always taken the route of managing my own local Keepass DB & key files. Sure it’s more cumbersome, but it prevents me from having to decide whether or not to trust some third party vendor or not. I know 100% that I’m in full control and I’ve never put my DB or key file in the cloud. I can sleep sound knowing that whatever password service, or file sharing service, somehow getting compromised, cannot endanger one of my most valuable assets
- perlpimp 5y agoStill using 1password6 not trusting the cloud store.
- phs318u 5y agoI recommend this every time a similar news item gets posted. Password Safe (designed by Bruce Schneier). I use the iOS and Linux apps and keep them synced via DropBox. Been around for years (I've been using it almost as long). Still getting updates. Still works. https://pwsafe.org https://pwsafe.org
- _wldu 5y agoBlog post about the design flaws of password managers: https://www.go350.com/posts/the-design-flaws-of-password-managers/ https://www.go350.com/posts/the-design-flaws-of-password-man...
- gruez 5y agoI can't say I like the post. >Users must also devise a master password to unlock the encrypted passwords stored by the password manager. This is similar to a master key. It is generally accepted that master keyed locks are less secure than non-master keyed locks. If the master password is exposed, then confidence (in all the passwords that it unlocks) is lost. 1. In a perfect world, having a master password is worse than having independent passwords. However, realistically you can't remember that many passwords, so in practice you end up reusing passwords across sites. Using a master password in this case is a worthwhile tradeoff. 2. on most password managers, you need access to both the database (either through the web, or as a file) and the master password to compromise its contents. Even if your password was "hunter2" or something, your accounts would probably be fine. >DPG Deterministic password generators/managers have problems of their own. Their main draw is supposedly the lack of state to keep track of, but realistically you still need to sync stuff (eg. usernames, site identifiers, password formats, counters), so that dream is never realized. >1. Never store passwords. Rather, generate them as needed based on user input. The need to backup, synchronize and properly encrypt passwords is removed. There is no master password that immediately unlocks all of the other passwords. There is nothing to become lost, stolen or corrupt. I can't tell whether this is satire or not. The author dunks on other password managers for having a "master password that immediately unlocks all of the other passwords", but his program literally has the same flaw? At least with traditional password managers you need access to the database and the master password.
- gkoberger 5y agoThis is framed so negatively toward LastPass, which is unfortunate. They stopped all usage of correct passwords they believed were compromised, which is exactly what I'd want them to do in this situation. Them warning users their master passwords are compromised is a good thing! Yet it's framed as though they're admitting to something. "However, users receiving these warnings have stated that their passwords are unique to LastPass and not used elsewhere." That's really hard to verify. I think most users would say that rather than admit they re-used passwords (or used similar passwords that were easy to reverse engineer). Since there only seems to be 2-3 reports of this, and they're self-reported and not cited, it doesn't seem like LastPass was compromised. I'm not saying I like LastPass (I use 1Password and find LastPass to be much worse), but I haven't seen any indication at this point that LastPass has been compromised at all. (To be clear, it's very possible I'm wrong and this message won't age well. But so far, it seems like LastPass is doing its job, and I'd want to see more than this before jumping on the blame-LastPass bandwagon.)
- vorpalhex 5y agoLastPass has had enough other security issues that I am doubtful of them to this day. https://www.mcafee.com/blogs/enterprise/cloud-security/lastpass-breach-by-the-numbers-91-enterprises-exposed/ https://www.mcafee.com/blogs/enterprise/cloud-security/lastp... Unfortunately the only password solutions I would recommend at this point are 1Password for something turn key, and BitWarden if you want to self host.
- gkoberger 5y agoAgreed, and I highly recommend 1Password. But just because they've had problems in the past doesn't mean the framing of this article is fair. The title made me think everyone's passwords were compromised due to a leak or hack, when in reality the article is a rehash of a HN post from yesterday.
- vorpalhex 5y agoThe official story from LastPass and the claims of the reporters are in direct conflict. Either the master passwords were reused and this is credential stuffing, or there is actually a LastPass breach affecting all users. One [incident] reporter claims they changed their master password and had a breach attempt using the new password. If that is true that is extremely alarming. There could be some malware targeting a LastPass extension or app cache somewhere, but that is groundless theory on my part.
- rpastuszak 5y agoProtip: even if you don't use LastPass any more, check if you deleted your account when leaving the service.
- n3dm 5y agoThey currently have disabled deletion of accounts. Everyone is getting a "A" error when trying to do so.
- rpastuszak 5y agoNah, I think the accounts get deleted but no one bothered testing the form. After all, this funnel won't convert into precious $$, so what's the point of maintaining it? (I removed my account recently and got the same error message, everything seems to be gone now)
- deleted 5y ago[deleted]
- latortuga 5y agoThis has to be a security issue with LastPass, right? Something like an as-yet unidentified usage of Log4j. > Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. This sounds to me like either a widely-compromised browser extension (LP itself?) or LP infrastructure.
- tuwtuwtuwtuw 5y agoOr just some malware like the latest keyloggers bundled with NPM packages? Wasn't it just a couple of weeks since that happened previous time?
- jeffrallen 5y agoSeveral years ago, I chose LastPass, bought it, and did all the set up. Then they were acquired by someone I didn't trust, so I immediately switched to 1Password, and never regretted it for a second. If 1Password sold out, I'd switch again, in a second.
- jjav 5y agoWhile this is a good approach at a high level, it's also worth pointing out that the usage should not be based on trust. You should evaluate if you're comfortable using this or that password manager even if they were aquired by the most evil company you can think of. If the design is solid, it shouldn't matter since the evil company shouldn't be able to compromise anything. If it does matter, then you shouldn't be using that software no matter how much you trust the company (because regardless of trust, they're still subject to secret court orders etc.)
- jeffrallen 5y agoYes, but password manager vendors seem to insist on moving towards cloud subscriptions, instead of "buy it once and you host it", which means you are somewhat dependent on them. If 1Password keeps pushing this direction and makes Dropbox sync stop, I'm SO outta there.
- CamelRocketFish 5y agoThe problem is we don’t have access to the design as it’s closed source?
- jjav 5y agoThat is certainly a factor to consider in the decision! I, for one, wouldn't use any security-critical software where the client isn't open source. (The server side doesn't matter for security for the same reason trust in the company shouldn't matter. No secrets should leak to the server.)
- llbeansandrice 5y agoI jumped ship from LastPass when they changed their subscription model so that I'd be paying for features that had previously been free. I'm now using Bitwarden for personal use and 1Password for work and I'm a fan. I previously tried offline password managers but syncing the files between devices and such was a huge pain.
- gravypod 5y agoIs there anything like lastpass that has TOTP + password remote backup that has a chrome plugin and an android application? I'm getting to the point where I'd love to switch off.
- wingmanjd 5y agoI use KeepassXC on my desktop OS's, storing my database on a NextCloud instance. Android can R/W that same file using the KeePassDX app (available on either the Play store or F-Droid). I can store TOTP keys in my Keepass database as well. My browser has an extension that lets me autotype the username, password, and TOTP codes. I know storing my TOTP passphrase along with my un:pw combo isn't as secure as keeping them in separate locations, but my threat model is just to stop someone with only my un:pw. YMMV
- GavinMcG 5y agoBitwarden. Its TOTP service is a premium feature ($10 per year).
- _dain_ 5y agoA spokesman said, "This is the one thing we didn't want to happen."
- rtomanek 5y agoIf you decide it's time to switch, consider switching to Keepass(-compatible software), with the DB file hosted via WebDAV (which you can either self-host or have hosted by a multitude of low-cost providers). This will give you nice conflict resolution if accessing (modifying) the file from multiple machines. There are clients available for all platforms. I use: Keepass (Windows), Macpass/ Keeweb/ Strongbox (MacOS), StrongBox (iPad) and Keepass2Android (Android, this one's fantastic!).
- michaelcampbell 5y agoYou should give KeepassXC a try. Way better QOL than the standard client, IMO.
- deleted 5y ago[deleted]
- civilized 5y agoConfession: I store all my passwords in a plaintext file on my local desktop. I'm sure some people will look at me very funny for doing this, but it seems to me that I have both fewer hassles logging in and fewer breaches than people using more "secure" methods (like handing your passwords over to LastPass's mystery Chrome extension). Think about today's threat landscape and tell me I'm wrong. I may not be more secure in every possible situation, but I'm more secure in the situations that cause the vast majority of breaches today.
- kalekold 5y agoI do the same and encrypt the file with a simple encryption tool.
- civilized 5y agoGood idea. I wish I could be bothered to do this slightly more secure thing to protect my entire livelihood, lol... I'll think about it.
- causality0 5y agoNot that your approach doesn't have advantages, but at that point I would just keep them in a paper notebook hidden in my desk.
- civilized 5y agoI'm a lazy bastard.
- foxfluff 5y agoThat's what I do. The number of times my home's been broken into: 0 (and based on news, virtually all of burglars are just looking for jewelry, wallets, and similar stuff and they won't bother trawling through your papers for passwords). The number of times I've had devices on my network that run some hastily put together vendor firmware that was last updated six years ago: too many to count. The number of times I've had to rush to update/patch my own computers to fix a newly disclosed remotely exploitable vuln: quite a few. The number of times I've actually witnessed attempts at trying to exploit said remote vulns: too many to count! Sometimes mere hours after I've patched my stuff. The number of times I've known I've had malware: at least a couple times (admittedly long ago, back when I ran Windows..). I just don't trust keeping personal passwords on online connected computing devices. And password managers are a very lucrative target today (plus it tends to be all eggs in one basket for most people!). I do keep passwords for employer's stuff in a password manager but not on the same device(s) I use said passwords on; even if you had malware on my work laptop, you wouldn't get my master password, nor would you be able to grab my password database. Passwords are also not stored on any third party service. The price I pay is a relatively minor inconvenience. (I do have plans for something more convenient though!)
- deleted 5y ago[deleted]
- koprulusector 5y agoI use LastPass - have been using it for years, and I'm pretty happy with it. I'm even happier now that they're going to be an independent company, no longer owned by "LogMeIn123" lol. But incidents like this don't bother me, because I require yubikey MFA. In fact, password breaches rarely bother me anymore, unless there's a rare case where I have an account on a site that doesn't allow me to use MFA.
- tgsovlerkhgsel 5y agoThey claim it's credential stuffing, but there are plenty of people on the HN thread (https://news.ycombinator.com/item?id=29705957 https://news.ycombinator.com/item?id=29705957) claiming to have used a unique password. Does LastPass/LogMeIn have a history of lying about/downplaying security incidents? I only remember a controversial (and to my knowledge unresolved) issue at TeamViewer (where the company claimed no compromise but due to the number of reports there were doubts about that claim).
- shakna 5y agoNot lying, but definitely downplaying past incidents [0], of which they have had a number. [0] https://en.wikipedia.org/wiki/LastPass#Security_issues https://en.wikipedia.org/wiki/LastPass#Security_issues
- tgsovlerkhgsel 5y agoOh, that leads to an interesting possibility: Yet another vulnerability in their extension, allowing a malicious web site to access the master password. This could be very hard to trace since users would have to notice the correlation between visiting a certain web site (or e.g. one of many compromised sites) and getting hacked. Worse, combined with malvertising, it could be exploited from almost any web site if the user doesn't block ads.
- SCLeo 5y agoTo those who are recommending all different password managers, I have a question: why not using Chrome (or Firefox/Edge/<any other browser>)'s built-in password manager? I have been using it for a couple years and haven't noticed any issue. Even if Google decides to screw me over and terminates my Google account, I can still access the passwords via the local copy in Chrome, so that is not really a concern. (Though, don't take this as my recommendation to use Google' password manager. I have not done enough research in the password manager landscape, which is why I am asking this question in the first place.) EDIT: also include other browsers' password managers. (It appears that it is a mistake to mention anything Google on HN :/)
- howdydoo 5y agoGoogle is an advertising company. In the coming years, they'll continue to erode the privacy of Chrome users. I've long since reached the breaking point and switched to firefox. You may not be there yet, but when the time comes, you should make it as easy to switch for yourself as possible.
- SCLeo 5y agoAlright google hater. I have edited my question to also include Firefox's password manager. EDIT: Also, if you don't know, Chrome also supports passwords export/import, so it not any more vendor-lock-in than any other password managers.
- howdydoo 5y agoThe browser built-in options are too limited. I want to do these things: - Use multiple browsers - Sync even if <browser vendor> screws you over and terminates your account - Store things other than passwords. Credit card numbers, PGP keys, SSH keypairs, etc - Backup the database to my own storage Export/import is not enough. If I use Chrome, then import to FF, then add a password in FF; now Chrome is missing some data. You need to be able to sync, not just import.
- AceJohnny2 5y ago
- umvi 5y agoAlgorithmic passwords. Come up with an algorithm a(website, rules) that you can remember and that generates unique passwords per website. Store the rules (length restrictions, special character restrictions, number of times the password has changed, etc) in a google doc or something. Print out your algorithm on a physical piece of paper and put it in a safe place for after you die and people need to access your accounts. People always poop on algorithmic passwords, but so far no one has hacked my brain and gotten the algorithm unlike all these other cloud-based password managers that keep getting compromised. Plus, if my phone or my yubikey or whatever is stolen in a foreign country I'm not SoL because the algorithm is in my brain and the rules are public knowledge.
- marcus_cemes 5y agoSounds like a lot of mental work just to log in. Or... Try a self-hosted password manager, or one that generally has a much better reputation?
- umvi 5y agoMental work vs. physical work, pick your poison. Self-hosted password managers aren't work-free, you have to set them up and get them working across all your devices and maintain them. When I need to log into Nintendo's eShop from my Switch, I use my algorithm. How does that work for a self-hosted super long random Bitwarden password? I'm guessing I need to bring up the password on my phone or something and manually copy and compare it digit by digit into the Switch which sounds like a lot of work.
- denton-scratch 5y agoA self-hosted password manager works for me; I only ever log in with a password from a single machine, so I use a local password manager that is completely unintersted in networks. I don't use a plaintext file, because like most people I have secrets; and because I trust people, not bureacracies (so I don't trust either the police or the government to hold my secrets safely). That isn't going to work for most people, obviously. Most people want to be able to use their credentials from arbitrary machines. I don't have that requirement.
- benbristow 5y agoNot good news - I use Bitwarden, not LastPass, but if you're using a password manager make sure to use 2 factor authentication and this really wouldn't be an issue in the first place. I have my TOTP codes stored in Bitwarden for other services like Facebook etc, but I use Authy as an independent TOTP provider for Bitwarden. 1.5 factor I guess (2FA tokens in a password manager), but works a treat and is very convenient!
- discardedrefuse 5y agoI've considered switching from Authy to Bitwarden for TOTP. But besides the headache of moving all my accounts...I worry about "having all my eggs in one basket". I mean, the purpose of TOTP is to have MULTI factor auth. With both the password and TOTP code in Bitwarden, you actually remove the multi factor part.
- benbristow 5y agoYes - hence the "1.5" factor. My Bitwarden account is protected by 2FA (via Authy - only backup method is SMS - which has become handy at one point when my phone was pick-pocketed abroad in Amsterdam as I'm able to get a replacement SIM card from my operator) but then if you get past that (and the master password) then you've 'pwned' me. It's a trade-off of convenience and security really - I think I'm doing a lot more than the average Joe and feel relatively secure. For the majority of my accounts (FB/Twitter/Instagram etc. etc.) if you get the password you're getting nowhere. Even then using a password manager I have a different password for every service so unless you breach my password manager you've at most made it into one account - if that doesn't have 2FA via Bitwarden. You might struggle a bit moving away from Authy though if you ever want to as it does a lot of 'proprietary' stuff. I had to use a bit of JavaScript to extract my TOTP codes from the Chrome Web App (e.g. for Twitch) otherwise you're unable to get them out of Authy.
- hn_throwaway_99 5y agoRelated question: I find it incredibly stupid that LastPass makes it so difficult to see your complete account login history. The "View Account History" table is beyond awful - beyond making it to filter for, example, failed login attempts, it is limited to 1 page and doesn't let you paginate, at least in my browser. Am I missing something?
- strenholme 5y agoThis is why I rolled my own cryptography to generate random passwords for each site I use. There is a tradition here that we tell programmers they must never write cryptographic code, that they will screw it up, and so on. To which I say: Yes, I agree that writing crypto code if you don’t know what you are doing can cause problems. It should not be done unless you know what you are doing; if you think using MD5 in any cryptographic context is secure, you don’t know what you are doing and shouldn’t be writing code using crypto. If one wishes to write crypto code, the first thing is to realize that it’s very important to choose an algorithm wisely. Use one which has been made by an esteemed cryptographer, has been released to the academic cryptographic community, and has not been broken by said community. Never try to make your own algorithm. Unless you know the difference between differential cryptanalysis and linear cryptanalysis, you have no business making your own algorithm. Even if you do, you have no business making you own algorithm and using it in production without releasing it to the academic cryptographic community so they can analyze it and see if it’s broken in some way you didn’t see. It’s not just algorithms. It’s how to use an algorithm. If you don’t understand why it’s a bad idea to use a block cipher in ECB mode, then you probably shouldn’t be writing code that uses a block cipher in live production. I would not have anyone write crypto code for production use unless they have read Applied Cryptography cover to cover; while somewhat dated (it came out before AES, MD5 getting broken, SHA-3, or post-quantum crypto) it is an excellent introduction to the basics. That said, I have written my own password generator. I have read Applied Cryptography. I know MD5 is broken. I know to random pad plaintext before encrypting it with RSA. I know not to use a block cipher in ECB mode. I have written cryptographic code used in production and it hasn’t ever been shown to be weak or broken; I have revised the code when purely academic attacks have been made against it: I started transitioning from AES to RadioGatún[32] back in 2007 because, while purely academic, I felt the cache timing attacks made it too insecure for me to continue using it in production code. My password generator takes a master password, and it appends it to that master password the name of the site I am visiting, then runs it through a strong cryptographic hash (RadioGatún[32], for the record, which has been around for over 15 years and remains unbroken) for over 500,000 rounds, to generate a secure password. Since it’s not an online service, there is no point of failure where hackers could get in to the online site; since it’s not a browser plugin, there is no point of failure where a browser security hole or a Javascript hack can get at my master password. The code is open source and available here: https://github.com/samboy/PassGen/ https://github.com/samboy/PassGen/
- ThalesX 5y agoI was considering some options to store passwords for both myself and my customers and LastPass was one of the candidates. After thinking about it, I went with Keepass and a single file that is stored on my cloud account. It's working great to be honest and at least I can keep track of my security chain.
- LookAtThatBacon 5y agoReminder to everyone that one of the private equity firms that acquired LogMeIn and took it private, Francesco Partners, holds a majority stake in NSO Group, an Israeli spyware developer.
- yob28 5y ago
- gregsadetsky 5y agoHey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I changed it. What the hell is going on?" https://twitter.com/shift_plusone/status/1475959354742525956 https://twitter.com/shift_plusone/status/1475959354742525956 "Exactly the same thing happened to me last night. They tried again literally minutes after I changed the password to something not used on any other form." https://twitter.com/Pablohere/status/1475966760130125828 https://twitter.com/Pablohere/status/1475966760130125828 "I had this same thing happen to me. Saw attempts yesterday, changed password last night to random generated pass from pass utility and had attempts today again from different countries." --- I saw a few mentions of uBlock origin in yesterday's thread. I definitely might have used it in 2017 (the last time when my compromised LastPass password was used). Could people that received the "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email please reply and confirm whether or not they have the uBlock origin extension installed? The other alternative is for the LastPass extension itself to have been compromised (and to still be..?). There are other alternatives as well (some clipboard sniffing malware for example). Let's try to rule out uBlock if possible. Thanks!
- pfg 5y agoI've been using LastPass for work since mid-2018 as well as uBlock origin for Chrome; no blocked login notification so far.
- gruez 5y ago>I saw a few mentions of uBlock origin in yesterday's thread Statistically speaking it's probably because everyone has ublock origin installed, rather than it getting hacked. It's used by 5M+ users on firefox and "10,000,000+" on chrome. If ublock was really compromised you'd expect widespread reports of account compromise, rather than for only one password manager.
- deleted 5y ago[deleted]
- miketery 5y agoA user posted this comment then deleted it. Is this true? If so. JFC. >>> Take this with a grain of salt. LogMeIn, the owners of LastPass, had a Chinese APT group in their servers for years. They only found out because the attackers started launching unoptimised SQL queries that started killing their database cluster. They didn’t have to report this breach, despite being based in Germany where it’s a legal requirement, because they didn’t have proof customer data was accessed. They didn’t have proof because they didn’t have any logging or auditing. Whatsoever.
- Natfan 5y agoNot saying you're lying, but could you provide a source?
- shakna 5y agoThey _may_ be referring to the 2011 incident [0], which was "unusual network activity". [0] https://www.pcworld.com/article/491164/lastpass_ceo_exclusive_interview.html https://www.pcworld.com/article/491164/lastpass_ceo_exclusiv...
- metabagel 5y agoFor what it's worth, I haven't received a notification of an attempt to login to my LastPass account. My LastPass password is horrendous and for sure not used elsewhere, and even if someone does gain access, I don't store passwords to major financial or email accounts in there.
- bboygravity 5y agoLots of people here recommending to switch to Keepass. I have both Keepass and Lastpass, but the reason I didn't do away with Lastpass yet is basically that it seems to me that Keepass can't do proper form-filling like Lastpass can? I'm talking about: auto filling custom configurable fields, addresses, credit cards, etc. Am I missing something, some addon/extension? My current Keepass setup: Keepass 2 with Keeweb for filling passwords in Firefox on PC and KeePassDX for filling passwords on Android. All Keepass DB files are synced using Syncthing, which works fine.
- discardedrefuse 5y agoI used to use Keepass + syncthing. But I switched to Bitwarden and haven't looked back. You can selfhost your own Bitwarden server if you're extra paranoid.
- GordonS 5y agoI use KeePass on multiple devices, all sync'd via SFTP to/from a database on a cheap VPS, and I'm really happy with my setup. KeePass lets me fill in the username and password fields, and I can configure the names of the fields if KeePass can't figure it out itself. My browser remembers not-so-secret stuff such as my address, and it's very rare I'd want additional form fields managed by KeePass, beyond username and password. That said, I wouldn't be surprised if there was a plugin that does that.
- DantesKite 5y agoWhy I just use Apple’s password manager system. But it also involves completely investing into the Apple ecosystem so I understand why that’s not an option for some. I just enjoy how easy generating new passwords are. Still has some work to do, but they’re definitely on the right track.
- racl101 5y agoThis is why I never liked that 1Password started moving to cloud based, subscription model. I hate that they try so hard to hide the standalone version for which you just paid a fixed price. That's the only way that I still use 1Password. Yes, there's not much redundancy or convenience without the cloud, especially if your computer's hard drive becomes damaged, but if I lose my master password at least it's on me.
- whymarrh 5y ago1Password's cloud offering architecture has a few important distinctions from other offerings. Namely the use of a password authenticated key exchange (PAKE) and a "Secret Key" that is never transmitted to 1Password servers. [1, 2] If you ultimately trust the app for local vaults, there's a case for extending that trust to the cloud offering. [1]: https://blog.1password.com/what-the-secret-key-does/ https://blog.1password.com/what-the-secret-key-does/ [2]: https://old.reddit.com/r/1Password/comments/rp8t02/security_question_and_need_advicehelp_on_choosing/hq353l3/ https://old.reddit.com/r/1Password/comments/rp8t02/security_...
- brendoelfrendo 5y agoJust a heads up: the article mentions that people were reporting a "Something went wrong: A" error after trying to delete their account. I got that error but my email address no longer works to log in to LastPass, so I think the account deletion went through anyway. I haven't used LastPass in several years, anyway, so no loss. For what it's worth, I got an unidentified login email today with an IP in Canada. I didn't see that login attempt in my LastPass access logs, however, so I don't know for sure if they used the correct master password. I did check, and it said that my master password was last set in 2015, so it's possible I was impacted in an older breach.
- errcorrectcode 5y agoKeePass or PasswordSafe, and some means of synchronization. None of these opaque, closed-source "cloud" password managers. Because if you don't control your secrets, then you don't have anything. I don't care if it's a zero-knowledge construction approved by Big Name Cryptography Guy or best intentioned founders since depending on a single service that could potentially hold your secrets hostage, expose them, or forget them would be insane. The end.
- beckman466 5y ago> LastPass so they basically have to change their name now, right? sounds like a broken promise otherwise.
- Schnurpel 5y agoGet Keepass. Put it on an USB stick
- Ikatza 5y agoThis is why I insist on having a standalone password manager, and I refuse to switch to 1Password's cloud solution. I'll sync my master file myself and keep my master password in my head, thank you very much.
- bugstomper 5y agoLastPass posted on their blog on Dec 28 that they identified a problem causing those emails to be incorrectly triggered: https://blog.lastpass.com/2021/12/unusual-attempted-login-activity-how-lastpass-protects-you/ https://blog.lastpass.com/2021/12/unusual-attempted-login-ac... "However, out of an abundance of caution, we continued to investigate in an effort to determine what was causing the automated security alert emails to be triggered from our systems. Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. As a result, we have adjusted our security alert systems and this issue has since been resolved."