9 ms·
Unusual login activity was due to bug
- nunez 5y agoLastPass has been circling the drain for years. I wonder how many users they will lose if 1Pass releases a migration tool..
- greenicon 5y agoMigration exists: LastPass allows a csv export that 1Password can import easily. Just the attachments need to be move manually, as it seems.
- ipiz0618 5y agoI saw the post the other day, and immediately switched to Bitwarden. I guess I was right that LastPass isn't safe enough. Bugs are inevitable but how they spin it shows they don't want to take responsibility (what was the bug??)
- meowface 5y agoOne of the worst-worded security communications I've seen. I'm dropping them.
- Mockapapella 5y agoAlright, I don't like the deflectionary way they talk. Reminds me of this post by Paul Graham: https://twitter.com/paulg/status/1366811342699696129 https://twitter.com/paulg/status/1366811342699696129 I'm going to switch to another password manager. Is there anything that is a drop in replacement for LastPass? ie has a browser extension for firefox, hosted in the cloud (I don't want to be managing a server for this), and has a mobile app. I've heard a lot about bitwarden and keepass, but they're usually accompanied by comments regarding self hosting, which I'm not interested in doing.
- gpm 5y agoBitwarden's hosted service works just fine, you can self host, but you certainly don't need to.
- deleted 5y ago[deleted]
- elFarto 5y agoI'm using Enpass, which mostly works fine. However, they've recently moved to a subscription model which is unfortunate, where-as I bought the Android version a while ago which gave me a 'Premium license'.
- charles-m-knox 5y agoYou can use Bitwarden’s official servers without self-hosting anything at all. I did it for a couple years and it was a great experience.
- shafyy 5y agoI second Bitwarden!
- BOOSTERHIDROGEN 5y agohttps://bitwarden.com/pricing/ https://bitwarden.com/pricing/ You use Bitwarden premium for 10$/y
- quelltext 5y agoWhy not the free version?
- zimpenfish 5y agoI pay for premium even though I don't really use any of their premium features (and could easily host my own) because I like the Bitwarden product and want them to continue as a company (without having to sell out to someone like LogMeIn...)
- riffic 5y agothere's not a lot of quality in the LastPass product, and there hasn't been for a very long time. There are much better competing products to use instead.
- FredPret 5y agoIs there a reason an all-Apple user would want to use a password manager like this?
- smilespray 5y agoI use the Apple keychain and am perfectly happy with it. If you need team functionality you might want to look around for another solution. I ditched LastPass years ago because of crappy UX/UI.
- PeterWhittaker 5y agoI started with LastPass before I made the switch to MacOS ~10 years ago, and despite being all-in on Keychain, I still use LastPass as well (yes, there are times this causes pain). The main reason for sticking with LP is that it is easier to find and display or copy a password in LP than in Keychain, which really isn’t organized for direct human use. Typical use cases, just this week: 1) logging in to Quickbooks after a long time not using it; it is not integrated with either KPad or LP, so hunt and paste it is. 2) logging back in to Dazn on my Roku: I have the enter the password manually, unlike some services that allow me to authenticate via my mobile. Overall, I prefer the near-seamless integration and ease of use of Keychain, but for the edge cases, LastPass has simply been easier to use. (Which is saying something itself, because LP has a poor UI 8-})
- jaburjak 5y ago> Our initial findings led us to believe that these alerts were triggered in response to attempted “credential stuffing” activity They originally said they “determined the activity is related to credential stuffing” [1], then edited the blog post and now they are saying it was just a bug. That sounds like their original story was simply a lie. [1] The original version of their blog post is no longer available, but Bleeping Computer quotes their PR Director: https://www.bleepingcomputer.com/news/security/lastpass-users-warned-their-master-passwords-are-compromised/ https://www.bleepingcomputer.com/news/security/lastpass-user..., below the “LastPass says it's credential stuffing” heading.
- kabdib 5y agoAs an early LastPass adopter, I paid for about ten years of their Premium tier (it was pretty cheap early on). After they were sold the first time, it took them several years to stop billing me every year anyway, so I've still got about a decade of pre-paid Premium. No, they wouldn't refund my extra payments. Strike one. I'm moving to something else now. Other companies might get away with "we fixed a bug, don't worry your pretty little heads." Not this application. Strike two. If this is nothing to worry our PLH's over, I wonder what their response to a REAL security issue would be like. Whatever it is, I want to experience it from a distance. I'm out.
- 5- 5y agoi don't understand why people comfortable with running a vps bother with these cloud services. i use pass https://www.passwordstore.org/ https://www.passwordstore.org/ git sync'd (encrypted) to a $5/month vps that also runs many other things. you could even get a free one from large cloud providers. pass has lots of clients for all kinds of platforms, works really well (how could it not? it's just a thin wrapper around git + gpg) and i don't have to worry about anything like the topic at hand. what am i missing?
- Arainach 5y agoThere's a longer chain of trust and research required here. I need to trust the original authors, the authors of whatever Android client I want, the authors of whatever Windows client I want, and so on. I need to figure out what options are available and why I should trust them and I need to constantly continue doing so to make sure those apps aren't sold to some other party I don't trust. There's no simple mechanism for sharing. Many clients don't support using multiple stores. Even if they did, the UX is never one that I would be able to convince anyone other than a software engineer to use. Single-party centralized solutions offer a simplified trust model and a common auth service makes sharing and recovery much simpler.
- aborsy 5y agoThis set up is much more secure than online password management.
- Arainach 5y agoThe most secure system is one that no one can access or use.
- swaggyBoatswain 5y agoso I tried to cancel my lastpass account, I didn't find an easy way to cancel my subscription. So I deleted my account instead. Still not sure if I'll be hit with a rebill next year though I don't know if this is becoming the norm, it seems really weird that cancelling things is becoming more difficult. I could have sworn cancelling the subscription used to be easier, it seems they've implemented more dark patterns to make this more difficult? Maybe it might be my imagination Also I moved to 1password and it's wayyyy more polished than lastpass. Not sure why I didn't move to a different service sooner
- dang 5y agoOngoing related thread: How did LastPass master passwords get compromised? - https://news.ycombinator.com/item?id=29735132 https://news.ycombinator.com/item?id=29735132 Recent and related: LastPass Login Attempted Activity Blocked – More Information - https://news.ycombinator.com/item?id=29731317 https://news.ycombinator.com/item?id=29731317 - Dec 2021 (12 comments) LastPass says no passwords were compromised following breach scare - https://news.ycombinator.com/item?id=29723319 https://news.ycombinator.com/item?id=29723319 - Dec 2021 (68 comments) LastPass users warned their master passwords are compromised - https://news.ycombinator.com/item?id=29716715 https://news.ycombinator.com/item?id=29716715 - Dec 2021 (313 comments) Ask HN: How did my LastPass master password get leaked? - https://news.ycombinator.com/item?id=29705957 https://news.ycombinator.com/item?id=29705957 - Dec 2021 (508 comments)
- ilrwbwrkhv 5y agoLastpass keeps having issues. This is the second time I heard of a security issue with them. It's not reliable at all and it sucks that our company uses them. Wish we switched to bit warden. Open source is the best when it comes to security.
- andruby 5y ago> Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. A lot of corporate text in this blog. This seems to be the only sentence where they say that the unusual login activity was actually a software error. (PS: I editorialised the title since the actual title is very generic says nothing)
- avsteele 5y agoExactly. What a garbage post from LastPass. What's the error? - was the message which says 3rd party had the correct password wrong? - was it was sent out to accounts other than those for which the 3rd party had the password? - something else?
- windthrown 5y agoAnd even then, "some" of the alerts being "likely" triggered in error makes it sound like quite a few may have been actual security issues.
- deleted 5y ago[deleted]
- vorpalhex 5y agoI hope they intend to provide more proof than their word...
- ochronus 5y agoPoor intern! </sarcasm>
- ochronus 5y agoThis is what I'm referring to, if it's news to somebody: https://www.cbsnews.com/news/hbo-max-intern-test-email-mistake-subscribers-respond/ https://www.cbsnews.com/news/hbo-max-intern-test-email-mista...
- stevebmark 5y agoI also submit Salesforce, an overall terrible infrastructure and company, publicly blaming an individual for their multi-day global outage https://www.theregister.com/2021/05/19/salesforce_root_cause/ https://www.theregister.com/2021/05/19/salesforce_root_cause... instead of firing Darryn Dieken for how they handled the whole thing.
- Croftengea 5y agoWith Bitwarden (which is better, cheaper and more open) I honestly don't see any good reason to use LastPass now given their poor track record of security incidents and naive (not to say stupid) business decisions.
- registeredcorn 5y ago
- Closi 5y agoI subscribe to 1Password which has a similar security model - it's a bit more expensive but I've been very happy with it and it's very polished. (Plus their support is excellent and saved my butt once - I upgraded my personal account to a family account and made my father an admin, after which he decided to 'cancel' his account by deleting the full family account, despite a warning saying everyone's passwords would be permanently erased for the full family. I lost access to all my accounts, however thankfully the 1Password team were incredibly helpful and managed to recover our vault from a backup).
- rlex 5y agoI selfhost bitwarden with rust implementation called vaultwarden, it uses little to no resources and works flawlessly. Compatible with original clients, too. Never looked back.
- kennywinker 5y agoWhere do you host it? I was thinking I’d host it on my NAS and only sync when i’m on my local network. Not sure if that’ll work with the clients? My nas is also it’s too old to have a supported docker package, so that’s a bit of a hurdle there. Pretty uncomfortable with the idea of hosting it on digitalocean or similar… wondering what others do?
- flandish 5y agoI do that but also allow sync when not on local network - via traefik and such as a reverse proxy. However ... I may still turn that off as I have wireguard on everything anyway, so it's super simple to turn wireguard on, sync "locally" and then turn wireguard off.
- kup0 5y agoPosts like this are so frustrating. It's a whole lot of words to say nothing. There's a small mention of the alerts being triggered by a bug/error, but it is surrounded hundreds of words of deflection/spin. Additionally, it is bothersome that absolutely zero detail on this error is given. Given the incredible gravity of the situation (potential of having one's entire password vault compromised), I expect a better response than this
- tryptophan 5y agoNot communicating clearly and pretending like dumb blog posts like this are an answer are both major red flags. I don't understand the thought process behind such legal-ese talk. Do they think we are dumb and can't see through it? Putting this sort of stuff up is just saying "we don't care about you in reality but here is a post saying we do".
- kup0 5y agoI think one thing that really got to me is that the post is by the VP of Engineering, which for some reason gave me an expectation of a detailed explanation of the problem, only to find none The post sounds like it was actually written by either legal or marketing instead
- redis_mlc 5y ago
- thrwaway9871 5y agoSo much this. Don't use any online password managers but with this response lastpass became godaddy for passwords in my book.
- nescioquid 5y agoAnd when the VP of Engineering writes > some of these security alerts...were likely triggered in error one can conclude that they do not know that any of the alerts were triggered in error (else he would have said as much). Some of the VP's statements were likely triggered by the legal department, though I don't know that any actually were. It doesn't exactly shed light on anything.
- bevacqua 5y agoso glad i switched to 1password a few months back
- alphabettsy 5y agoThis is a completely unacceptable lack of detail from a security-focused software provider. Especially given their history of issues and prior poor or misleading communication.
- Havoc 5y agoThey really botched the entire thing. Bunch of people report their unique password gets this message and they investigate credential stuffing? Makes no sense. >some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. "some"? "likely"? They really don't sound like they've got a grip on this
- thrwaway9871 5y ago> Bunch of people report their unique password gets this message and they investigate credential stuffing? Makes no sense. You never worked in IT if you believe what your customers tell you, especially the ones that don't pay you.
- singlow 5y agoThere are probably a baseline of real security alerts for 3rd party credentials per day. For any given user, hers may have been from this bug or it may have been a real attack. If normally there are 200 alerts per day but while this bug was present there were 20k per day, then any given message was likely to have been from the bug, but some were probably real.