4 ms·
>Seems like instead of spending Christmas with my family, I will spend it changing passwords for 100s of accounts. Why didn't you just use decent passwords in
by rosnd 4y ago
>Seems like instead of spending Christmas with my family, I will spend it changing passwords for 100s of accounts.
Why didn't you just use decent passwords in the first place? You were using a password manager, what's the fucking point if your password is still "kittens1"?
This is all on you.
- rolenthedeep 4y agoBecause the password manager storing the strong, randomized passwords is now compromised, you walnut.
- rosnd 4y agoOnly the encrypted randomized passwords were leaked. Unless you knowingly used a bad password for your cloud-based password manager, you're fine. If you did use a bad password for the cloud based password manager, you're the walnut. The whole sales pitch is that lastpass can't fuck you as long as you have a reasonable password protecting your vault.
- rolenthedeep 4y agoYour encrypted data is compromised, it is in the hands of an attacker who really wants to decrypt it. You're pinning all of your digital security on encryption holding against an active attacker. What if there is an undiscovered or undisclosed vulnerability in the encryption? What if last pass isn't using encryption as secure as they claimed? What if the attacker just gets really lucky and your password is in the first thousand bruteforce attempts? Same rationale applies when a random website gets hacked and leaks their password database. Yes, your password is salted and hashed, and hypothetically unrecoverable. But you change your password anyway. You have the option to guarantee your accounts are secure, or do nothing and hope it will be fine. There's a lot of situations where your vault might be decrypted. Sure, they're all pretty unlikely, but the risk is not zero. Changing your passwords does make that risk zero. You're already fucked. LastPass lied in their sales pitch, and they released a bunch of your data unencrypted. Having absolute trust in their encryption as your sole layer of security at this point is incredibly reckless and stupid. You don't know that your master password isn't uncompromisable, you're trusting the company's sales pitch, and they've already lied to you. There is no reason at all to assume your vault will be secure forever.
- rosnd 4y ago> Your encrypted data is compromised, it is in the hands of an attacker who really wants to decrypt it. You're pinning all of your digital security on encryption holding against an active attacker. Well, yeah. Just like you leak your encrypted password to the internet every single time you log into a website. >What if there is an undiscovered or undisclosed vulnerability in the encryption? lmao, if aes-256-cbc is broken then LastPass is probably the least of anyone's concerns. This happens to also be one of the more difficult AES modes to screw up. >What if last pass isn't using encryption as secure as they claimed? Shit, if that was a real concern you would have to be a complete idiot to use LastPass in the first place.
- paulpauper 4y agoAES CBC not broken, but it's likely LastPass implementation of AES was bad , such as bad RNG or other possible problems.
- rosnd 4y agoWhy do you think it is likely? That's a very strong claim. > such as bad RNG How could that be a problem? The attacker doesn't control your passwords. How would you exploit a known IV as an attacker in this context?
- paulpauper 4y agothere are many ways the encryption could have been implemented badly. a weak RNG is one
- bbbbb5 4y agoDo you actually know anything about this subject, or are you just speculating?
- paulpauper 4y ago
- gillesjacobs 4y agoRest assured I have a strong master password that would take in the order of 10^2 years to bruteforce, not taking any chances though.
- rosnd 4y ago[flagged]
- Bud 4y ago[flagged]
- rosnd 4y ago[flagged]
- deleted 4y ago[deleted]
- Bud 4y agoOne has to wonder what would prompt someone to issue such a violent, random, unhinged threat, in response to a simple question. You're clearly here propping up LastPass, you don't seem to have a particularly strong argument, as noted by many, you have no substantial history of doing anything constructive on the site, and now you're threatening SWATting me? I have a better idea: stop the childish, dangerous, violent, criminal threats, and just answer my question, instead. Do you feel big and powerful issuing threats from behind a cloak of anonymity? Go for it.
- bbbbb5 4y agoYou came looking for a fight, don't act so surprised when you get one. Go verbally attack random people on the street, see if you don't come home with a bloody nose. If your comment hadn't been so obviously in bad faith, you'd have received a different response. A 7 months old account that has only mentioned LastPass within the past 24 hours was obviously not created to systematically defend LastPass. In fact, the account you were replying to hadn't even been "knocking down any criticisms of LastPass" as you accuse. There's not a single comment made by "rosnd" you could reasonably describe as defending LastPass.