6 ms·
Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross
by bikeformind 4y ago
Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality.
not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastPass should shut down the businesses, refund customers, and help them migrate to a new service? You are just not the organization for this job.
- leni536 4y agoThey could might as well dissolve the whole company. Most, if not all of their products are very security sensitive.
- otachack 4y agoAa long as they have paying customers that are ignorant, willing or not, to the issues I suspect they'll keep chugging along.
- mtlmtlmtlmtl 4y agoMore interesting to me is that this shouldn't be an issue, they should just lose out to the competition organically. And yet here we are.
- mhneu 4y agoDuopoly. Plus cost of switching away once you sign up. Network effects and monopolistic (anti-competitive) features allow bad companies to survive today. Monopolistic practices are probably a worse problem today than in the 1920s. In the 1920s governments used regulation to break up huge firms and defeat advantages due to cost of capital (hard to start a new railroad in the 20s because the cost of trains and tracks was just so high.) Today, cost of capital is relatively less important, and things like switching cost and bundling and people valuing their time and convenience are bigger factors. We need anti-trust/government regulation to address those. (For example, in the case of password managers, imagine if there were laws requiring publicized security audits and seamless migration to a new service of customer's choice. A competitor to Lastpass might have arrived by now.
- hackernewds 4y agoMuch of this could be addressed by antitrust enforcement as well as actually having competent lawmakers that understand the products their citizens use overwhelmingly daily. Policymakers barely understand the internet, let alone zero knowledge architecture and encryption Sundar Pichai being asked about if someone is handpicking search results comes to mind, as an illustration
- akerl_ 4y agoAll major browsers offer password management, then there's Apple Keychain, 1Password, KeePass, Bitwarden, and Lastpass. And that's just the ones I could think about while reading your comment. Where is the the duopoly, and who's being forced out of the marketplace due to lack of government regulation of password managers?
- therealdrag0 4y agoCompetition is slow to take effect when there is cost of transition.
- comte7092 4y agoMost economic models of equilibrium explicitly state that they model outcomes “in the long run” for precisely this type of a circumstance. Should a firm with a history of these types of problems lose out to competition organically? Sure, but there is no binary “losing out tot he competition” switch that just gets flipped one day. This is part of the reason why I get so frustrated with the laissez faire mindset/meme.
- mtlmtlmtlmtl 4y agoRight. Crucially, these models don't actually state that the companies that do the best job will win out, but that the most profitable ones do. The problem arises when screwing over the user is more profitable than doing it properly. That's why the tech industry is so ethically corrupt today. There's very little regulation to make dark patterns and sloppy security practices more costly than they are profitable.
- foreverCarlos 4y agoI feel this way but this is wishful thinking. It's more likely that they will transition even more into a gray privacy territory by marketing LastPass to less and less tech-savvy users, eventually bundling it for free with some spammy ad-supported service and/or preinstalled on a phone or laptop (basically, Norton and McAfee territory). The parent company is already not trustworthy, and this breach is the last nail into LastPass as a trustworthy service.
- stainablesteel 4y agoin one regard i'm with this and i do want them to have a fiduciary like responsibility on the other hand i almost see this as similar to the groups of people who swarm towards televangelists, who sign up to donate their last dollar to a millionaire who's scamming them for everything they're worth if you trust it, then maybe falling for it is the best thing for you, to learn this lesson the hard way :/
- peterangular 4y ago> Lastpass has failed their fiduciary duty I get where you're coming from, and ultimately agree. But I doubt anyone at LastPass on the business side agrees - to them this is just another PR snafu. The business continues to chug along regardless of how many catastrophic breaches they go through. I think they see these numerous issues as a cost of doing business vs. having a critical broken product offering. Again I agree, but, I doubt they're going to change their ways this late in the game.
- hn_throwaway_99 4y agoI think the whole LastPass fiasco just shows why everyone wants to get into the SaaS business so bad - subscription revenue is the gift that keeps on giving. LastPass has proven they have no business safekeeping anyone else's credentials. Anyone who cares a modicum about their security will have migrated off. But migrating off is a HUGE pain (people will need hours to update hundreds of passwords), and LastPass's announcement just days before Christmas was obviously done so that your average Joe would just miss it. So LastPass will be able to continue collecting subscription revenue from users who were too busy or just not paying attention to the news, despite the fact that they really should be giving refunds to everyone who depended on their service.
- adornedCupcake 4y ago> But migrating off is a HUGE pain It took less than 10mn to migrate to Bitwarden. What do you mean by migrate?
- bentcorner 4y agoMoving passwords managers is easy, but if you assume LastPass lost your passwords you need to change every password.
- smcin 4y agoBut that isn't migrating, it's "changing all your passwords on all sites you use". Even if you stayed on LastPass(!), you should still do that, right? It's a penalty for LastPass compromising them.
- coffeefirst 4y agoIn theory yes, but the risk associated every account is not equal.
- rhamzeh 4y agoLast time I migrated (many years ago), not all the data was in the export. And the secure notes especially were mostly missing or messed up. I think others have posted on HN that they experienced the same last year when they attempted to migtate. So you may have exported in 10m, but do not assume you got everything, go through the list and make sure everything is there (including verifying the contents).
- sydbarrett74 4y agoYou're not being vindictive. If anything, you're being overly gracious.