41 ms·
LastPass breach gets worse
- jerry1979 4y agoIs there a reason why I shouldn't just store my passwords in Firefox?
- thescriptkiddie 4y agofirefox and other browsers are just not very good at password management. it does seem like a feature that should be built in to the browser.
- jerry1979 4y agoI'm confused and not trying to be argumentative, but if I enter my passwords into my browser anyway, why not store them there?
- intunderflow 4y agoThe fact they're drip-feeding how bad this breach actually was is terrible enough and yet their entire product is built on nothing but trust. Part of me wonders if this was an intentional strategy: Downplay during the initial media round then very quietly reveal this was a worst case scenario. Personally I'm never touching them again - anecdotally everyone I know who was an individual customer has migrated away and inside companies lots of engineers have stopped adding new passwords.
- blitzar 4y agoIf drip-feeding the details is an intentional strategy it is a stupid one. Keeping the negative story in the headlines for a day longer means it will reach more people and draw more attention.
- code_runner 4y agoThey’ll only piss off the people paying attention to every drip.
- ryanjshaw 4y agoNot just that, this drip feed of information makes formulating a proper response very difficult. If, for example, you deleted your account after the first report in August (a rational decision), you have no way of checking what iterations setting you had, now that people are talking about it. It's also unclear whether you will receive any data breach notifications detailing the exact impact to your data, since your account is now deleted - do they keep a history for "post-fact" situations like this? And of course, if you didn't keep a backup of your passwords before deleting your account, you'd have to reset everything to be sure. Terrible, awful company with no respect for their users.
- jolmg 4y agoThere's not really any benefit to deleting the account other than forgetting they're untrustworthy and accidentally using them in the future. I would think it's better to change all passwords (at each service, not at lastpass) and leave the account at lastpass active, precisely to be in the know for such things in the future. That's unless I'm misunderstanding something about their service that makes it better off to delete the account. I've never used them.
- dividedbyzero 4y agoThey still have a list of accounts, email, usernames, even if the passwords have been rotated, plus whatever happens to be in secure notes and the like. Deleting the account is really easy (has to be for EU customers) and they're obliged to delete all data they hold on the user (under EU law), so I don't see any reason to let that kind of data sit around on an untrustworthy party's servers. I certainly won't need a reminder that they're untrustworthy.
- jolmg 4y ago
- prepend 4y agoWhen it comes to important stuff I think it’s important to trust no one. I’m sure LastPass tried really hard to protect data. But everything fails eventually. If there’s things that are life threatening or financially devastating then I don’t think I can afford to audit people sufficiently to trust them with the info. This is also why I can’t imagine ever using Plaid/Mint/etc that require my bank credentials just to do minor stuff like make payments or read transactions. These password managers are in a tough spot market wise as they aren’t smart enough to secure super important stuff and for unimportant things, iOS/chrome password management is pretty good. I don’t mind if my audible account gets rooted, but it would be very bad if my bank or brokerage gets rooted.
- mdla-hn 4y ago"but it would be very bad if my bank or brokerage gets rooted" Yup. I put everything in the password manager except primary email and bank/brokerage.
- sofixa 4y ago> This is also why I can’t imagine ever using Plaid/Mint/etc that require my bank credentials just to do minor stuff like make payments or read transactions. That's the fault of banks. We need open banking, with APIs using OAuth or similar with scopes or some way for per-action/item access.
- ak217 4y agoThings are improving bit by bit. BofA and Chase both have OAuth and pretty granular permissions now. Citi and Wells Fargo have OAuth APIs too, though I haven't worked with them personally. That's the top 4 consumer banks, but many credit unions are stuck in the past. Credit unions in general need to wake up about how far behind they are in IT investment, and use a common IT vendor to modernize.
- rxyz 4y agoAlready exists in EU.
- usrusr 4y agoAnd each drip paints a bigger crosshair on the back of keypass wrt supply chain attacks (the only angle where keepass isn't inherently better than others). I wish lastpass all the best in terms of improving their communication!
- verisimi 4y agoI'm now expecting a raft of these sort of leaks. This sort of thing, will all encourage us to 'naturally' move towards a government backed, biometric solution. Which will of course be phone based, will hold your wallet, id and medical information, and will be provided to us by kindly corps such as twitter, google, apple, microsoft, meta, etc.
- medellin 4y agosurprisingly the government based sites i use let me use email for 2fa which is better than phone since i can add 2fa for my email as well. It’s the banks that keep insisting i use a phone for 2fa. I have moved away from ally because of this
- lolinder 4y agoI don't think it was intentional: this is one of those places where ripping the band-aid off is far better than slowly dragging it out. The drip-fed reveal increases the raw number of headlines about the breach and drills the idea "GoTo is bad at security" into people via spaced repetition. If they said "our entire company was pwned" on day one, they would have had their day in the media and by now only HN would still be grumbling about it. I think what's actually happening is that they're just really bad at security. Either every few weeks they discover something new or they still haven't successfully locked the attacker out.
- LocalPCGuy 4y agoI do think they are being very intentional in how they release and frame things, and one of the things dripping it out can do also is produce some level of fatigue on reporting it. It definitely seems like they knew some things before it came out - some people have looked at changes to their site and there are new or updated marketing changes that in retrospect seem very correlated to what we're learning now. Not definitive proof, but very concerning. I also think you are correct to a point, they are really bad at security so it is also possible that some of these things are just coming out also.
- aggie 4y agoThis assumes everyone sees all the headlines. This approach is very bad for people paying attention, but the type of people to pay attention to this kind of news would probably be unwilling to go near LP again if it was revealed all at once. Their play might be to assume the initial headlines get the most coverage so soften the message there, then wait for a general audience to tune out and reveal the worst parts.
- arp242 4y ago> Part of me wonders if this was an intentional strategy: Downplay during the initial media round then very quietly reveal this was a worst case scenario. Seems like a poor strategy. This is like an infected wound that keeps on festering. A turd that will not flush. A house guest that won't take multiple hints it's time to leave. Better to just get it over with in one go; next week the news cycle will be something else and it will be over; now it's in several news cycles again and again.
- Denzel 4y agoCan confirm. Migrated from LastPass -> 1Password last month.
- altacc 4y agoWhilst not good, this seems to be bad news for some GoTo products but not specifically Lastpass: > a threat actor exfiltrated encrypted backups from a third-party cloud storage service related to the following products: Central, Pro, join.me, Hamachi, and RemotelyAnywhere Lastpass is a GoTo product, so in general the multiple security breaches undermine confidence in all their products. Your password manager is not something you want low confidence in.
- snehk 4y agoGoTo has been bad for a while. I recently sent their team a support ticket for their GoToWebinar API (API response contained completely different/wrong data). They said it's not that much of a problem and said they weren't gonna fix anything. Hilariously bad.
- lotsofpulp 4y agoI was under the impression LogMeIn (GoTo’s previous name) already was known as malware many years ago when they bought Lastpass. Lastpass was the first password manager I used, and when it sold to a scummy company like LogMeIn, I learned my lesson to just stick with KeepassXC.
- avhception 4y agoKeepassXC + unison is the best combo for me. I'll never let some cloud service lay their hands on my passwords.
- bogomipz 4y agoWhat does unison provide in this strategy. I remember the old Keepass, is KeepassXC the next generation in this?
- SCdF 4y ago> I remember the old Keepass, is KeepassXC the next generation in this? It's the same database format, KeepassXC is a fork of KeepassX with more active development. https://superuser.com/questions/878902/whats-the-difference-between-keepass-keepassx-keepassxc https://superuser.com/questions/878902/whats-the-difference-...
- ThatsAllForNow 4y agoI have recently moved away from lastpass onto 1password and find myself with some 1000+ credentials that I will now have to change. Been working though the list and made a small dent of 50 accounts so far... There must be a quicker way to do this?
- fckthisguy 4y agoWe should introduce an industry best practice for account management. A "/.well-known" url for changing passwords would make this trivial to do in bulk with a password manager.
- monsieurbanana 4y agoNothing could go wrong with having a way of hitting millions of websites at once with a 0 day exploit :)
- dns_snek 4y agoThe functionality provided by such an API could be limited to disabling the account until the password is manually reset given that the client provides a valid email and password. The blast radius for that would be pretty small. I don't use 90% of the entries in my password manager on a monthly basis so anything that allows me to delay the password change on hundreds of accounts until I need to use the account again would be valuable.
- devnullbrain 4y agoObscurity is security, as the saying goes.
- deleted 4y ago[deleted]
- handerz 4y agoIsn’t the saying, “security through obscurity is no security at all”?
- 2Gkashmiri 4y agoas a keepass user, i cannot be more happy. contrary to popular belief, maintaining a file synchronized is not difficult. This "breach" is just as good as assuming google or apple or any other bitwarden or any other cloud password manager is broken because they all work in the same way "we promise to keep it secure". this is different from storing a keepass file on the same google cloud because an attacker has to break into your cloud login first, then hope to find your keepass file. Then try to break that file. as opposed to breaking into your google account and seeing the passwords or by breaking into bitwarden or 1password or something else. if someone has a login to 1password of 10 people, there is good reason to assume there will be passwords stored.
- somezero 4y agoI was a long time keepass user but moved to Bitwarden. My problem with keepass is the low quality and often poorly supported closed source clients that you get on mobile.
- 2Gkashmiri 4y agoi dont know about you but i have been using keepassdroid and another client from F-droid for years now..... maybe this was because as you said " low quality and often poorly supported closed source clients"...
- lotsofpulp 4y agoStrongbox works great for me on iOS and macOS.
- Jamie9912 4y agoMe too. Yes I paid for it. Yes it works extremely well.
- totetsu 4y agoThe occasional times I haven't been able to log into my bank because I was on a computer that didn't have my kdbx file, or the small worry I have of keeping it up to date in multiple places while transitioning my main system.. are no bother compared to constant worry that someone might have my logins because of some security breech.. That said I just give apple everything when on that echosystem. ¯\_ (ツ)_/¯.
- Toutouxc 4y agoWhat does everyone think about just using Apple's Keychain for everything? Seems that for Keychain the most serious threat is actually being rando-banned by Apple and losing access to my stuff.
- andybak 4y agoOne would have to exist solely in the Apple ecosystem for this to be viable, surely? Surely most people on HN have at least one device that isn't Apple!
- crooked-v 4y agoThere's a Windows app for iCloud to show passwords, but it's very basic.
- Toutouxc 4y agoYes, it's only convenient on Apple devices. But it's still doable if you don't access that much stuff on other devices, e.g. when I need to access something on my Windows computer (which basically exists to run Microsoft Flight Simulator), I just manually retype passwords from my iPad.
- KyleBerezin 4y agoI'm not sure about apple's cloud stuff, but the keychain is an actual just a file on your system. It is password protected, but it is just your login/sudo password (depending on which file it is). I just had my keychain corrupt last night while I was testing the SecItemAdd API. So keep that in mind, maybe make backups. I was pretty shocked that you can corrupt the keychain using just the API, the entire security process started to lock up too. I had to (manually!) delete the entire keystone and start from scratch. Luckily I don't rely on it much. It is worth noting that after you back it up to a remote location, it may not be a very secure concept anymore.
- seanieb 4y agoWhat happens to the serial security recidivists? Where are the regulators? LastPass has had security incident after security incident, how are they still allowed to operate?
- Alifatisk 4y agoThey failed to secure sensitive user credentials, that must’ve broken some law. Also, people can store notes on lastpass, did those get leaked too?
- HPsquared 4y agoWould this sort of thing fall under GDPR?
- Alifatisk 4y agoAnd probably CCPA in that case?
- poglet 4y agoYes "that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data." https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/ https://blog.lastpass.com/2022/12/notice-of-recent-security-...
- Alifatisk 4y agoI would not be surprised if such sensitive details could ruin someones life, and that is now in hands of a bad actor.
- briffle 4y agoI think at this point, they need to get purchased by Experian, so they can combine into such an ugly mess of problems, that identity laws get overhauled.
- 4y ago
- deleted 4y ago[deleted]
- andjelam990 4y agoWow! This should definitely not be downplayed, they have lost users' trust for good.
- Alifatisk 4y agoI am so happy I left and destroyed my account before this breach and went with Bitwarden. They showed red flags a long time ago!
- matesz 4y agoSame here but unfortunately have done it 1 month ago. This breach helped me learn why it is important to have strong passwords.
- thenickdude 4y agoThis doesn't necessarily mean you're in the clear, as we don't know what the age of the backups that were stolen are. If you were a LastPass user at any point you should rotate all the credentials that touched that service.
- Alifatisk 4y agoYou’re completely right. I’m slowly changing password on every important account. But I had sensitive notes too, so IF my details got leaked then I am ruined either way.
- nickjj 4y agoIn the comments on Reddit someone linked to a podcast where they broke down what this really means in terms of how "secure" your leaked encrypted vault is. The TL;DR is even with 100k+ iterations of PBKDF2 an attacker can crack a password with 40 bits of entropy in about 71 days if they had access to 200 modern GPUs. For comparison if there were only 1 iteration instead of 100k the same type of password could be cracked in 61 seconds. 50 bits of entropy changes things a bit. Now it takes 1 year instead of 71 days but if you're a high value target they can just ramp up the number of GPUs to reduce the time. The difference between 40 and 50 bits of entropy for a password look like this: 40 bits: !climb33 50 bits: ClimbS1@ 40 bits: any 9 lower case letters 50 bits: any 11 lower case letters The takeaway I got is you're probably ok if you have a really good password (150+ bits) with 100k+ iterations but if I were using Lastpass personally (which I'm not) I would absolutely re-roll everything and never use the product again. I personally use a command line tool called `pass` which stores everything locally. This story interests me though because I am mildly involved with someone who is using Lastpass and I suggested they re-roll everything. I'm happy to see someone did the math, it's the exact information I wanted to know. The podcast show notes are on page 6 which has more numbers and practical examples: https://www.grc.com/sn/SN-905-Notes.pdf https://www.grc.com/sn/SN-905-Notes.pdf
- philjackson 4y ago`pass` is lovely, but don't you need your passwords on your phone when you're out-and-about?
- rsstack 4y agoThere are apps for mobile devices, some sync with a GitHub repository (which you should make private): https://www.passwordstore.org/#:~:text=password%20(OTP)%20tokens-,Compatible%20Clients,-The%20community%20has https://www.passwordstore.org/#:~:text=password%20(OTP)%20to... The contents of the GitHub repo are of course encrypted with your own key, which you need to manually sync to your other devices.
- Kwpolska 4y ago
- traceroute66 4y agoMakes me pleased to be a loyal Zetetic Codebook[1] (née STRIP) customer. The thought of storing my passwords on a web/cloud-based service always struck me as the dumbest thing anyone could do as it would be only a matter of time until such a service was hacked. I started using Zetetic after learning about them via a 2012 Black Hat conference presentation[2] where they took a bunch of password managers and STRIP came out on top. I figured if it was good enough for them, it was good enough for me. The product has only got better and better since 2012 (note that the presentation PDF is out of date in terms of security, they have of course changed hash and substantially increased rounds ! see their website for detail). Their support is first-class too. [1] https://www.zetetic.net/codebook/ https://www.zetetic.net/codebook/ [2] https://media.blackhat.com/bh-eu-12/Belenko/bh-eu-12-Belenko-Password_Encryption-Slides.pdf https://media.blackhat.com/bh-eu-12/Belenko/bh-eu-12-Belenko...
- avhception 4y agoNo Linux support =/
- neandrake 4y ago+1 for Codebook. I’ve been using it for ~5 years and haven’t had an issue, I feel secure in managing where my vault is stored and haven’t had issues with syncing. It’s a one-time fee per device type - I paid for iOS, macOS, and Windows without any hesitation. Additionally their support is really good. They added a feature on iOS version (and Android I assume) which copies the TOTP when you use codebook to auto fill a login. However it cleared the clipboard when the TOTP code expired which was sometimes too soon - I suggested they add a buffer of ~15-30 sec which most TOTP validators allow, giving the user a bit more leeway in pasting it. They added it in the next version. Some cons though: They do lack Linux support. Syncing is manual (I think they mentioned the next big update will make it more automatic), and there aren’t any family/team sharing capabilities. For these reasons I would really only recommend it for tech-savvy individual use. I’ve recommended it to a few colleagues and they have had great experiences and continue to use it for several years now.
- traceroute66 4y ago
- sureglymop 4y agoHow many more times can we shout it. KeePass with Syncthing.
- twobitshifter 4y agoI use strongbox pro, which is an iOS keepass app, and keep it on iCloud Drive. It’s a simple no fuss solution.
- chinathrow 4y agoAs a long time KeePass user, I throw in KeePassXC. Much more polished.
- sureglymop 4y agoFor sure! I meant KeePass the database format :). I use KeePassXC also.
- irrational 4y agoWhat is Syncthing? A thing that syncs?
- vageli 4y agoYes, it's a service to keep files on your devices in sync with one another. https://syncthing.net/ https://syncthing.net/
- npteljes 4y agoPeer to peer dropbox, kind of.
- usefulcat 4y agoA self-hosted replacement for Dropbox.
- marcosdumay 4y agoHum... No, it's not a replacement for Dropbox. It solves issues Dropbox doesn't (like dealing with segregated networks), and doesn't solve issue that Dropbox does (like sending files to people).
- ikekkdcjkfke 4y agoWhat idiot transfers all their passwords to a small private company
- Freak_NL 4y agoWhat idiot transfers all their passwords to any private company?
- jonsolo 4y agoWhat idiot keeps all their money in a bank instead of securing it themselves? Sometimes it’s preferable to pay the professionals, especially if you’re not an expert. I’ve recommended LastPass to my grandparents for years because it’s better than using their grandkids’ names as passwords everywhere.
- ejb999 4y agoDo password managers have FDIC coverage? banks do. Big difference.
- kossTKR 4y agoI use iCloud keychain - has there been any reason to suspect this is an idiotic move, especially when coupled with twofactor auth on important sites? Really important stuff is of course handled in other ways..
- jonplackett 4y agoOne word of caution - do you realise that anyone with your iPhone + PIN code can access all those passwords? All you have to do is go to settings > passwords and enter the pin and there they all are. Sao if you use this, have a really good iPhone pin!
- traceroute66 4y ago> have a really good iPhone pin iPhone PIN ? Say what now ? Only fools use PINs. iPhones have supported keyboard entry for passwords for a very very very very long time now. And more recently, TouchID and FaceID, of course. You can also configure iOS to erase after n incorrect entries. At this point in time, you get what you deserve if you still use numeric PINs.
- Weryj 4y agoFrom paying customer, to deleted account.
- prepend 4y agoWhat’s the best way to delete an account? Overwrite all password values? Wait a month, overwrite again, wait a month, delete? It’s hard to tell what’s sufficient to reduce risk of someone who breaches in the future will use my data. I doubt LastPass deletes my data when I delete my account. I even wonder if to comply with GDPR, they just disassociate the data from me so it can never relink, but keep the data so it can be used, sold, or rented.
- sethammons 4y agoBest is to rotate all your stored passwords and not store the new ones in lastpass, delete all the items, and change the lastpass master password. Check any notes for sensitive info before overwriting and then deleting the entry and assume someone else will read what you had there.
- bigiain 4y ago> What’s the best way to delete an account? Overwrite all password values? Wait a month, overwrite again, wait a month, delete? The only sensible approach is to change every password on every site that you’ve ever stored credentials in LastPass for. Any attempt to change the passwords is just hoping hay their backups are better secured than their prod database (they are almost certainly not), and also that the data wasn’t popped before you changed them (which they almost certainly were, probably multiple times). Delete your account, but revoke/update all those passwords asap as well. Since the site/url and email addresses were not encrypted, I’d be changing the email address on at least critical accounts as well where I can.
- loudmax 4y agoFor important accounts you should probably update your passwords. Assuming you aren't reusing passwords, you shouldn't need to track down every online store you once bought something from. But your should consider updating your passwords for bank accounts, Paypal, Amazon, Google and whatever else would be a major headache if it were compromised.
- bjt2n3904 4y agoAnd my stance against "cloud based password managers" -- and really, paid password managers -- is vindicated. Never! I have evolved a little on using software to track passwords though, and I'm using Unix Pass quite happily now. It's just a short bash script that is very readable, and uses GPG as a backend. Edit: What's doubly nice is how elegantly it scales from a simple folder of gpg encrypted text files to a multi user synchronized git repository on everyone's phone. But all that's optional, and only requires you to trust other tools that you already regularly depend on.
- gsk22 4y agoThat might be fine for the HN crowd, but cloud password managers are still the best solution out there for the typical person.
- ransom1538 4y agoCan someone explain it to me like I am 5 years old. Why would I take all my passwords, centralize them and place them onto a 3rd party site? Why is this security best practice?
- ejb999 4y agoIt's not.
- sofixa 4y agoIt's a recommended practice (I hate the term "best", everything depends). Why? Quite easy actually - having random passwords is better than reusing the same everywhere. Random passwords are impossible to remember by a regular human, hence you need a password manager. Using a local file as a password manager poses a usability/availability risk (you have to sync it yourself, you have to back it up yourself, you have to make it available on all devices without putting it at risk, you have to secure it, etc.), hence cloud-based password managers are better for the average person, especially coupled with MFA for critical accounts (banks, email, etc.). If you're a highly technical or highly security conscious person, or under threat, the equation changes of course, but the recommendation for a cloud-based password manager isn't meant to apply to everyone, just most people.
- daveoc64 4y agoBecause using a password manager as intended solves several well-known and very common password-related attacks like credential stuffing. A password manager makes it possible for the average person to have high length, completely random passwords for each and every site, and to have them available on all of their devices. That makes it a lot less likely that people will do bad things like re-using passwords, having short passwords, or writing them down. My LastPass account would have been in the breach, but as my vault was protected with 151,000 iterations and a very long password, it'd take an attacker a long time to be able to get to my Hacker News password, which they'd find was 50 random characters long and looked something like jtES^cqhPj3@&rgPW5#frmDpf#^gGyf3eRoPH#fUZWJQGNFJvW They'd also find that I've since changed it!
- loudmax 4y agoYou have to consider what the security landscape looked like when LastPass got going in 2008. The common practice for non-technical people was (or still is) to reuse the same password everywhere. A password that's really easy to remember like "p@$$word". In this context, the common alternative to LastPass isn't best practice, it's worst practice.
- Gregoriy 4y agoMaybe an overkill, but i use cryptomator, which encrypts the files, the files are synchronized with nextcloud of remote location, but i suppose you can use whatever software you want. Inside that there is a https://keepassxc.org/ https://keepassxc.org/ It works on a phone too, cryptomator open vault with finger, open keepassxc with finger, well not the quickest way but it will do. I still have some useless passwors in chrome but for not important stuff.
- iillexial 4y agoI use KeepassXC too, and Dropbox for database sync. Probably not very secure, but I store root password only in my head, and secret key offline. Never used mobile client though, not sure if they can be trusted.
- hnrodey 4y agoSucks that LastPass has these significant problems. From purely a product perspective it's pretty good. I used it for years quite happily as it kept myself and wife in sync with all of our accounts/passwords across all of our devices and browsers. LastPass is one of only a handful of products that truly works on virtually all platforms and browsers. Windows and Mac, home and corporate devices, mobile, you name it.
- bigiain 4y ago> LastPass is one of only a handful of products that truly works “Truly works” except for the one critical feature that is the sole reason people use it. It does not keep your passwords safe. Doesn’t matter how nice their Windows app is, or how smooth the animations on iOS are, or how well it’s browser plugins work. It fails at its only real task, safely storing your credentials.
- pragmatick 4y agoThe new addon for Firefox doesn't just work but instead is unable to match the current URL to entries. You have to switch off the "Advanced autofill" which is automatically turned on nearly every day. The android autofill doesn't "just work" but that may Android's fault.
- coder543 4y ago1Password works everywhere too, and it works much better than LastPass from everything I've heard and seen. 1Password also actually encrypts your entire vault, and it uses a strong, generated secret key in addition to your password, so even if a user does not use a strong password, their vault would still be very hard to crack.
- ranting-moth 4y agoA good advice I was given a long time ago and I have since followed: When you need to admit a mistake or apologize, get it all out and be truthful about it. Effectively get it over and done with. People do appreciate honesty, but will strike back with retaliation if they find out you only appeared honest. Telling a half truth is no better than lying.
- sethammons 4y ago"If you have to eat crow, best to do so while it is warm."
- andrewmcdonough 4y agoOne of the most frustrating things about the LastPass leak is that they still haven't provided all the information needed to determine whether a customer is at risk. For example, it's clear backups were stolen, but they won't say how old the backups were, or what their retention policy is. So even if you changed your password to a stronger one, with more rotations, it may be that the attacker got hold of very old backups with weaker security. I've asked their support team for information about time windows of backups stolen, if they have a retention policy and whether it was adhered to, but they won't share that information. Instead we are left with a blog post that is more than a month old, no recent updates, and questions remaining unanswered. I'm a paying 'enterprise' customer, and they are meant to be ISO270001 compliant, so a retention policy should be a pretty simple thing to share.
- bombcar 4y agoEven if you change all your pssswords NOW you’ve still had the metadata of where you have accounts leaked.
- ShredKazoo 4y agoIn principle, your passwords might be stored as a JSON blob encrypted using a key derived from your master password. In which case that metadata could still be secure. I doubt it though.
- lolinder 4y agoLastPass already admitted that the metadata was all leaked. Usernames and passwords were encrypted, but all else seems to have been in the clear.
- ThunderSizzle 4y agoBased on what happened to my wife, if the password was encrypted, breaking it was trivial
- aledthemathguy 4y agoif i closed my LastPass account a year ago (migrated to a different pass manager), am I in a problem?
- toomanyrichies 4y agoI just migrated over to 1Password and deleted my LastPass account. Better late than never, I suppose. It was surprisingly easy- for all of LastPass's faults, at least they don't use shady vendor lock-in practices (like making data export needlessly difficult). And 1Password has a LastPass-specific import page, which made the migration dead-easy.
- throw_pm23 4y agoHonest question: what's the point of password managers? By migrating from one to the other, aren't you exposing yourself to the exact same risk?
- tomsmeding 4y agoThe point is to allow oneself to use a different password for each website, and strong ones at that. The time required to memorise a large number of strong passwords is significant, and a password manager alleviates that.
- throw_pm23 4y agoWhy not store them locally (in a file on your laptop) or on a piece of paper in your wallet?
- foundart 4y agoWhat happens if your laptop is stolen or its hard drive fails or you lose your wallet?
- throw_pm23 4y agoThe same thing like when you lose your car-key or any other valuable.
- x86x87 4y agoLol. A piece of paper with 200 passwords?
- xwdv 4y agoWe’re finished with LastPass. We are actively moving employees away from it and will never touch their products again.
- this_steve_j 4y agoAccording to https://layoffs.fyi https://layoffs.fyi a company named “GoTo Group” based in Indonesia recently laid off 1200 employees, however they appear to have no obvious relation to “GoTo Company” which owns LastPass. Under the circumstances, a staffing shakeup in the CISO office sometimes occurs in companies after this kind of accident. Does anyone know what the situation is like inside LastPass headquarters? After a previous LP incident I noticed a number of senior security officer positions advertised on the LastPass Careers site.
- uyaij 4y agoThat "GoTo Group" was formed when Gojek and Tokopedia merged [1] and isn't related to Lastpass. [1] https://en.wikipedia.org/wiki/GoTo_(Indonesian_company) https://en.wikipedia.org/wiki/GoTo_(Indonesian_company)
- 2OEH8eoCRo0 4y agoI use KeepassXC with password + yubikey challenge response. My mental model is that this encrypts my database using my password combined with the yubikey response. With this configuration- it appears that I should be able to put my database anywhere in the open. Which leads me to my point: If the password manager is properly used then why do we care if the encrypted databases were leaked?
- AmalgatedAmoeba 4y agoNot all the contents of the databases were encrypted.
- garganzol 4y agoKeepass encrypts the whole database. There are no unencrypted parts, in contrast to some other password managers.
- bogomipz 4y agoFrom the top of the reddit post: >"For those that may not have seen it, since instead of a new post they “updated” the one from November…Looks like it’s even worse than they first let on" Can anyone say if they notified their customers that they had updated the original post?
- d23 4y agoFirst rule of security breaches: it’s always worse than they let on.
- ChoGGi 4y agoUpdated a blog post from November in January, classy move. Not to mention https://en.wikipedia.org/wiki/LastPass#Security_incidents https://en.wikipedia.org/wiki/LastPass#Security_incidents
- xwowsersx 4y agoGoTo considered harmful
- d23 4y agoThis is amazing.
- ubermonkey 4y agoIt sure sounds like they're doomed.
- finnh 4y agoAfter using LastPass for years, this breach led me to do something I should have done long ago: remove my bank account & email account passwords from it (and change them, of course). My wife did the same thing. At some point I'll probably switch password managers, but the basic realization was that those passwords are qualitatively different than the rest and should never, ever be trusted to any password manager. So now I remember ~3 passphrases, instead of 1, and sleep much better at night.
- ericpauley 4y agoI disagree, mostly because the password manager is more than just a place to store passwords. The origin binding also prevents you from typing the password on the wrong domain. For many people they’re probably more likely to get phished for a memorized password than pwned for a managed password.
- hunter2_ 4y agoI wonder if there's an app/extension that streamlines remembering/autofilling usernames but not passwords. I doubt many people would be into it, but it would be the best of both worlds for the case you describe, I think. Or simply a personal allow list of origins, with a happy green indicator prominently overlaid onto login forms on those origins you've saved -- doesn't even need username storage. Maybe even a community-sourced allow list, but that would need some seriously trusted management (including purging upon domain registration expiry/transfer) but that would mostly duplicate the domain warnings that browsers already offer, anyhow.
- deleted 4y ago[deleted]
- criddell 4y agoThat's a good point that I hadn't thought of before. I used LastPass for years and switched to BitWarden a couple of years ago. I did delete my LastPass account after switching, but I have zero confidence that they actually deleted my data. Fortunately, my master password from back then is long and complicated.
- jonnycomputer 4y agoA reddit thread about another company. Can anyone link me to where the LastPass announcement changed?
- drunner 4y agohttps://www.goto.com/blog/our-response-to-a-recent-security-incident https://www.goto.com/blog/our-response-to-a-recent-security-...
- abfan1127 4y agoWhat product supports Cross Platform (minimum of Windows, Mac, iOS) that is easy to setup for non-technical people?
- gopkarthik 4y ago1password. In addition to above, it has Linux support & browser extensions
- abfan1127 4y agofrom a position of ignorance, why/how is 1password better?
- whatch 4y agoSurprisingly, Apple built-in password manager. They have Chrome extension for windows (but not for Mac OS Chrome, unfortunately)
- softwaredoug 4y agoJust make sure people with password access update their iPhone passwords to be strong. With FaceID, this shouldn't cause too much incovenience.
- rishabhkaul1 4y agoIf I have 2FA set up, would I still need to change the passwords (despite the leak)?
- coder543 4y agoIf everyone knows the password, then it's really just 1FA at that point. If you want it to remain 2FA, then yes, you would need to have a new password.
- thenickdude 4y ago2FA bypass bugs on websites are common, e.g. this PayPal bypass that stemmed from them allowing their own app through without 2FA, since their app didn't support 2FA at the time: https://duo.com/blog/duo-security-researchers-uncover-bypass-of-paypal-s-two-factor-authentication https://duo.com/blog/duo-security-researchers-uncover-bypass...
- acdha 4y agoMFA means that you're not immediately exploitable. It doesn't mean that you can't be phished — and remember that someone with your LastPass vault can make some pretty convincing targeted phishing messages — if your 2FA is anything other than a FIDO2/WebAuthn key. This has become routine and there are toolkits for attackers to make it easier so it's definitely not an emergency but not something you want to slack on. It also doesn't doesn't help if there's any way around the MFA process. For example, could the attacker convince a minimum-wage support person / chatbot that you need to reset your MFA? Many companies skimp mercilessly on support costs and that makes this easier than it should be. I've even seen sites where your MFA can be reset using an email challenge!
- LastTrain 4y agoI spent part of my holiday break cleaning up after this mess, resetting hundreds of credentials. On the plus side, it provided a much needed opportunity for some house cleaning.
- lampshades 4y agoDid the same. Took several days but feels good to not have to worry about LastPass anymore.
- d23 4y agoIt also made me realize just how many sites have broken or missing password reset flows.
- insane_dreamer 4y agomoved everything important off LastPass a while back; still using it for convenience on pwds/accounts that I don't care that much about, but using KeePass offline for anything of consequence. Not really ready to trust Bitwarden.
- richiezc 4y agothere is only 1 rational course of action: (1) export and delete your lastpass account (2) import to new PW manager, in my case bitwarden (3) change all your passwords
- ComputerGuru 4y agoI’ve been sitting on what I think might be the last straw to break the proverbial camel’s back but I didn’t think readers had any more bandwidth to hear more about this breach. I have my reasons to believe there’s a good chance LP knows of a means by which the master keys if some users may have been once compromised long before this incident.
- ramses0 4y agoThe other difficulty is it appears there is little-to-no support for API/automation: https://github.com/lastpass/lastpass-cli/issues/602 https://github.com/lastpass/lastpass-cli/issues/602 https://github.com/lastpass/lastpass-cli/issues/624 https://github.com/lastpass/lastpass-cli/issues/624 https://github.com/lastpass/lastpass-cli/issues/604 https://github.com/lastpass/lastpass-cli/issues/604 ...their CLI tool is de-facto deprecated (unsupported) and has several unreliability issues (ie: `lpass ls/userls ...` reports differing amounts of values depending on when a user was added to the folder or not). Basically `lpass ls ... | xargs -n1 ...` cannot be trusted, and you can only get an accurate list of passwords (or users) from the actual GUI. It makes automation, auditing, reporting, near impossible.
- jp191919 4y agoSo glad I switched to KeepassXC
- JonChesterfield 4y agoA question for those "starting to migrate away". Why bother changing passwords that you then put back into LastPass? Change the passwords yes, all of them, but if you're going to put the new ones back in to be re-exported by your adversary you may as well save yourself the time and stay with the already breached ones.
- emodendroket 4y agoI use them too, but password managers feel like they’re building atop a poor foundation. I’d like if we could go further in the direction of site login using a big, well-known identity provider (sure, let there be some independent one if you don’t want to trust Google or Facebook). Failing that, this incident does show the virtue of the old-fashioned method of writing down the passwords and keeping them somewhere safe.
- ghusto 4y agoYears ago, I told them privately of a vulnerability in their implementation of 2FA. They dismissed it as a non-issue. A couple of weeks later they sent out a statement "clarifying" how their 2FA had a caveat. It was basically marketing bullshit glossing over the fact that they don't enforce 2FA locally (sorry, details are very vague in my memory now, but I remember it being a serious mis-implementation). Clowns.
- AtNightWeCode 4y agoMy personal password policy is. Never store passwords in PW-managers to important things that can be accessed without MFA. Especially not work related things. I have not figured out where to store those backup codes though.
- sys_64738 4y agoI asked the tech lead at a past job if he'd have been willing to resign over his decision to store our keys in the "cloud", using LastPass. He never responded.
- ipaddr 4y agoHas this soured the concept of a password manager? Instead of many different accounts and passwords you also add one more account that gives you access to everything. Backdooring yourself. People will say you have to use one because you might reuse a password. If a hacker gets a hold of it they will have access to other accounts. Hopefully many use different emails and/passwords but even if they don't an attacker doesn't have a list of websites this works on and will try to login to major sites which usually alert the user. If your lastpass account has been hacked they know all sites large/small and will have an easier time stealing info/money from smaller sites with lower protections and can blackmail you because you saved your pornhub account (with a privacy email address) in lastpass. People are going back 5 years trying to get information from a company they have no relationship with. This company kept your passwords after you left. Once you give them to lastpass they are no longer secured even if you decide to leave..10 years later coming in through that backdoor you left open.
- octobus2021 4y ago[...sound of offline password managers' users munching on popcorn intensifies...]