9 ms·
The fact they're drip-feeding how bad this breach actually was is terrible enough and yet their entire product is built on nothing but trust. Part of me wonder
by intunderflow 4y ago
The fact they're drip-feeding how bad this breach actually was is terrible enough and yet their entire product is built on nothing but trust.
Part of me wonders if this was an intentional strategy: Downplay during the initial media round then very quietly reveal this was a worst case scenario.
Personally I'm never touching them again - anecdotally everyone I know who was an individual customer has migrated away and inside companies lots of engineers have stopped adding new passwords.
- blitzar 4y agoIf drip-feeding the details is an intentional strategy it is a stupid one. Keeping the negative story in the headlines for a day longer means it will reach more people and draw more attention.
- code_runner 4y agoThey’ll only piss off the people paying attention to every drip.
- ryanjshaw 4y agoNot just that, this drip feed of information makes formulating a proper response very difficult. If, for example, you deleted your account after the first report in August (a rational decision), you have no way of checking what iterations setting you had, now that people are talking about it. It's also unclear whether you will receive any data breach notifications detailing the exact impact to your data, since your account is now deleted - do they keep a history for "post-fact" situations like this? And of course, if you didn't keep a backup of your passwords before deleting your account, you'd have to reset everything to be sure. Terrible, awful company with no respect for their users.
- jolmg 4y agoThere's not really any benefit to deleting the account other than forgetting they're untrustworthy and accidentally using them in the future. I would think it's better to change all passwords (at each service, not at lastpass) and leave the account at lastpass active, precisely to be in the know for such things in the future. That's unless I'm misunderstanding something about their service that makes it better off to delete the account. I've never used them.
- dividedbyzero 4y agoThey still have a list of accounts, email, usernames, even if the passwords have been rotated, plus whatever happens to be in secure notes and the like. Deleting the account is really easy (has to be for EU customers) and they're obliged to delete all data they hold on the user (under EU law), so I don't see any reason to let that kind of data sit around on an untrustworthy party's servers. I certainly won't need a reminder that they're untrustworthy.
- prepend 4y agoWhen it comes to important stuff I think it’s important to trust no one. I’m sure LastPass tried really hard to protect data. But everything fails eventually. If there’s things that are life threatening or financially devastating then I don’t think I can afford to audit people sufficiently to trust them with the info. This is also why I can’t imagine ever using Plaid/Mint/etc that require my bank credentials just to do minor stuff like make payments or read transactions. These password managers are in a tough spot market wise as they aren’t smart enough to secure super important stuff and for unimportant things, iOS/chrome password management is pretty good. I don’t mind if my audible account gets rooted, but it would be very bad if my bank or brokerage gets rooted.
- mdla-hn 4y ago"but it would be very bad if my bank or brokerage gets rooted" Yup. I put everything in the password manager except primary email and bank/brokerage.
- sofixa 4y ago> This is also why I can’t imagine ever using Plaid/Mint/etc that require my bank credentials just to do minor stuff like make payments or read transactions. That's the fault of banks. We need open banking, with APIs using OAuth or similar with scopes or some way for per-action/item access.
- ak217 4y agoThings are improving bit by bit. BofA and Chase both have OAuth and pretty granular permissions now. Citi and Wells Fargo have OAuth APIs too, though I haven't worked with them personally. That's the top 4 consumer banks, but many credit unions are stuck in the past. Credit unions in general need to wake up about how far behind they are in IT investment, and use a common IT vendor to modernize.
- rxyz 4y agoAlready exists in EU.
- usrusr 4y agoAnd each drip paints a bigger crosshair on the back of keypass wrt supply chain attacks (the only angle where keepass isn't inherently better than others). I wish lastpass all the best in terms of improving their communication!
- verisimi 4y agoI'm now expecting a raft of these sort of leaks. This sort of thing, will all encourage us to 'naturally' move towards a government backed, biometric solution. Which will of course be phone based, will hold your wallet, id and medical information, and will be provided to us by kindly corps such as twitter, google, apple, microsoft, meta, etc.
- medellin 4y agosurprisingly the government based sites i use let me use email for 2fa which is better than phone since i can add 2fa for my email as well. It’s the banks that keep insisting i use a phone for 2fa. I have moved away from ally because of this
- lolinder 4y agoI don't think it was intentional: this is one of those places where ripping the band-aid off is far better than slowly dragging it out. The drip-fed reveal increases the raw number of headlines about the breach and drills the idea "GoTo is bad at security" into people via spaced repetition. If they said "our entire company was pwned" on day one, they would have had their day in the media and by now only HN would still be grumbling about it. I think what's actually happening is that they're just really bad at security. Either every few weeks they discover something new or they still haven't successfully locked the attacker out.
- LocalPCGuy 4y agoI do think they are being very intentional in how they release and frame things, and one of the things dripping it out can do also is produce some level of fatigue on reporting it. It definitely seems like they knew some things before it came out - some people have looked at changes to their site and there are new or updated marketing changes that in retrospect seem very correlated to what we're learning now. Not definitive proof, but very concerning. I also think you are correct to a point, they are really bad at security so it is also possible that some of these things are just coming out also.
- aggie 4y agoThis assumes everyone sees all the headlines. This approach is very bad for people paying attention, but the type of people to pay attention to this kind of news would probably be unwilling to go near LP again if it was revealed all at once. Their play might be to assume the initial headlines get the most coverage so soften the message there, then wait for a general audience to tune out and reveal the worst parts.
- arp242 4y ago> Part of me wonders if this was an intentional strategy: Downplay during the initial media round then very quietly reveal this was a worst case scenario. Seems like a poor strategy. This is like an infected wound that keeps on festering. A turd that will not flush. A house guest that won't take multiple hints it's time to leave. Better to just get it over with in one go; next week the news cycle will be something else and it will be over; now it's in several news cycles again and again.
- Denzel 4y agoCan confirm. Migrated from LastPass -> 1Password last month.