5 ms·
After using LastPass for years, this breach led me to do something I should have done long ago: remove my bank account & email account passwords from it (and ch
by finnh 4y ago
After using LastPass for years, this breach led me to do something I should have done long ago: remove my bank account & email account passwords from it (and change them, of course). My wife did the same thing. At some point I'll probably switch password managers, but the basic realization was that those passwords are qualitatively different than the rest and should never, ever be trusted to any password manager.
So now I remember ~3 passphrases, instead of 1, and sleep much better at night.
- ericpauley 4y agoI disagree, mostly because the password manager is more than just a place to store passwords. The origin binding also prevents you from typing the password on the wrong domain. For many people they’re probably more likely to get phished for a memorized password than pwned for a managed password.
- hunter2_ 4y agoI wonder if there's an app/extension that streamlines remembering/autofilling usernames but not passwords. I doubt many people would be into it, but it would be the best of both worlds for the case you describe, I think. Or simply a personal allow list of origins, with a happy green indicator prominently overlaid onto login forms on those origins you've saved -- doesn't even need username storage. Maybe even a community-sourced allow list, but that would need some seriously trusted management (including purging upon domain registration expiry/transfer) but that would mostly duplicate the domain warnings that browsers already offer, anyhow.
- deleted 4y ago[deleted]
- criddell 4y agoThat's a good point that I hadn't thought of before. I used LastPass for years and switched to BitWarden a couple of years ago. I did delete my LastPass account after switching, but I have zero confidence that they actually deleted my data. Fortunately, my master password from back then is long and complicated.
- BowBun 4y agoYet another point of absurdity. Only if I live in California do I have the right to demand a company clear all my personal data. Meanwhile we have multiple large organizations that have hemorrhaged data to the world and caused irreparable harm to individuals, with little or no consequences. We're all held hostage by tech.
- swyx 4y agoive thought of a mitigation for this - always intentionally enter the wrong password on the first try. if you're being phished, you'll notice when the wrong password gets you in
- function_seven 4y agoI thought some phishing attacks act as a relay or middle-man? I don't know how common that is.
- coder543 4y ago100% correct. You might have 2 factor enabled, so they also need to check that and phish the 2FA code as well. That 2FA code expires quickly, so it needs to be used in real time to get a session. I'm sure there are some very basic phishing attacks that just save whatever you entered, but... let's avoid trying to come up with "clever hacks" that only lend a false sense of security.
- eviks 4y agoa much more convenient mitigation - create an item without a password, so it would autofill username (and not autofill if you're being phished, so domains wouldn't match), so all you'd have to do is enter the password from memory
- eviks 4y agoYou can create an item without a password for this purpose - it would show an indicator if you have an account at a given domain, would even autofill the user name But you still get to save the critical password from the poor security of password managers Win Win
- coder543 4y ago> the critical password from the poor security of password managers Just because one restaurant has a bad health inspection score and is constantly making everyone who eats there sick does not mean all restaurants are bad. People who just lump "password managers" into one group are fundamentally assuming that one bad password manager means that all password managers are automatically bad, we just somehow don't know it yet. Don't bother eating at restaurants ever again if you feel that way, I guess. I know people who have gotten sick eating at restaurants, but that doesn't stop me from finding good restaurants. Most password managers have a very good security track record. Users creating and remembering their own passwords does not have a good security track record at all. Better to use a completely offline password manager (which risks you losing your backups or getting into a conflicting sync state) than no password manager at all, but a password manager that actually encrypts all your data end to end (which LastPass does not) and requires a strong key to unlock (such as the 2SKD method, which again... LastPass does not) is extremely safe, even if you don't trust "the cloud", because you don't need to trust the cloud.
- latchkey 4y agoThis logic is like learning that most accidents occur within 50 miles of your home and then moving 51 miles away. Why would you remove those bits of information and also not switch password managers too?
- deleted 4y ago[deleted]
- deltarholamda 4y agoI was always a bit wary of these services. They sound great, and the convenience is amazing, but I have not much of an idea how everything works behind the curtain. I went with unix pass installed inside of a FreeBSD jail. It's more complex than auto-filling with a browser plugin (though those exist), but as long as I can get an SSH terminal I can get to my passwords, and various other bits of data. You have to allow password login from sshd (which isn't ideal, but I was going for "access from anywhere I can get an SSH session), so your passphrase had better be good. And you need to have terminal discipline to be sure you clear the screen if shoulder-surfing is an issue. But it has the advantage of knowing exactly what's going on at all times. And, for added benefit, there are only a handful of things you need to have printed out and stored in a safe or whatever so that your family can access all of the encrypted important stuff if you get struck by lightning.
- coder543 4y ago> I went with unix pass installed inside of a FreeBSD jail. > And, for added benefit, there are only a handful of things you need to have printed out and stored in a safe or whatever so that your family can access all of the encrypted important stuff if you get struck by lightning. Presumably this print out includes an instruction manual for using FreeBSD, opening a terminal on a FreeBSD machine, launching a shell inside a jail, and accessing this "user friendly" software? Exactly how technical is your family? Forgive my disbelief that this is an actual solution for anyone but yourself. > but I have not much of an idea how everything works behind the curtain You could choose to learn: https://1passwordstatic.com/files/security/1password-white-paper.pdf https://1passwordstatic.com/files/security/1password-white-p... Any good password manager documents this stuff very well. LastPass has a very shallow white paper that constantly refers to encrypting "sensitive data", but they never define what that sensitive data is, which is suspicious, and it turns out that LastPass doesn't encrypt everything, which everyone who cares about this stuff has known for years. In the 1Password document, they talk about how every item in the vault is encrypted, and every item contains various fields such as Title, URL, etc. 1Password encrypts everything. 1Password also talks about the benefits of using a user password plus a generated 128-bit "Secret Key" (2SKD), which is a security feature I strongly appreciate.
- smt88 4y agoIt is absolutely insane that you're going back to LastPass after this. We have no reason to believe they're not still fully compromised. Switch to 1Password. It takes ~5 min to export and import.
- tasuki 4y ago> Switch to 1Password. Doesn't cease to amaze me with what confidence people recommend these "Switch to 1Password", "Just use BitWarden". I switched to KeePassXC because it seems all the cloud-based password managers have the same endgame: get hacked. > It takes ~5 min to export and import. Only 5 minutes, and you've just doubled your attack surface area. Congrats.
- sbuk 4y agoI switched to only eating food I prepared myself because it seems all restaurants have the same endgame: spread salmonella.
- tasuki 4y agoThat's a pretty bad analogy. If by going to a restaurant I'd have to commit to eating at that particular restaurant forever, I probably would choose to prepare food myself...