14 ms·
LastPass users locked out due to MFA resets
- wryoak 3y agoOne reason I left LastPass was because it kept bypassing 2FA (or incorrectly presenting it when it for whatever reason wasn’t required) - I could just press cancel and then there all my passwords were. The macOS app was … wild
- causality0 3y agoWhy would LastPass let you "unsubscribe" from critical security emails like "hey you're gonna be locked out"? Or have they tied critical emails to marketing garbage emails in their communication preferences?
- Obscurity4340 3y agoHate to say it but these remaining users were and are fools for not having jumped ship like yesterday. This is not a serious + competent password manager product/company. Hopefully they had backups or they are in for a world of hurt dealing with the worse mess of being stuck in such an absurd loop.
- iLoveOncall 3y ago> Hopefully they had backups We know they do, since they got their backups stolen not even a year ago lol.
- toyg 3y agoAh but maybe they reacted to that by stopping backup jobs. Wouldn't put it past them, pretty shambolic operation.
- KnobbleMcKnees 3y agoHey I'm not a fool! Just time poor and a bit lazy. Also I use 1Password at work and find it a bit doddery compared to LP, which is no speed daemon itself.
- iLoveOncall 3y agoIt took me 30 min to migrate from LastPass to BitWarden, they have a process to import the passwords so it really doesn't require any effort. https://bitwarden.com/help/import-from-lastpass/ https://bitwarden.com/help/import-from-lastpass/
- frizlab 3y agoIt does require effort though. Migrating the passwords is a thing in the process, but there is also finding a good alternative first, that integrates well the softwares one uses, getting used to new UI, new shortcuts, new bugs, etc. All in all, it does take (much) more than 30 minutes.
- degenerate 3y agoI hear you, and generally you are correct, but migrating from LastPass to BitWarden (and setting up the extension to work exactly the way I liked LastPass to work) truly did take 30 minutes. I wasn't expecting 100% feature parity but it's there. What took the longest was discovering CTRL+SHIFT+L is the shortcut to auto-populate username/password in forms. Pressing it again will cycle to the next account in the vault.
- JaggedJax 3y agoI knew about Ctrl+Shift+L but never thought to try using it to rotate through multiple credentials. Thanks for that!
- orheep 3y agoLastpass user here that probably should migrate. Is that keybinding changable and how is the iOS experience?
- lukevp 3y agoIt’s great on iOS! It integrates into the password manager just like LastPass did, so you get the “Passwords” button or the account name. If you have faceID or touchID set up, it’ll auto auth you and autofill the password. Bitwarden is seriously almost a drop in replacement. The biggest difference is the extension settings in browsers don’t autofill by default in the same way as LastPass. Also you can self host bitwarden (what I do).
- ramraj07 3y agoI continue to use LastPass because I’m lazy and I never trusted any app fully in the first place. All my main account passwords are in my head alone.
- doublerabbit 3y agoYeah. I don't get this. I've never required a password manager, maybe I'm just good at remembering passwords. And why would you even trust a cloud based product. If I can't see the hosted source code storing the password then I'm not trusting it regardless.
- ajmurmann 3y ago> I've never required a password manager, maybe I'm just good at remembering passwords. How is this possible? I must have at least 50 passwords I use with some regularity and many more I use once a year or so. All my passwords are at least 16 characters long and totally random. Are you able to remember that without compromises like repeat passwords or patterns used for generating them (including website name in password or similar)?
- somehnguy 3y agoIf you can remember your passwords I have a strong suspicion that you’re using weak passwords and/or re-using them. All my passwords are 12+ (whatever the site max is) random alphanumeric+symbols and don’t get re-used across sites - there is no possible way I could remember them all.
- doublerabbit 3y ago9-12 characters upper and lower case with numerical and special characters, pretty much unique.
- 5e92cb50239222b 3y agoDiceware is easy to remember. https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases https://www.eff.org/deeplinks/2016/07/new-wordlists-random-p... https://www.eff.org/dice https://www.eff.org/dice This generator uses a different wordlist with about 18000 words. https://1password.com/password-generator https://1password.com/password-generator Using a quick back-of-the-napkin calculation, you get roughly this amount of entropy from 1password's wordlist when compared to random alphanumeric strings [a-zA-Z0-9]: - 5 words ≈ 12 chars - 6 words ≈ 14 chars - 7 words ≈ 17 chars - 8 words = 19 chars If we take 5 words as the minimum you'd want to use on a web service: - halvers persia dutiful manes party - append medalist society duke disobey - acoustic halo assuage upkeep dexter - area theist motile align trespass As a non-native English speaker (which should be obvious from my strained speech), I'd say it's rememberable enough.
- palata 3y agoGenuine question: why are there still LastPass users? I mean, if you have a password manager, it means that you somehow care about your passwords. If you have LastPass, it means that you chose something that was not the default Google Wallet or Apple whatever-it-is-called. Are there so many LastPass users who haven't followed the news in the last 2 years?
- wruza 3y agoSome of them may be company-plan users who can’t choose and it’s hard to replace overnight.
- Waterluvian 3y agoYes. Most of them. It’s such an important lesson for informed people, and tech people, especially, to learn: our context is absolutely not the common one. Things that are obvious and clear to us are a world away for most others.
- iLoveOncall 3y agoBut you don't even have to have followed the news. LastPass has sent an email to all its users informing them of the somewhat recent breach. I had already left by then but I would have otherwise.
- Waterluvian 3y agoYep. They either don’t know or don’t care. There’s a level of security fatalism among non-techs. I can imagine a security professional explaining to a random person everything they ought to do to be secure. Not gonna happen.
- zdragnar 3y agoPeople still read their emails? I thought it was mostly just for registration verification links and spam.
- UncleMeat 3y ago
- friendlypeg 3y agoThe entire website is written in PHP. I have nothing against the language, but it's a major red flag when you would expect it to be using Java instead like most bank and government websites do.
- giancarlostoro 3y agoI dont know that a website running Java gives me warm and fuzzy feelings only because its on Java. I care mire that whatever the underlying website is powered by is not easily exploitable by bad actors.
- esskay 3y agoThe language you use matters very little. It's how you use it. PHP's not at fault here, even if they used Java or another language their incompetence would still be the issue.
- veave 3y agoI know this is a troll comment, but, a website being written in Java screams "this was subcontracted to junior devs" to me, which is not precisely a green flag.
- esskay 3y agoMore fool anyone silly enough to still be using LastPass.
- bob1029 3y agoI am completely over the idea of storing secrets inside of one of these 3rd party systems. I've currently got a team member writing an internal secret storage app for our organization. Creating a SQL schema with a "Secrets" table and maybe some audit logging and organizational extras should take a seasoned developer ~30 minutes. Throwing a CRUD web app on top of this and making it accessible to your employees - maybe another day or 2. I really don't know why you'd risk this sort of stuff with a 3rd party. It just boggles my mind. What are they doing that you can't do? Even a 3 person startup can probably find time around a weekend to knock this out once and for all. Edit: clearly I missed an important point. We don't care about browser integration. I am not going for 1:1 feature replacement. If you seriously believe "a safe place to keep internal text" is an extremely hard problem that absolutely must be outsourced, I don't know why you would even be involved in technology.
- sk0g 3y agoThose are the most project manager estimates I've ever heard! Security seems to be missing entirely from the requirements, for one thing. Access control as well.
- have_faith 3y agoLooking forward to the audit and post-mortem
- skrebbel 3y agoI've wondered why so many software companies have so extremely many engineering employees. SaaSes raising a 9-figure Series D and hiring thousands of devs for a customer support app. I just never got it, I wondered about this for years. But now, thanks to your comment, I finally understand.
- jmclnx 3y agoI do not understand why people need to use these things, maybe they make it easier and more secure for Cell Phones ? I never use my Cell Phone for anything Finance or Medical Related. But for me, I keep an encrypted text file and get the passwords my using emacs or vim. I generate passwords using: tr -cd "[:alnum:]" < /dev/urandom | fold -w 16 | sed 10q and with the result I may replace 1 character with what they call a "special character". To me that avoids a lot of worry.
- commandersaki 3y agoMy bank has gimped the web interface of banking services. Similarly government services gimp the web interface of tax, medical, etc. and try to push you onto mobile apps. I can't fight this trend. Good for you that you can opt out of this nonsense.
- danielbln 3y agoWhat's with these comments who can't possibly conceive why a certain product is popular and in use. Convenience, sharing, application integration, recovery, 2FA, passkey, SSH agent integration, the list goes on. LastPass is kind of bad considering their avoidable security snafus, but there are more reputable vendors out there. Yes, you can roll your own, but that's not a scalable solution if you're an org or have requirements that lay outside using a Textfile.
- dwheeler 3y agoAgreed. I've used vim for decades, and also use a password manager. I have a laptop and phone, and routinely use multiple web browsers. I want to sync encrypted passwords across devices, and auto fill in when I visit a a website... and websites infuriatingly vary. 1Password and Bitwarden help with this. Your use case might be different and that's fine.
- spdif899 3y agoIt's probably safe to say that 99% of people using this sort of password manager don't know what emacs and vim are, and additionally use their cell phone for most of their online computing. If you look at it from the opposite perspective the value is clear - this isn't a tool for people who can generate and store their own passwords, it's a tool for people who got their Facebook hacked because they used the same password for everything for years and hey, this app can help avoid that mom, let me show you how.
- dav1app 3y agoI was an user of LastPass. Happly switched to Bitwarden.
- 8organicbits 3y ago> The forced logout + MFA resync events are taking place as we increase all customer's password iterations. Typically you just need to wait for a user to log in, then validate the password against the old hash and create a new stronger replacement hash. Ending all sessions is a good way to log everyone out and force that. But I'm confused. If weak password hashes were leaked, then the passwords need to be changed too. Increasing the rounds doesn't prevent attacks on the previously leaked weak hashes. Maybe they expect everyone already did that but some people did it before they increased the hash rounds? The MFA reset shouldn't be related to the increase in hash rounds, those are unrelated. So they must suspect the MFA seeds were also stolen, but aren't saying it, right?
- Wowfunhappy 3y ago> If weak password hashes were leaked, then the passwords need to be changed too. Increasing the rounds doesn't prevent attacks on the previously leaked weak hashes. Maybe they expect everyone already did that but some people did it before they increased the hash rounds? I assumed they were just increasing the rounds as a general good practice. The best time to plant a tree was ten years ago, the second best time is now, and all that.
- crote 3y agoIf it is just a regular rounds increase, why force an immediate re-auth on all users? It would be way more user-friendly to just wait 6 months or so for natural re-auths to occur, and only do a forced re-auth on the few remaining users afterwards.
- ExoticPearTree 3y agoFrom an user experience perspective, this would be the way. At some at the company I work for, we decided to changing hashing algorithms and we did it on the fly when user authenticated again. Users were happy, we were happy. But as someone already said here, there's a high probability that the OTP seeds were stolen so that's why they are doing this forced reset for MFA re-enrollment.
- nicetryguy 3y agoI don't even let Chromium / FF save my passwords what a genuinely horrible idea. Get off my lawn!!!
- iLoveOncall 3y agoThat just means that you have such a small number of passwords that you are much more unsafe that someone using a compromised password manager. I guarantee you your passwords have been leaked in individual website's breaches and that has exposed all your other accounts using the same credentials.
- nicetryguy 3y agoPossible, however: My personal strategy, much like i have a "junk email" address for signing up for random BS and a personal one for actually using is that i have a "junk password" that i sign up for unimportant services, and i guarantee it has been leaked many times. My important banking / amazon / etc passwords are indeed (slightly) unique and backed up by an digitally impenetrable firewall: pen and paper. Granted, this is just for personal use, and i can totally see a use case for a password manager in a company / corporate environment.
- BrotherBisquick 3y agoWould you be amenable to a program like Keepass? Your password store is a single file, it can be encrypted, backed up (or not), distributed/synchronized between your devices (or not). It belongs to you, not to a third party. The inevitable rejoinder is, "what happens if someone gets that file?" Well, what happens if someone gets your piece of paper?
- nicetryguy 3y ago> Well, what happens if someone gets your piece of paper? Considering it's in my house there is short list of suspects, unlike exposing it to the entire world VIA TCP/IP, but yeah i get your point. > Will you ever use a password manager. Not for personal matters and that is a personal choice. My way ain't broke and i ain't fixin it. A password manager smells like something that could break, get compromised, or go out of business at any time without any warning and i don't like the smell of it. I also code with Notepad++ with none of that autofill suggestion crap and doesn't take 8 smoking cores to fucking type a sentence if that tells you anything about my personality. Get off my lawn!!!
- sashank_1509 3y agoStarted with LastPass, switched to Bitwarden like 6 months back. It’s brilliant, it works and I never need to touch LastPass again
- IG_Semmelweiss 3y agoOk. I'll take the advice here. I am a time-constrained Lastpass user. I'm aware of the issues but not thw seriousness. I will abandon the platform now, but I could use your help: 1- is industry gold standard 1password or bitwarden ? Key requisite: edge or FF browser extension. (I dont use mobile password management apps and will never do so) 2 - in light of the LP breaches. Do I change all my pw accounts, the master LP account, or both??
- piaste 3y agoBitwarden is the gold standard, and it has browser extensions in addition to the cross-platform app.
- stavros 3y agoI really like its pricing, too. $10/yr is an easy sell.
- oraetlabora 3y agowho says that Bitwarden is the gold standard?
- Caboose8685 3y agoBitwarden is fantastic IMO, vaultwarden if you like to self host. Out of an abundance of caution, it would be prudent to change the passwords for the most critical accounts in your life initially. Things like your bank, email, Google. Accounts that losing control of would immediately make you go "oh shit, I can't do X that I need for daily life". Then slowly over time change the less critical ones.
- skrause 3y agoI recently discovered Vaultwarden (https://github.com/dani-garcia/vaultwarden https://github.com/dani-garcia/vaultwarden) and love it. It's basically single Rust binary (self-compiled: https://github.com/dani-garcia/vaultwarden/wiki/Building-binary https://github.com/dani-garcia/vaultwarden/wiki/Building-bin...) with a SQLite3 database running on my own server, implementing the Bitwarden server API. I can use all the official Bitwarden apps on my phone and desktop, but have the backend and backups under my own control.
- deleted 3y ago[deleted]
- DistractionRect 3y agoCaveat, bitwarden-cli isn't supported last I checked. They also only implement a subset of bitwarden features. Not to knock it vaultwarden, I've used it for years and have no plans to migrate anytime soon. The bitbetter project[0] shims bitwarden licensing for personal use. It might be better if you're looking for complete feature parity and client support. [0] https://github.com/jakeswenson/BitBetter https://github.com/jakeswenson/BitBetter
- jeroenhd 3y agoWhat parts of the cli doesn't Vaultwarden support? The cli client works fine for me when it comes to basic password operations. I'm aware that the backend doesn't implement every API Bitwarden has but I've also never noticed any missing features. It did take some time before Bitwarden Send was implemented, but I can't fault the devs for that. I also expect the upcoming BW passkey support to take a while to make it to Vaultwarden. Personally, the whole organisations thing is only a nice to have when it comes to hosting Bitwarden. The standard Bitwarden installation eats up gigabytes of memory for (I assume) optimizations for large installations that most self hosters probably don't really need.
- 0x0000000 3y ago> They also only implement a subset of bitwarden features. Any idea what's missing? Vaultwarden does add TOTP support, which the free official server didn't last time I checked, so while it may be missing features, it also unlocks features you wouldn't have without paying.
- makach 3y ago1Password is probably the best kept secret when it comes to password managers. I don’t understand why not more IT professionals advocate this software.
- maerF0x0 3y ago+1 Made the switch this quarter. It's practically the same price, incredibly easy to switch, comfortably similar if you've used lastpass before... And as I went through this process I also discovered despite breaches and insecurity, my LP account actually had some hardening issues remaining that they fixed for new signups, but failed to do so for long time customers. So fuck them. (I've since rolled many of the most important credentials btw) 1. Comb through your last pass, and delete cruft 2. Signup for 1password https://1password.com/switch/ https://1password.com/switch/ 3. use their auto import tool to pull from lastpass 4. Profit for ~3 months just for safety 5. Delete each item in last pass (who know if they do hard or soft delete?) 6. Request account deletion https://lastpass.com/delete_account.php https://lastpass.com/delete_account.php
- devnullbrain 3y ago>I don’t understand why not more IT professionals advocate this software. I can have an offline password manager that just works, for free, and I don't have to worry about backdoors or hackers or incompetence.
- pasc1878 3y agoThe big problem is that you have to store the information on 1Passwords site. I can't see how any business would allow secrets to be stored on hardware they don't control Earlier versions allowed the store to be on other sites like dropbox for syncing or on your own servers or a mix. Note I do use 1password as I don't need any corporate secrets at the moment. It allows me to use other browsers than Safari and also Windows and macOS
- SparkyMcUnicorn 3y agoEverything is end-to-end encrypted, SOC 2 certified, PCI and HIPAA compliant, and they've been audited many times https://support.1password.com/security-assessments/ https://support.1password.com/security-assessments/ If businesses can't trust any of that, then we wouldn't have any online businesses.
- paultopia 3y agothe blame the user responses reported in this story are just hopeless. Also, as far as I can tell, untrue: I cancelled my lastpass subscription after the last horrific breach and migrated to a new password manager while changing my critical passwords, but every once in a while I have to use lastpass to dig up an old unimportant password for something that didn't make the list for immediate changes... and I've never seen any kind of message about resetting MFA.
- AdmiralAsshat 3y agoI jumped ship to Bitwarden at the beginning of the year, and haven't logged into LastPass in some time, although I forgot to delete my vault and account. I suppose there's some assurance that if I'm indefinitely locked out of the account then at least hackers are, too?
- cube00 3y agoUnless their backups get stolen (again)
- account-5 3y agoI genuinely don't know why people don't use offline databases like keepass. The conveinance of online password management is not worth the hassle they can cause. All be it lastpass appears to be tge worse!
- Dayshine 3y agoBecause I have four devices I need my passwords on, on three different OSs, and no admin on one. All of my banks use a mobile app for confirming transactions, which requires me to login. Sometimes that requires reauth not just biometrics. I'm not going to go home and try and type a 20-30 character password into a phone when trying to pay for car parking.
- ilikehurdles 3y agoBack when 1Password honored its offline, non-subscription license we bought, we could store the encrypted vault in a cloud storage service like Dropbox (or your own server) and simply set up other instances of the 1Password client to use the vault on that folder.
- account-5 3y agoExactly what I'm doing with my keepass database. I have an offline keyfile that's never in the cloud for added security. I've found this to be the best solution.
- commandersaki 3y agoI feel like people that say "I don't store in the cloud" don't really understand how modern encryption works.
- account-5 3y agoCare to elaborate? It's not like I don't store in the cloud, since my database is in the cloud. Why would I store the keyfile next to the database?
- ClumsyPilot 3y agoI don't like any of this. Your passwords need to be with you, not rely on a server. I use keypass, it stores all passwords in a file, encrypted. The file can be stored in Onedrive/Dropbox/ etc. But the point is, if all the aervers in the world go down, I have all my passwords in a local copy. There is also an android app. You can even edit the database file independantly on desktop and on mobile and it will be able to merge two cobflicting files https://keepass.info/download.html https://keepass.info/download.html
- 93po 3y agoReminder for anyone with keepass on iOS, make sure it isn’t the malware one. I had it and had to change all my passwords
- BrotherBisquick 3y agoThere's malware on the iOS app store? What's the point of all that garden-walling and 30% tax and hoops you have to jump through if there's still malware?
- 8organicbits 3y agoIt happens sometimes [1] [2]. Reduced malware and quick removal is all you can hope for. I have an app in the Play Store and received some unsolicited requests to install (and get paid for!) adding some extra jar file to my app and hosting someone else's apps in my account. Attackers put in a lot of effort to sneak in. [1] https://www.wired.com/story/apple-app-store-malware-click-fraud/ https://www.wired.com/story/apple-app-store-malware-click-fr... [2] https://www.reddit.com/r/KeePass/comments/13o0s0q/ioskeepass_aka_keepassmini_is_compromised/ https://www.reddit.com/r/KeePass/comments/13o0s0q/ioskeepass...
- latexr 3y ago> What's the point (…) if there's still malware? Having fewer malware would still be a worthy goal. That said, I’m not defending the App Store. It’s still riddled with junk, ads, casinos for children in the form of free-to-play games, and adult casinos disguised as children’s games. https://soyacincau.com/2021/04/17/ios-app-games-for-children-are-actually-secret-online-casinos-gambling/ https://soyacincau.com/2021/04/17/ios-app-games-for-children...
- digdigdag 3y agoWhy anyone would continue to use their service after their amateur hour operation was revealed is beyond me. That's not to say their competitors are guaranteed to be better. Really, you shouldn't depend on any offsite service for password management. Use something like Pass (https://www.passwordstore.org/ https://www.passwordstore.org/), self-hosted bitwarden or at worst, GPG encrypted text files (which is essentially what Pass does).
- anonym29 3y agoNo matter how many compromises, how many DoS events / lockouts, or how many other times internet-based password managers royally screw up, it never ceases to amaze me how people continue to trudge back to these sorry services. "It's so convenient!" "I don't like having to manually sync between devices with <100% local password manager>!" Convenience addicts making excuses for their next hit of convenience... no matter how severely convenience harms them.
- kevincox 3y agoI hate to say it but convenience is king. If I need to log into accounts on my phone and computer there are two options 1. Use a crappy password that I can remember 2. Use a syncing password manager. If the password manager doesn't sync it doesn't provide enough convenience to be useful to me and I will fall back to 1. Convenience has long been an underrated aspect of security. If you make the secure option as convenient (or even more convenient) than the insecure option people will do it. Of course security is always in opposition to convenience to some degree (otherwise we wouldn't have passwords at all, just type in your username to log in, we trust you completely), but minimizing the inconvenience is key to making the system secure in practice. If you make the system too inconvenient people will just work around it no matter how secure it is in theory. I think we are beginning to understand this and things are improving, but many legacy systems still suffer. For example NIST guidelines have accepted this and now recommend against time-base password rotation[1] but many organizations still enforce it. [1] https://pages.nist.gov/800-63-FAQ/#q-b05 https://pages.nist.gov/800-63-FAQ/#q-b05
- kstrauser 3y agoThis is so critically important! “Convenient + good” is vastly better than “inconvenient + better” for 99% of common use cases.
- anonym29 3y agoSecret security isn't a common use case, as it has an uncommon but critical property - it's binary - either the credential is leaked / stolen or it isn't. If "convenient + good" isn't good enough and your credential is compromised, your solution fails completely, 0% score. If "inconvenient + better" does prevent the compromise of your credential, then it is an absolute success, 100% score. Prioritizing convenience over security while selecting your password manager is like prioritizing keyless entry over functioning brakes while shopping for a used car - it's clearly a stupid decision even from the perspective of a layperson. I'll shed zero tears as I play the world's smallest violin when people who've made such decisions have their identity stolen, home forclosed, and savings drained because "muh convenience!"
- semiquaver 3y agoI recently had to start using Lastpass for work and I am absolutely mind-boggled at what an all-around terrible piece of software it is. I have my complaints about 1Password but those are peanuts compared to the mile long list of show-stopping bugs and UX problems I experience every day with LP. Irredeemable garbage.
- AlbertCory 3y agoI don't use a password manager. You shouldn't, either, probably, unless you want to share passwords with a group or something. I have a file of hints which are only meaningful to me. Even if a malefactor got hold of the file, it wouldn't help them. (no, I'm not going to give examples; if you can't think of some combinations of characters that only you can remember, then fine, use a password manager). I'm always thinking of new ones, too. You don't need a unique one for every site, either. Having 15 or 20 that you choose at random means that an invalidated one doesn't affect everything you do. Occasionally, the Hint file has an actual gibberish password with no hint, where I have to copy/paste it. I think this is fine once in a while. All I really have to remember is the password for the place where that file is stored, and my email's. Often it happens that my stored hint doesn't work (maybe I forgot to update it), but every site has a Forgot Password link.
- ryan-c 3y agoCounterpoint: Use a password manager and unique passwords for every site, and be mad about the terrible authentication UX, just like the vast majority of experts in the field recommend.
- diarrhea 3y agoThis is not the way. So much churn for less effect.
- AlbertCory 3y ago"churn" ?? what are you talking about? or is that a hint that's only meaningful to you? /s
- Latty 3y agoMore vulnerable to phishing, a good password manager checks the URL programmatically and won't fill a different domain, human validation of domains is weak, we forget and can be tricked.
- AlbertCory 3y ago
- remote_phone 3y agoI still use my licensed 1Password version from like 10 years ago. I share passwords over Dropbox to my other computers and I cut and paste passwords. It’s not hard at all and I don’t have to pay a subscription.
- x86a 3y agoSame here, but I would gladly pay 1Password to support this model again.
- jrm4 3y agoTo borrow a refrain from crypto; "Not your keys, not your passwords." Hope people don't fall for the stupid thing that Google/Apple et al are trying to do, either.
- justinclift 3y agoThe problem of needing a current login session in order to access support is a fairly common failure mode in some organisations. Strangely enough, some places don't fix it when they learn about it. I'm not sure why though, as that makes no sense to me.
- sowbug 3y agoIt's scary when a company ships a security feature with a buggy "happy path," because it generally means the engineers who built it don't follow personal best security practices themselves. An example is whether a website's login form works with browser autofill. If it doesn't, it probably means the person who built that page doesn't use browser autofill, which means they probably use the same password on all their personal accounts, which is terrifying. (Bad example for a product that's supposed to replace the browser's built-in password manager, but you get the idea.)
- Whatarethese 3y agoIt's just issue after issue with LastPass. Is it just apathy that is keeping people using them? There are much better options out there that are cheaper and better.
- n05tr0m0 3y ago[flagged]