6 ms·
I mean, duh? Anything that gets breached and leaked will obviously end up in various lists, and has always been doing so. > In November 2022, the password mana
by capableweb 3y ago
I mean, duh? Anything that gets breached and leaked will obviously end up in various lists, and has always been doing so.
> In November 2022, the password manager service LastPass disclosed a breach in which hackers stole password vaults containing both encrypted and plaintext data for more than 25 million users. Since then, a steady trickle of six-figure cryptocurrency heists targeting security-conscious people throughout the tech industry has led some security experts to conclude that crooks likely have succeeded at cracking open some of the stolen LastPass vaults.
> longtime cryptocurrency investors, and security-minded individuals
I'm not sure how "security-minded" you are if you, months after a breach of your password manager, still haven't changed all the involved passwords and keys, especially those involving things worth a lot of money!
- krebsonsecurity 3y agoI thought about that also, and then one of the victims I talked to brought up a good point. An 8 character password with symbols and numbers doesn't sound like a great password today, but many of the accounts getting drained were tied to people who were very early LastPass users, and mostly longtime investors. Back then, affordable GPUs that can do 4 million hash cracking attempts per second weren't really a thing. What I found was a lot of people made security assumptions and never revisited those assumptions. Or never fully did.
- gxs 3y agoHonestly, if this is truly the case, LastPass is partially to blame here. Sure, there's nothing in the TOS contractually obligating them to do this - but starting a low level awareness campaign to warn people with passwords that haven't changed in years about this risk seems like an easy thing to do that a (in keeping with the theme) "security minded" company should be enthusiastic about doing. You can't nanny everyone, but surely if you're paying for a password manager you'd appreciate these kinds of notices.
- djfdat 3y agoThey did have something like that back when I used it. It would tell you repeated passwords, passwords that have appeared in leaks, weak passwords, etc
- diogenes4 3y ago> but starting a low level awareness campaign to warn people with passwords that haven't changed in years about this risk seems like an easy thing to do that Rate of change seems like a very poor signal compared to absolute password strength, which won't change over time. Isn't this already built into lastpass?
- gxs 3y agoAh, I was talking about OPs comment - it wasn't that passwords weren't changed often - it's that they were created a long time ago when that particular length/complexity was thought to be enough.
- diogenes4 3y agoI see what you're saying, but 8 characters was also considered not enough 20 years ago. Naturally it takes a long time for good practices to propagate but
- oefrha 3y agoLastPass was founded in 2008, and an 8 character master password was clearly inadvisable back then, as it was already in the nation-state-can-crack-it territory, and computing power was rising rapidly. I started using 1Password in ~2010, not long after the founding of LassPass, and my first master password was 30+ characters, 90+ bits of entropy. After a few years I upgraded to 50+ characters, 140+ bits of entropy. Good luck cracking that even if only one round of PBKDF2 is used. But I suppose you have a fairly loose definition of "security-minded".
- anonym29 3y agoOne malicious JS script being inserted on the page where you enter your master password. One supply chain attack. One upstream dependency. One contractor clicking one wrong button in an office document. Your entire digital life compromised, in that one click.
- oefrha 3y agoI don't know how your comment is in any way related to mine, as I was responding to the claim that 8-character master passwords were considered safe <some time in or after 2008>. TFA also doesn't mention any evidence of keylogging.
- weq 3y agoI totally agree that Password managers lead to bad security practices. Yeh your a mhad dog for easily generating different complex passwords for every websites, but at the same time you paint a massive target on your head being part of the honey-hole. Based on history, if you store a password in a obfuscated location on your computer, and you copy and paste it into every websites, its more secure then using a password manager in my opnion. Sure you wont be able to login to every secure websites from every device you have; but SHOULD you be? What is the price of that convience?
- diogenes4 3y agoI seem to remember 8 character passwords was also considered weak back when bitcoin was first launched, but i could be wrong.
- SV_BubbleTime 3y agoThat was the issue with LP never upping the number of PBKDF iterations. BUT… this never mattered if you used a strong master pass phrase. 8 hasn’t been the recommendation in quite a long time. I pushed Lastpass to my company in 2017, made everyone use 24 char. The LP hack was bad, but I wasn’t worried for any of our people.
- lxgr 3y ago> I pushed Lastpass to my company in 2017, made everyone use 24 char. Do people actually memorize that?! If so, I strongly suspect that these pass phrases have much less entropy than 24 truly random characters would allow.
- SV_BubbleTime 3y agoIncorrect. I trained people for 5 word pass phrases with no BS. They were free to spice them up if they like. In 6 years I have had zero password reset requests.
- lxgr 3y agoFive English words have an entropy of about 55 bits [1] "Spicing them up" probably adds a handful more, but not much. That's about as much as a 12-character truly random case-insensitive alphanumeric password without special characters (log2(36^12) = 62). > In 6 years I have had zero password reset requests. What do you mean by that? This can mean that either your scheme is secure, or that nobody has ever attacked it (or you haven't found out that it did happen). [1] https://crypto.stackexchange.com/questions/62597/calculating-entropy-within-xkcd-936-password-strength https://crypto.stackexchange.com/questions/62597/calculating...
- SV_BubbleTime 3y agoDepends if you are counting correct and common English words. But yea it’s close to about 12 char anything you can hit on a keyboard entirely random. I figured 3e23 vs 4e23, you know “close” ;) Now… get 80 people to remember a 12 char randoms. No resets means no one has forgotten their pass phrase. I can not be just explaining passphrases to you now. But also, spicing a pass phrase up is huge and not just a few bits more entropy. You go from 24 chars that are 5 word options to 24 char almost completely random again.
- vitus 3y ago> What I found was a lot of people made security assumptions and never revisited those assumptions. Or never fully did. I appreciate that KeePassXC has a feature to audit your passwords (Database -> Database Reports -> Health Check), which tells you which of your passwords are weak / should be changed. https://keepassxc.org/blog/2020-08-15-keepassxc-password-healthcheck/ https://keepassxc.org/blog/2020-08-15-keepassxc-password-hea... for more details (the threshold for "good" has since been bumped from 65 -> 75). The score corresponds to bits of entropy, with penalties for things like password reuse. (It also has HIBP integration if you want to perform a one-off check that none of your important passwords have been compromised.)
- therealdrag0 3y agoDoesn’t LastPass have this as well?
- vitus 3y agoSeems like it (the "Security Dashboard"). In fact, it looks like it uses the same standard library for calculating entropy (zxcvbn). I didn't know offhand, since I've never used LastPass. My point is that if your password manager allows you to readily identify which of your passwords are insecure / have been compromised, that's a very useful tool to revisit any previous security assumptions you may have had.
- lxgr 3y agoIf that feature were to be implemented truthfully, it would have to report “go and change all of these; we were compromised and your master password was probably not secure enough” (i.e. based on the master password’s strength in addition to that of stored passwords).
- JohnTHaller 3y agoUnderrated feature, really. And most folks don't even know it's there. It also shows your health level on each password entry in the normal vault lists as a color square and when you open your entry as a colored line.
- anonym29 3y ago> longtime cryptocurrency investors, and security-minded individuals I'm not sure how "security-minded" you are if you used a centralized, network-accessible password manager service in the first place. Actual security minded folks keep their password vault on an air gapped machine they maintain full, physical control over. The kind of people who use centralized, networked password managers are, by definition, those who prioritize convenience over security in the first place. Sure, using something like LastPass is better than just saving all of your passwords in your browser, or just using one password everywhere. Citing this as evidence someone is security-minded is like saying someone is environmentally conscious because they recycle aluminum cans, despite driving a Hummer H2 and burning the rest of their trash. Is it better than nothing? Absolutely. Does it make them an environmentalist/security-conscious person on it's own? No. Does it make up for the other shortcomings in strategy? Nowhere remotely close. It's a half-assed baby step for people who want to LARP as being serious about their goal (environmentalism or security), without the slightest ounce of inconvenience to their otherwise completely polluting/insecure habits. Keep driving your H2 and telling yourself you're environmentally friendly. Keep using your PMaaS (password manager as a service) and telling yourself you care about security.
- distortedsignal 3y agoWhat do passwords do on an airgapped system? Being serious - if the system is already not able to get anywhere, nobody needs to authenticate on it or with it. If you have passwords there, they don't _do_ anything. I'm pretty security minded - the word "security" is in my job role - but my password vault is in Google Drive. I need to have it on many machines, and I want it to be backed up. I know my limits - I don't have the hardware and software infra and expertise that Google does - so I trust them with that data. Could it bite me? Yes, but it would require someone a) downloading my passwords file and b) decrypting it. That's enough steps that I'm confident that I'm safe enough.
- anonym29 3y ago> What do passwords do on an airgapped system? Get read and re-entered by exactly 1 person, the only person who's authorized to read them. Oh, sorry, you wanted to copy and paste because you didn't think twice about the security of your clipboard, whether other userland programs are reading your memory? My bad. > I'm pretty security minded - the word "security" is in my job role - but my password vault is in Google Drive. I'm on a corporate red team. People like you with your mindset are why I have a job and why big breaches of F500's that "care about security" will always keep happening. You don't prioritize security, you prioritize convenience, and security is a nice add-on to your convenience. By all means, please continue doing things exactly as you do - my bank account and I will forever be grateful for folks like yourself. Never stop prioritizing your absolute convenience!
- deleted 3y ago[deleted]