7 ms·
How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous
by jagged-chisel 4mo ago
How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
- pluc 4mo agoPeople still use Windows
- zulban 4mo agoA lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.
- stymaar 4mo agoAnd it will continue until we can sue company being breached for criminal negligence. Should a single company executive be personally liable in these situations, the scale of the problem would be orders of magnitude less severe because they would spend the appropriate amount of effort to cover their damn ass.
- jordanb 4mo agoThis is it. These companies don't really care about their customer's data. Their SDLC is no more rigorous than any other SaaS product. They have junior people and (now) AI pushing code with a quick "LGTM" PR check just like everyone else. The way to stop this is to have actual consequences for the decision makers here. You can build high-integrity software and some fields (avionics) have done it. But the organization needs to be built from the ground up to do it and nobody's going to do it if you can just get breached and offer a phony apology over and over again.
- Forgeties79 4mo ago“Here’s a year of credit monitoring. Be grateful.”
- close04 4mo agoMoving to another solution involves some expense and operational risk (changing procedures, increased human error rates, locking yourself out). Even though the risk of staying with the existing solution goes from "unlikely" to "possible" (so maybe from yellow/amber to red), a lot of companies rationalize it as "but now the provider will be extra careful so the likelihood is actually lower". Crowdstrike had a famous incident and is still probably #2 in the cybersecurity world. Sometimes assessing risk is a funny business.
- seb1204 4mo agoTrue, but how come such risks are addressable when adding AI or opening up to yet another API or when some savings are promised with a new product/product feature?
- close04 4mo ago> when adding AI ... or when some savings are promised Because savings are promised. And who could say no to AI? (/s) There's always some risk mitigation possible but it's costly or inconvenient. Companies pretend the risk is lower so they can do whatever they wanted to do but now with less accountability. The risk matrix says so. But sometimes the tradeoff is genuinely not worth it. The bottom line is that each company has to do it's own calculations and decide whether moving is overall a better choice. Which risk is higher, that your provider is breached again or that you have new operational issues with the new solution. Which costs more, a chance of another security issue, or the guaranteed expense of replacing the solution? You do the same math at home all the time. Your washing machine leaked once, do you replace everything or just patch the hole?
- fpoling 4mo agoI worked for a big company that switched from 1password to Keeper. The transition was smooth and I do not see why it shouldn’t be as long as IT knows what they are doing.
- ivanmontillam 4mo agoThis. If you want to be a security vendor reseller, just make sure to sell to orgs that have a compliance requirement, either by law or similar. Do you sell firewalls? sell them to banks or something. Anti-malware endpoints? Insurances too. SIEMs? payment gateways for their PCI DSS environments. Price it just below what would be the fine for not complying, that way you maximize the invoice. I stopped playing the security vendor reseller game because it got too boring this way to make money.
- bko 4mo agoI think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data. I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness
- brendoelfrendo 4mo ago> I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. Yeah but wanting a product like LastPass doesn't require that you use LastPass. There are many good alternatives.
- bko 4mo agoWhat's the solution? Don't have a CRM and store stuff about customers under lock and key? Don't give access to the CRM to any employees? More security training about clicking shady links? I don't get how you think some other competitor would be better suited against this threat. The right solution is to mitigate the damage. CRM has minimum available stuff, like names, addresses, etc. Don't keep stuff like payment information, passwords, etc in that place as that's the vulnerable system. It seems like that's what LP does and probably every other company in this space does. Again, it's entirely reasonable to have an off the shelf CRM, pretty broad access to it. You try to prevent phishing email or phone scams (assuming this is what it was) but you have 800 employees, its bound to happen.
- iamacyborg 4mo ago
- TimXare 4mo agoAt some companies, "approved security vendor" just means the breach comes with procurement paperwork.
- toomuchtodo 4mo agoIt is inertia. Customers are sticky, they do not switch unless they have to. If you're an enterprise, you have to go through establishing a new vendor relationship, onboarding a new password vault with your IT team, communicate it across the org, migrate data from the old password vault to the new password vault, etc. There is a real cost in time and resources to do this, and so, many avoid it until they have no other choice. Lastpass is owned by PE. Why? Because Francisco Partners and Elliott Management bought a cashflow that is sticky. Its why most software companies were acquired by PE prior to the Cambrian explosion of generative AI.
- jasonge0_0 4mo agoAlso use them as a password manager like an advanced version of Excel that fills in the passwords for you. Security isn't part of it. I have the feeling LastPass agrees.
- niyikiza 4mo agoBecause procurement is hard. Changing vendors is a big undertaking for big companies. They are certainly not going to be switching vendors every time there is an incident
- ibejoeb 4mo agoWell, these types of companies typically carry cyber incident insurance. If there was, say, a ransomware attack, the carrier is going to bring in a forensic team to investigate. If it is determined that there was negligence, like not patching a system, that will be used to deny a claim. This might be a little different from the lastpass situation in that it's an untrustworthy vendor, but there's still significant exposure. If this bank were my client, I would make sure that the decision-makers were aware.
- FireBeyond 4mo ago"We need to be able to answer an RFP that asks "do you have a comprehensive credential management system?"." Just like a previous employer I had, on background checks. "We need to run one. We don't care what you did or didn't do, if you're doing good work for us. But some of our customers require that we have performed them."
- farfatched 4mo agoWhat's the risk, and does that change by moving to an alternative? Companies deal with leaked secrets a lot. A company already using a password manager is ahead of the game. Suppose they move to a competitor. That's a migration and training that someone has to drive. What do they gain? Another company that can also have exploits? Or they self-host, and now have to fund that, and still potentially get exploits? Ultimately, this likely isn't that big of a deal for a company. And they have to weigh it up against all the other things that they can be doing.
- wongarsu 4mo agoCompare https://hn.algolia.com/?q=lastpass https://hn.algolia.com/?q=lastpass to basically any other password manager, like https://hn.algolia.com/?q=1password https://hn.algolia.com/?q=1password or https://hn.algolia.com/?q=bitwarden https://hn.algolia.com/?q=bitwarden Those companies do not have the same number and severity of security incidents. lastpass is truly in a category of its own
- parpfish 4mo agoi'd love to switch from my lastpass family plan to... something else. but there is a non-trivial switching cost to migrate several people (with varying technical aptitudes) that each use several platforms. if 1password had a one-click migration flow they'd be able to win over a lot of converts.
- vel0city 4mo agoFile > Import > LastPass. Log into LastPass. Now you have your LastPass details in 1Password. https://support.1password.com/import-lastpass/?mac https://support.1password.com/import-lastpass/?mac
- mhurron 4mo agoYou pretty much export your data from lastpass and import it into 1password. The only thing it doesn't do is have 1password log into your lastpass account and pull it out itself.
- fidotron 4mo agoThe one that amazes me is Okta. OK their Mac UX is great, but given their rate of incidents how can you trust it? Clearly this stuff is not actually bought based on track record.
- lowdude 4mo agoAs someone that is not really in the game, does Okta have such a bad track record, and are there alternatives that are considered solid? From the outside, it seemed like EntraID is a bit of a burning dumpster fire, while Okta seemed expensive, but usable and decent (from comments I read)
- mrhottakes 4mo agoThe current default for lazy enterprise customers seems to be an unholy tangle of Active Directory, Entra, and Okta. If you use all three it's 3x more secure, right?
- Avicebron 4mo agoOkta I get, Entra I sort of get. But AD is great.
- jordanb 4mo agoFunny I used to work in an org with Okta. Having your own auth workflow was instant fail with the well architected framework committee. Using Okta was instant pass. I don't necessarily disagree with that policy but given that Okta was breached several times while I was working there, it was interesting the extent to which our CSO had blinders about it.
- eddieroger 4mo agoLiability is the answer! If you build an auth system and it fails, it's your backside. If Okta fails, it's theirs. Enterprises buy products as much as they buy protection from problems.
- DANmode 4mo ago> They were using LP immediately following a previous LP security incident “Yeah, but they fixed that!” Normies don’t pull the historical list of breaches and vulns. They just read headlines.
- dwoosley 4mo agoI’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were the ones that had been breached in the past. Until the execs and board see the dollar impact themself and not just read about it, the security program never gets the funds it needs. I’m not saying I recommend LastPass for that reason, but I wouldn’t write them off for that reason.
- gonzalohm 4mo agoBut LastPass has been breached multiple times by now. I don't think they really care
- dwoosley 4mo agoThere are lots of types of a “breach”. The first and second (the major ones) were likely related so more like one continuous incident. This one was a vendor breach that had access to their data so not a reflection of their security program as much as the first. I’m not saying you’re wrong, I’m saying you can’t tell from this incident.
- sys_64738 4mo agoWhat happened to the old days of only getting one chance to f-up? Once chance and they should be gone permanently.
- felmos 4mo agoIf the execs and board of a password manager company need to experience a breach to take security seriously, I don't really know what to say.
- dwoosley 4mo agoWeirdly being a security company actually can have the opposite affect. A small portion of potential customers or investors assume the company is more secure because they are a security company after all (and should be); therefore, the customer's security review are less stringent so exec can get away with smaller internal security budgets. Of course good security companys with good leadership doesn't do that... but those aren't the big companies.
- hosteur 4mo agoHow does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.
- xtracto 4mo agoThis. KeePassXC plus Google Drive client is all you need.
- kirici 4mo agoPassbolt and Bitwarden can be self-hosted on top of offering the usuals pros like MFA, an API incl. integrations (e.g. https://external-secrets.io/latest/provider/passbolt/ https://external-secrets.io/latest/provider/passbolt/) and a better UX that does not involve syncing files between team members
- mook 4mo agoI use KeepassXC, but I have no need to share passwords with other people. In a corporate situation that would probably not work as well.
- commandersaki 4mo agoE2EE done properly is why. See 1Password security whitepaper for how.
- sigzero 4mo agoKeePassXC is not for a "normal" user. It really needs to get default entry tempates [1] out the door. [1] https://github.com/keepassxreboot/keepassxc/issues/8228 https://github.com/keepassxreboot/keepassxc/issues/8228
- dsjoerg 4mo agoit's "trivial" in the sense of "I can launch the app in 2 minutes," but "non-trivial" in the sense of "I have a working, synced password manager across my devices with good security practices."
- hosteur 4mo ago
- sys_64738 4mo agoI remember ten years ago telling our so-called leaders that the data will get leaked from LastPass. They were all gung-ho about it being secure blah de blah. Luckily most of us don't work there anymore.
- burnte 4mo agoI had one of their salesmen harassing me back in 2018 or 2019 when one of their many breeches hit. I said "this is why."
- lazyasciiart 4mo agoIf you think I'm going to try and get my mom onto a different password manager, after it took literally ten years to migrate her away from the printed list in her purse...
- njarboe 4mo agoA printed list in her purse has certain beneficial properties that a password manager does not.
- lazyasciiart 4mo agoSimilarly, it has certain deficits that a password manager does not.
- QuantumGood 4mo agoIf the passwords are still not known, the "breach" is not a fail for the end user. If the master password to the vault is secure, and the only way to the vault is still only through the master password, it's still doing what the end user wants it to do. "Breach" is meaningless without qualifiers.
- nkrisc 4mo agoI think most people use password managers for convenience, not security.
- yieldcrv 4mo agoEnterprise IT is all about outsourcing enterprise IT nobody cares, there’s like 2 people whose job it is to care, one works for your company and one works for the third party IT company - and maybe your company’s General Counsel but even they just care that your CTO said they care everyone else just has whatever enteprise service was presented to them
- sidewndr46 4mo agoAs others have pointed out, LastPass is often chose for compliance. Not for security.
- jagged-chisel 4mo ago[dead]