LastPass requesting password reset after facing unknown anomaly
blog.lastpass.com
blog.lastpass.com
Either way, they seem to be taking this seriously, even if they are just being overly paranoid, I find it comforting.
as far as i can see they are being extremely paranoid. they seem to be monitoring (and following up on!) traffic flow, which is itself pretty impressive, are flagging this even though they have no other error signs, and have done a good enough job in their implementation that can say, without any more details, that the only risk is via brute force cracking.
i use keepassx locally, but my take on this is that they are way better than average. this kind of report would make me use a company, not switch from them.
Transparent would have been describing exactly what they saw
So the post basically means: "we have no idea what's going on/went on, but here we are, informing you early. Here's the steps we have taken and here's the steps we are going to take"
You can't have everything: On one hand, everyone wants to be notified early (see playstation network breach), on the other hand, people want to know everything when they get the information.
I think that's asking a bit much. Either we get informed early ("we've seen something strange, but we have no idea what's going on") or you want all information ("we've discovered and researched a breach. here is what's happened", followed by a story that spans two weeks).
As lastpass contains potentially sensitive data, I'm happy they chose to inform early, even before they had a complete picture.
(disclaimer: I'm not using LastPass nor any other password manager as the risk of losing access to that and to all the services I used them with is too high for me)
Can you point out some examples of "corpspeak" in their notification?
This sounds exactly like the release we got from Sony a few weeks ago, detailing the points of entry, the volumes of data released from their servers, and estimates about who is and isn't affected. And who can forget when Sony told us all exactly what steps they were taking to make sure this wouldn't happen again?
/dumb
Anyway, since many are mentioning 1Password - I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows.
Also, since I use two-factor authentication, I wonder if that's the reason they have not asked me to change my password?
"We're only forcing the issue right now you when we see you come from an IP you haven't used in the past few weeks (if you disable logging logins this might mean immediately)."
It hit me straight away even though I'm using a static IP, because I disabled the logging of logins after this happened: https://grepular.com/LastPass_Vulnerability_Exposes_Account_...
I find that Keepass, with the database saved on my Dropbox folder, works well. No browser integration needed - Keepass registers an OS hotkey (at least on Windows) for ctrl+shift+A which will autotype ${USER}TAB${PASS} in the currently focused field, using the title of the browser window as the entry to look for in the pw database. Great for a free solution.
Just wanted to add that it's possible to configure any auto-typing (the default is ${USER}TAB${PASS}), which means sites having all sorts of other info are easy to work with as well.
I actually wrote a blog post about using Keepass with various tricks: http://www.loopycode.com/solving-sign-up-anxiety/
Edit: Some more negatives to password storage. Must protect stored password file. May be required to log access to stored password file for compliance reasons. Stored password files may become corrupt and stop working.
I tried to make traditional password managers work for a number of years, before realizing that the traditional approach (password storage, master password) is fundamentally flawed and introduces more problems than it solves.
Additionally, some accounts have restrictions on usable characters or password length. The FAQ for SHA1_Pass says "try base64 half-encoding, its only 14 characters, and if that's too long maybe you shouldn't be using that website". Well I'm sorry but some BANKS do not allow passwords that long. You and I both know it's idiotic, but some banks have a small maximum password length, and some of them even restrict you to alphanumeric characters only.
I applaud SHA1_pass for trying to be innovative, you don't know what works unless you try it, but it looks like the result is a failure to me... too much complexity generated around the goal of trying to make passwords easy to remember, yet hashed to be secure. Just generate a random password with Keepass, whatever length and character sets you want, and store it.
What's the big deal? Yes, there's a chance that Keepass didn't do their encryption properly and your master password will be crackable, and someone will hack into your dropbox account and then have all your passwords. But with SHA1_pass there's also a chance someone will guess or socially engineer your passphrase, and since all your site words are "facebook" for facebook etc etc they too have full access to all your accounts.
This is an inaccurate statement. You remember a sentence. Sentences are naturally and easy to recall. The fat, green stick. for example. And then a word for each site you visit. That's it. You can use it anyway you like and take my samples for what they are... samples.
What's the big deal?
Controlling your passwords on your devices and not relying on others. Passwords are IT Security 101, if you get them wrong you fail.
1) Login in 'offline mode' then reconnect your cable/wireless connection and go to gmail... This is the preferred method. 2) Download Pocket, and have it find your local offline copy from the drop down of files and login there.
Edit: Also, SHA1_Pass does not rely on websites or anything remote from your device to operate. It just requires you (the user) and your brain ;) That's the biggest reason I wrote it.
You can read up http://www.passpack.com/en/faq/
And why the hell didn't they use scrybt in the first place? For a company so paranoid, that seems to border on neglect.
Nope. I'll make strong passwords on my own and encrypt my own copies, thanks.
This is simply not a feasible solution for the general public. LastPass has demonstrated that they are 1. paranoid as hell and 2. that the only real vulnerability in this situation is that if you have a dictionary password, it may be able to be brute forced, if the worst case scenario happened. They even outlined steps that they are taking to fix this problem.
LastPass is an incredibly smart security solution for the majority of people. Telling us that they are taking steps to protect their users because of an event that they haven't even verified was a compromise is better than you discovering that your bank password was stolen because you forgot to update your firewall.
As for getting access to his data anytime: Yes, except if he has a backup.
Worse case scenario is something causes the file to get deleted and that propagates to all of the other hosts and deletes their local copies. But yes, I have backups so that isn't a problem.
My passwords are encrypted and accessible at all times, even if Dropbox is down or I lack Internet access...
However, to be more accurate:
"So is LastPass, unless you disable offline login, or enable the use of a Yubikey"
This freakout reminds me of the radiation poison bullshit from a few months back. Bananas have radiation therefore bananas are dangerous. Practicality dictates that you are plain wrong.
On the other hand, if you get my LastPass password you better have my grid too (I keep it online so I can access it wherever, password protected). Additionally LastPass is working on SMS codes for login.