LastPass confirms hackers had access to internal systems for several days
techradar.com
techradar.com
So the threat model of a "normal user" is that one of their reused passwords will be breached and released, and these services prevent that.
If you are in the situation of being specifically targeted because of a system you have access to, you have an entirely different threat model and should consider the tradeoffs in light of that.
The centralization can't really be avoided and is also somewhat a separate issue. You can weigh the benefits and risks of doing it yourself, keeping it in a physical book or stack of postits, paying one of these companies etc but it has to happen if you're truly using unique passphrases and none of these is free from risk, either of discovery or unrecoverable loss.
- Rotating important passwords, so old copies are less useful
- Bucketing into multiple vaults, easier with file based tools like KeePass, though you could have separate accounts on various SAAS vaults
- Requesting to be forgotten from old services, especially those which have shared PII and passwords
- Hardware 2FA
It is intellectually similar to the argument that "the cloud providers might have downtime, but they're probably going to have less than your private DC due to the economies of scale and returns on investment in reliability"
I think the key word here is "initial" - they have no evidence thus far that user data was compromised, but that doesn't mean it wasn't, or even that evidence doesn't exist - right?
I get wanting to make a statement promptly and reassure customers but I'm not sure how valuable this is for users of LastPass. Should they just assume everything is fine until the company discovers it's not?
That is how it works. You can't prove a negative, so the data is not compromised until the investigation shows that it is.
The developer's credentials was compromised, but those credentials don't give access to the production databases where customer data is stored, then there is a good reason to assume no customer data was breached. Of course you still do due diligence and investigate anyway, just to be 110% sure.
Notifying customers of a breach is a much more ethical approach than sitting on the information. In some countries it is even mandetory to report breaches to affected users, which I personally think is better than not doing it.
The activity in 2011 was never confirmed to be a breach. It was a overcautious response on LastPass's part after seeing an outlier in the logs. The investigating party gave a report saying they couldn't find anything, and the CEO later gave a statement saying they overreacted to an outliter out of an abundance of caution.
Things like notes and financial information might need special attention, but the basic process is prety quick.
“What doesnt kill you makes you stronger”, so to speak.
I’m thinking that something like unrestricted dev access for four days would be more like a death blow, though. I suppose that depends on how much source code was exfiltrated and how many backdoors got planted in systems, etc.
I don't consider that "short term" thinking.
In the short-term, definitely a drawback, and one of the reasons that I’d always recommend something like KeePass for most situations.
The big red flag here is that they didn't catch it for so long! How did they not notice?
The chances of LastPass and a competitor getting hacked is very low.
Password manager is insanely convenient, but its all your eggs in one basket