Lastpass Security Incident
blog.lastpass.com
blog.lastpass.com
"This comes just months after LastPass confirmed that hackers had stolen some of its source code in August and had access to LastPass’ internal systems for four days before getting detected. It looks like this new attack is connected, as Loubba says it determined that hackers gained access to user data “using information obtained in the August 2022 incident.”"
https://www.theverge.com/2022/11/30/23486902/lastpass-hacker...
it's certainly not acceptable that all they are saying is "certain elements of our customers’ information." very unacceptable, if it's credit card numbers or home addresses, they have to reveal that. the current language makes it look like they want to hide some kind of very bad news which is worse. Also their August post indicated that the developer account that was compromised had no access to customer data, so why exactly was that wrong.
The current update fits pretty well exactly on my screen, so I saw no hints that it was a series. After seeing the usual corporate speak and signoff, I assumed that was it.
I went looking in their history of posts for more information on the August incident but couldn't find anything, as the older installments do not show up individually.
You must make sure the exported CSV file has everything!
oh wow, what a surprise.
For a password management company, they can't even be bothered to fuzz their export functionality. QuickCheck works unreasonably well on `import(export(a)) == a`.
But maybe it's intended to be buggy, in order to keep you in their walled garden. Clearly the sync between devices works, so they have solved this problem.
Presumably they don't use CSV to sync, they're using a saner json/etc. data structure that they're not letting us export ourselves. Seriously, being limited to CSV in this day and age...
I want to move but I'm terrified of the export process
* custom "items", so instead of "Password", I also have my own * attachments, which I know 100% are not exported. There is a CLI app to help with that, but still horrible * I have large notes with weird characters, which makes me concerned if they will be exported properly * Last time I checked, the CSV seemed very broken (not respecting the standard), I'd be surprised if it imports properly
That's the reason why I haven't moved.
I'd move to bitwarden, but the lack of tags is too much for me. I use tags everywhere, I don't want to deal with directories anymore, so 1Password it is.
I... would definitely not recommend them, no.
They seem to have a CLI to export attachments!
One issue I ran into: the CSV file that "downloaded" in the browser didn't have all of my passwords, only about ~20 of ~400. I had to copy and paste the CSV text in the browser to a new CSV file with a text editor. But upon reviewing that, the format of the passwords was fine.
I have been a paying customer of Lastpass for about 15 years. I moved to Bitwarden for all sorts of reasons. I work in technical information security so it was also for that teason (but not only)
There was some apparently compatible rust implmementation in PostgreSQL tho...
I self host it for a year or two and it is a single container. The BW officer docker distribution is a nightmare.
Add to that a proxy with caddy and you get a great solution.
EXACTLY why so many companies opt to stay on-prem, to the amazement and bewilderment of every vendor sales rep that calls on the phone.
Go ahead and ask them which Cloud providers their company uses. Ask them which open-source libraries their SaaS uses. Ask them to show you the audits they've performed on THEIR supply chain this year. You won't get any answers.
So sick and tired of everyone jumping on the "more links in the chain is better" bandwagon.
> Our investigation determined that the threat actor gained access to the Development environment using a developer’s compromised endpoint. While the method used for the initial endpoint compromise is inconclusive, the threat actor utilized their persistent access to impersonate the developer once the developer had successfully authenticated using multi-factor authentication.
This is similar to other recent hacks, e.g. where a crypto company was hacked when a developer opened a malicious PDF he thought was a job offer.
So, in other words, being on cloud vs. on prem, and potential supply chain hacks, had nothing to do with it.
So sick and tired of everyone jumping to conclusions to fit their preconceived notions of what is good/bad when it comes to security.
When you're on prem you only have to worry about your own employees opening sketchy PDFs. When you're not, you have to worry about everyone in your supply chain opening sketchy PDFs.
Nevermind the fact that the next time a major world conflict occurs, the big 4 cloud providers will probably be destroyed, taking about 90% of the western economy with it.
This is just plain wrong. When you’re on prem you have to worry about configuring all of you hardware and software correctly yourself. Your firewalls, your SSH server(s), off site backup systems, hardware failures, software patching, access points to your network – the list goes on. Some of these are true for cloud services as well.
They are just different trade offs. Sometimes on prem makes sense, and sometimes cloud services makes sense. You can’t say that security is less of a concern in one of them.
> Nevermind the fact that the next time a major world conflict occurs, the big 4 cloud providers will probably be destroyed, taking about 90% of the western economy with it.
And it somehow does _not_ take your on prem system with it? Even though cloud providers are spread across the whole world, and your on prem system is most likely in one, single location?
That's absolutely not correct. Besides, I have more respect for the security and operations procedures for AWS, GCP and Azure than I do for 99% of startups running their own infrastructure.
But my primary point is that you seem to be arguing that being on prem is inherently more secure, and more importantly, being in the cloud made LastPass less secure, despite the fact that the breach vector in this case would have been equally effective regardless of whether they were in cloud or on prem.
On-prem business is a diversified attack vector. Cloud storage is a consolidated attack vector. Would russia rather attack 100,000 small diverse targets, or one enormous target with 1,000,000s of customers?
Also, attacks against 'on-prem' services still scale, in the sense that an exploit against a service's code can be used on any number of independent deployments of that code. The solution to that is to actively avoid monoculture. [0]
Well, even with private cloud and on-prem these are pretty relevant questions...
I Worked with a government organization where I was part of the team on-boarding a new on-prem system. It was purchased through a tender, where on-prem was a requirement. The product was SaaS by default, but they offered an on-prem version. We pretty much got a copy of the stack of containers and docker-compose file that they used to run their SaaS offering.
While running the application, I was missing a lot of context, since logging was minimal, so I asked the company how to connect a log store to get an overview of all the sub-systems. There was no option for this (then how did they monitor their SaaS?). So I used docker to get command line in the containers and see if I can find some logs there to then get into a log store. In one of them, I noticed an error because something in the container was trying to phone home with telemetry, to a server that wasn't owned by our supplier. 'Luckily', our on-prem box didn't have an internet connection, because of the sensitivity of our data.
This was when I realized that our supplier didn't roll their own containers, but just used off the shelf stuff they didn't even audit. So who knows what their SaaS offering was leaking from these containers? I mentioned this to both internal IT architects and the supplier and nobody really seemed to care.
This is a supplier that was named 'Leader' by Forrester and got a $30M funding round last year.
And, to be fair, it's a large part of the Docker experience.
I recently had a pretty much identical experience with a vendor that is industry leading in their sector and counts most large companies among their customers. Just imagine what their cloud looks like.
A supply chain attack on these guys wouldn't even be difficult, and the only reason I can imagine we haven't heard about it is that we just haven't heard about it.
I would suggest to split this problem into two different problems - the processing ("data in use") vs data on rest. Each of these problems should be tackle with a different solution/approach.
I'm working on the tackling the second approach and if anyone want to talk just reach out (reply/mail/link/whatever you prefer)
- OS sees the device as a keyboard
- Two versions. One with bluetooth, and one with only USB for a little more security.
- Open source software package to sync your collection of PSDs
- Open source browser extension to autofill passwords
- Tiny keyboard on the device (detachable to share between your collection?)
Usage:
1. Install browser extension
2. Navigate to a password field
3. Follow prompt to populate password
Alternate usage:
1. Manually search for password using the device keyboard
2. Click into password field in browser
3. Press button on device to have it type the password
Or of course you could just view the password on the device if you prefer.
Passwords and login credentials are dead. No user wants to deal with them. Password managers are a solution to somewhat sanely and securely manage this complexity, and not something that the average user wants to think about. In that sense, they don't improve security overall, and introduce many other issues (a centralized honeypot, in the case of services like LastPass).
The industry has been trending towards OTP, FIDO, WebAuthn, and all sorts of identity solutions, instead for years now. It's clear that nobody wants to manage credentials, and having a separate security device is not something mainstream audiences will adopt, so maybe by integrating it with smartphones, this will finally catch on.
It will likely take years for most of the industry to move away from passwords, and we'll likely still require traditional credentials in some cases. The myriad of standards out there is a hurdle for adoption, but it feels like we're settling on something that might be usable for everyone.
It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells).
Unfortunately google requires either their app or SMS. They dropped pure totp for some reason.
Awful experience.
Gmail TOTP still works fine?
I use TOTP with my Google Account all the time. If you have a phone registered with that Google Account it will default to the push notification system first (it might even be possible to make this no longer the default, I'm not sure), but you can always click the button to switch to alternative 2FA options.
Google plainly dropped totp wherever possible in order to confirm everyone's identity.
Totp was an open standard that didn't help them spy on anyone, and they regret releasing it bigtime.
You have to add a phone number, turn that on for 2fa.
Then you can add TOTP.
Then you can disable SMS.
SMS will still work for at least a week because fuck you.
There are alternatives to this, such as typing a code into the login prompt instead of following a link (which will be submitting that code). This does limit the size of token that can be used because it needs to not be too inconvenient for the user to type, but if the code's validity is sufficiently short-lived, and properly unguessable, this can be done without compromising security any more than it already is by involving SMTP in the process.
Of course the other problem with email-only password resets is that users often receive email on the same device they are trying to authenticate – so if someone has left a machine unlocked with their mail account logged in, an attacker can gain access to any site/app that uses this password reset mechanism. One of the reasons that email and SMS are not great choices for a second factor, and even less good choices for what is sometimes effectively the only factor.
I actually occasionally fantasize about implementing a mechanism that I could use from my desktop (where my password manager is) to send passwords as needed (e.g. one at a time) to my devices (I really like not worrying about syncing whole vaults). Encrypt the password using an epehemeral key (gets deleted after 60 seconds, for example) on the transfer service and a local key derived from a random six digit number. Display the number, send a url to the device, and anyone hitting that URL has 60 seconds to enter the six digit code and it decrypts the password and drops it on the device clipboard. This is about 1000 times better (and over-engineered, naturally) than my current practice of "paste it in a slack message to myself."
User authentication has been a hot mess for at least two decades. Passwords need to go.
Which, as someone else explained below, is far superior to plain text passwords.
https://www.crowdsupply.com/sutajio-kosagi/precursor/updates...
Probably just needs a screen and like 3 buttons: record/play/navigate mode (use your keyboard to actually navigate).
PS: I have worked in computer security and I am drunk. Eat your salt
Anyway - it's not a good position to be in.
This reminds me of a very brief security review I did of a 3rd-party browser extension that was being installed on everybody's laptop at a previous job. The extension itself had very little code, it was just something that bootstrapped with code from the company's servers. There was no real way to review it or freeze a reviewed version.
The kicker was that the server-provided JS was being loaded over plain http (and no, nothing was checking signatures or anything like that).
Still, local decryption is more secure than sending the master password to the server (so, just compromising the server holding your vault wouldn't be enough to steal your password). I think I will switch to BitWarden which uses the same approach, LastPass seems to be getting hacked alot nowdays.
I am concerned at some level on the lastpass breaches, but I am less affected so far than I have been by the equifax, target, and t-mobile breaches. I have had years of free credit monitoring since each one of those handed out enough data to compromise my identity several times over.
Edit: hadn't considered that addons also autoupdate by default when back online.
Won’t be touching LastPass again except offline, while I figure out where to go from here. I had been putting off finding a better password manager, but this is the last straw.
Keepassxc supports Yubikey, so you can lock it down strongly!
> So in a sense, it makes your password stronger, but technically it doesn't qualify as a separate second factor, since this is not an authentication scheme and also because the expected response doesn't change every time you try to decrypt your database.
I'd argue that the biggest threat against a (non-cloud-synced) password manager is a local database compromise, and the Yubikey does not meaningfully help here.
To be fair, I don't think anything can help in this threat model – a password manager is ultimately a key/value storage for bearer tokens, and if an attacker can exfiltrate those key/value pairs, it's game over.
So the Yubikey certainly helps against an otherwise too short/reused password manager unlock password, or against somebody shoulder-surfing your password and able to steal your database, but not otherwise tamper with the device you're decrypting it on.
But other than that – if somebody can steal your local database and sniff your password (e.g. via a key logger), they can probably also sniff your Yubikey challenge/response, which is returned via the USB HID protocol as well.
Also, you omitted an important sentence at the end of the FAQ that you quoted. The response changes every time you save the database. Yubikey uses HMAC-SHA1, which is a hash of a shared key and a counter. The counter, and hence the response, changes when the file changes. That helps a lot, with constantly rotating the master key. It also adds 140 bits to an otherwise easy to remember password.
It seems to kick the attacker out of getting future database updates after a point-in-time compromise, but do users using a password manager frequently change their passwords stored in it? At least I don't.
Syncthing improves the security, for instance, just in case a vulnerability creeps into the keepass code.
Syncthing works, has no central server to be beholden to, is free, and I have much more stability with it.
The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open source? "How many years of experience do you have in open source?"
(Probably because the recruiter had a list of tech and skills required and simply went through it.)
Anyway, I went with it and eventually got a coding assessment. The docx document told me to implement a little deck of cards in Java using classes and inheritance. This was for a senior position.
I did not do that and withdrew my application.
[0] https://www.joelonsoftware.com/2006/10/25/the-guerrilla-guid...
We've had candidates with "20 years of experience" completely unable to do what amounts to "call a web service, deserialize some json, write a couple for loops and if statements, and post back some json to a web service" in over an hour, or in a take home scenario.
It will never cease to amaze me that there are people employed in this field that just. can. not. program.
At my previous company, we had a technical assessment - this was about ten years ago now. It boiled down to: read XML, do some math / business logic, and build a REST API to do so.
Interestingly, ten years ago, at least half the applicants said they found it interesting because they had never worked with REST or JSON before. A lot were Java developers, so the XML part wasn't a problem, and they would often add some SQL database as a bonus.
But 5-10 years later, as development switched to (Node)JS and web, it became the inverse and people said they had never done anything with XML before.
Yes.
But I think there's a reasonable upper limit to the amount of time a company can expect someone to spend on a job opportunity.
If they're burning an appreciable amount of that time on a trivial coding exercise, that's not great.
You're missing the point.
The premise is that someone capable can blast through trivial assignments in no time. Either this is the final proficiency challenge or there are subsequent, harder questions. In the former case, why not see the salary/offer and then decide?
I have a GitHub profile with a lot of code on it and on my resume I highlight projects I've done a lot of work on. "What if faked tho?"--there's literally too much there to be worth faking. If a hiring manager looks at my resume, has the option of going to my GitHub profile, and between the two goes "I'm going to hand him a college-level Java problem because I'm not sure," then there probably isn't a way we're going to work together. And that's okay, on both sides of it; there are a lot of developers who aren't bothered by that kind of low-trust relationship. I am. Not a fit.
(This is in contrast to, for example, asking a question like that during an interview. Interviews are bidirectional, and are showing an investment in the hiring process on the part of the employer. If a card-deck Java problem is worth addressing with my time, then it's worth addressing with your interviewer's time. The contrapositive is also true.)
However, I do understand where the offline exercise idea comes from - it's not necessarily about lack of respect for candidates' time, but is generally done with the best of intentions in response to feedback, because candidates complain that the interview technical exercise scenario is needlessly artificial: in a live interview candidates do not usually have easy access to their usual tools or Google/Stackoverflow, and many feel pressure and panic from having to code/problemsolve live while someone is watching and feel they would do better if left alone to do the same thing for the same length of time.
Given the incredibly strong feelings either way, perhaps it might not be a terrible idea to let people choose which approach they prefer; but I've never seen any company's hiring do that, though, thinking about it, there really is no good reason why not (provided I still get to talk through the results of the offline exercise with the candidate during the live bit!)
Making it an option for somebody who would rather wouldn't be bad, but yeah, as you say, nobody's learning a lot about the other people that way, and they're probably more important.
(The OP's card deck problem is just faintly ridiculous and a bad allocation of the candidate's time, and I assume there are more hoops to jump through afterwards.)
> If a hiring manager looks at my resume, has the option of going to my GitHub profile, and between the two goes "I'm going to hand him a college-level Java problem because I'm not sure,"
I know we're talking hypotheticals. I get your position 100%, and good for you.
My view is that I'd tell you that
1. I've seen your Github profile
2. However, I didn't have time to go through your entire Github profile looking at your efficiency and productivity. I want to do a quick, ad-hoc programming exercise to see how fast you operate on basic tasks (which #1 doesn't readily address). I expect you to crush it really fast and this is the only coding exercise I'll have you do.
To me, that doesn't seem unreasonable if I'm upfront about expectations. Your response will also say a lot about you (not necessarily negative, but for fit).
These requirements come up because someone always slips through diligence. While you might be getting punished, interviewers are trying to de-risk candidates as much (and as fast) as possible.
Right. And to do so in good faith, this absolutely can and should be a collaborative exercise with an interviewer. It demonstrates that the employer has skin in the game and isn't body-shopping. Once you're out of junior/low-mid hiring, this is really, really important to getting quality candidates to go through your funnel.
> interviewers are trying to de-risk candidates as much (and as fast) as possible.
Of course they are. They should also be aware of the tradeoffs in doing so.
Although I experienced recently what you said exactly! I was asked to build a deck of cards for the screening interview. It was a fun back-and-forth and I felt really good about things. Then in the next steps, I was asked to implement Conway's Game of Life. So like, I've been programming professionally for 13 years, I'm well aware of GoL and maybe should know how to do it, but I've never bothered since there are just a mountain of other projects, programming and not, that interest me over that. It's all good if you want your engineers to be able to solve that type of problem as it's your company and you do what you like with it. But like, they were an e-comm company and I have a ton of e-comm experience and was actually pretty into what they were doing, so why were they using something like GoL to assess me?
On the flip side of things to get a little tangential, I often feel companies reject me because they just don't like me, and I wish they would just say as much since that hurts way less than being told I'm a not a great engineer, lol.
Anyway, maybe a bit too much TMI... interviewing right now is a bit of a shitshow with all the recent layoffs and I'm maybe a little bitter, but also realllllly enjoying unemployment while it lasts.
If the first, that sounds like a terrible question. If the second, that sounds like a quite straightforward fizbuz style coding task.
> I'm well aware of GoL and maybe should know how to do it
What do you mean “should know how to do it”? I don’t think you should have memorised the rules, or an implementation. But I think if you are a software developer you should be able to turn human language into code. That is a key skill of the job.
Recruiters and subsequently hiring teams are often told they can't give much actual feedback to candidates, out of a fear for legal challenges. I cannot assess the validity of these fears, just relaying what I heard. I guess folks have been burned when their presumably-good faith attempts at feedback were twisted into inclusion and equal opportunity cases (which are also important subjects that I don't want to dismiss either).
Sure there are different ways to do this but it's a small enough task that the quality of the solution is easy to judge.
I think the nail analogy works. If a blacksmith can't make a decent nail he shouldn't be hired. Same if a developer can't use one of a few very well-known standard library data structures to implement a deck of cards.
Are there any good ones? I find that people introduce an analogy...it is discussed, another 'contradictory' analogy is introduced....and eventually someone has 'won' the argument referring to something completely unrelated, and thereby have 'won' the original argument, by default.
My boss is particularly good at his :-) To me, its a form of gaslighting.
As soon as i hear "But what if...?", or "it's as if...", I refuse to budge, and simply ask "Are we talking about 'the original subject', or 'Blacksmiths'? If it's the latter, let's talk about Japanese swordsmanship first, then the history of European metallurgy first - just to be on the same page."
Often used at the same time is the No True Scotsman fallacy.
Set ridiculous boundaries on the analogy, ignore the fallacies, and the original subject soon gets re-discussed. It's amazing how many people actualy find that uncomfortable.
This task is just a pre-filter, something to weed out surpirsingly high number of people who claim to be able to code but actually can't.
Add "This person doesn't know about my firm's hiring process, aren't willing to do basic tasks, doesn't want to work at my firm," etc.
An engineer at our competitor got laid off and my PM found out and hired the guy to do FPGA work. My PM knew the guy through some contracts we had with the competitor and assumed he was an expert in the field. Turns out the guy was more of middleman between program management and the engineers so while he could talk about the work, he hadn't really done it in like 10 years. My PM got the hiring expedited and since we don't really do interview tests in our industry, the guy was now on our team before anyone could ask any pertinent questions.
Long story short, the FPGA team starts assigning him work but it's taking way too long and he's asking for more documentation and for help on things that he definitely would have worked on in his supposed previous job. Eventually we all figure out that he kinda overstated how fresh his skills are and we transition him to a sort of documentation role so he wasn't burning hours on things he just couldn't handle. While he was perfectly capable of doing that kind of work, it involved a lot of insight to our design so it took him a while to get onboarded to the system and able to properly describe the design. Eventually he was doing good work and got the project to the point where he wasn't needed but he left a bad taste in everyone's mouth. We could have hired two junior engineers to do the work he was doing for the same price and probably gotten it done much faster. After the guy transfered over to another project, we reamed out our PM about his hiring decision and begged him to give us some input next time. Of course, due to the waste of money from the last guy, the functional managers stopped taking hiring inputs from our project and would just assign whoever the fuck they thought we needed despite the kind of roles we actually needed.
I've had a few startup jobs, a couple megacorp jobs (not Apple), and a handful of mom and pop and defunct business jobs as well.
My least favorite interview questions involve regex or deep internals of BSD or Linux, my favorite interview questions are off the cuff solutions to problems presented, and then backtracking the explanation.
I've also been asked to perform job interviews for positions that i probably ought know enough about to interview a candidate for, but I went off my gut feeling about how the person acted in what i consider a stressful situation (a slew of interviewers asking asinine questions). I don't like interviewing, i am not very good at finding candidates that are "in for the long haul" but every time we were tasked with finding someone who can do X before end of Q3, my hired candidate recommendations always nailed it in that time frame. All this is to say, i find the whole process ridiculous. My CV apparently looks like a train wreck. I refuse to wear a tie or get a haircut. I'm eerily relaxed in interview situations.
My trick? one time i hung out with a CEO of an IT company from the PNW, and they basically told me everything i thought i knew was trash, my resume was trash, my attitude was trash, and the only thing i was good at was solving problems in a hurry. We did, in fact, get coffee for our meetup. I scrapped every idea of what a resume should look like - what i envisioned a perfect professional resume looked like - and started fresh. I learned to say no to most recruiters in a way that made them ask me about different "opportunities" more aligned with my personal ethics and values in the future.
I have 4 FPGAs, and i've never done anything with them, because the bitstream is proprietary on all of them. I wouldn't hesitate to tell an interviewer that i am interested in FPGAs and custom ASICs, because i am. I'm also interested in bacteria, but i won't be applying to a bioscience lab anytime soon. I certainly wouldn't say "yeah i can program an FPGA", or C, or do front end development, or any of that.
From my reading of these sorts of comments, in aggregate, most people try to impress the interviewers. I want them to impress me.
Does this make me privileged? Probably. <sigh>
On the other hand, I have reviewed resumes from people with five years of experience that are 'experts' at twenty five unrelated technologies. As soon as I see that, I think, 'yeah..... no'. I worked with some genius level folk at Bell Labs back in the mid 1990s, ten years into my career, and they were each really good at two or three things. I took note of that. Yes, they could figure other stuff out, they could move on to new technology, updating the three things that they were good at, but that list always seemed to be short.
You have to laugh at 'experienced' or 'expert at' followed by JS, JAVA, Full Stack, Python, Linux, BSD, C#, AWS, C, C++, MySQL, PostGRES, Lisp, Lua, Azure, MathCAD, DSP, AI, Excel, SystemC, Perl, regex, Bash, git, assembly, Verilog, ...
https://news.ycombinator.com/item?id=33739094
It's still archived, though:
https://web.archive.org/web/20221119032911/https://overemplo...
and
https://web.archive.org/web/20221116023708/https://overemplo...
Key takeaways:
> I started learning to code in 2019 as my new years resolution.
> Job #1 Senior front end dev
> Job #2 Senior front end engineer
> Job #3 Front end engineer (mid-level)
There are just too many niches where the knowledge we each consider necessary simply isn't. I had one particularly bad interviewer grill me on how the ARM GIC worked in detail (e.g. interconnect details, differences between versions, etc) because they considered it basic knowledge. I've personally never needed to know anything about it that wasn't in a TRM.
One question I have found useful in embedded development is asking someone to discuss the difference between a thread and a process, and the difference between thread based OSs and process based OSs. It is a general question, not bound by anything like CPU architecture, but just gives an idea into whether the person is comfortable about general memory domains.
I have mentored people, bright programmers that never worked in small embedded systems, that initially tripped all over the thread model, but eventually came to understand it.
They get progressively more complex as we go, but the candidate is fully aware they are filter questions that I hope they clear with zero effort.
When I'm explaining the process I usually preface with these being designed to gauge their skill level, not just make sure they meet some minimum floor, so there are going to be some easy questions and some that are hard and I don't necessarily expect them to answer all of them and not to get discouraged or be afraid to say they don't know. I usually just keep going until they miss a couple in a row.
If someone actually doesn't know the job, I'm only asking maybe 5-10 relatively simple questions and thanking them for their time.
I have some technical hurdles candidates have to clear, but I try to speed run past them and get the background stories on things that stick out to me in their resume. Also, hitting them with the DevOps equivalent of a LC hard right out the gate is a dick move that sets a bad tone and demonstrates a hostile process.
When I was teaching in high school the deck-modelling thing is one that the kids come up with a lot especially when it came to doing their term project. I love the idea of being asked to implement a deck of cards using Java and inheritance! Here’s my implementation:
SUITS = “♠♥♦♣”
RANKS = “A23456789XJQK”
deck = {(s, r) for s in SUITS for r in RANKS}
That’s about all you can commit to. Suits and ranks should probably be enums but we can start from these three lines and see how it goes.Sorting? Depends on the game. Value? Depends on the game, and some games give the same card two values. Inheritance? Shared behavior depends on the game and is orthogonal to the card itself and often is dependent on game state as well as what card you have. Are we even playing a game, or is this just for rendering poker themed wallpaper? Calling it a “deck” is probably wrong. A deck is ordered and may have duplicates… it depends on the game! This is more of a pack than a deck.
It’s probably an amazing question for interviewing candidates in person to see how far they dig into the premise. As a take-home question, you could probably spend a minute on the code above and then an hour on implementing three different games. Maybe that was the original docx, but it didn’t sound like it.
I did a take home for Walmart Labs once and they completely ghosted me. What a complete waste of time.
Would you really just ignore the requirements and give the simplest starter as a way to start a conversation?
Those would be better questions which could start off with a discussion about the general solution, followed by a quick “how would you model the cards part of this?” component.
public enum Color {
RED, BLACK
}
public enum Suit {
Diamonds(RED, '♦'),
Hearts(RED, '♥'),
Clubs(BLACK, '♣'),
Spades(BLACK, '♠');
Color color;
char symbol;
public Suit(Color color, char symbol) { this.color = color; this.symbol = symbol; }
}
public enum Rank {
Ace('A'),
Two('2'),
//...
}
public record Card(Suit suit, Rank rank) {
// ...
}
The question is fundamentally broken because data objects shouldn't be inheriting anything. That's in almost all cases bad design that demonstrates only that you have no clue how to write sensible object-oriented code.You wouldn't want to check whether a poker hand has a pair by using a bunch of instanceof's or getClass()-shenanigans. You also don't want to encode knowledge about poker into into the card object. That's just data.
Thanks!
Many card games have a reduced deck - e.g. lots of French card games use a 36-card deck. Some card games use multiple decks mixed together (e.g. Canasta). Some have extra cards (jokers are common, there are others); some have entire extra suits (e.g. games that used to be played with various forms of tarot decks).
All this stuff needs to be parameterised, and suddenly you have an enterprise-worthy class hierarchy and a ton of complexity before you've even really started on game-specific stuff.
Shuffle
Draw
Deal
Cut
Pile
Turn
Now imagine you have pinocle uno and cribbage as games. they each start with a different set of cards, but can use the functions above. The fact that it’s a 52 card deck with suits and ranks isn’t stated by GP, and there’s also the optional jokers.
For a real game, you’d probably need the back of cards as well for animation, and maybe you implement card designs to give the game some customization - now the deck needs some more properties or methods.
After all of that, think of whether the generic deck could be used to play magic or pokemon by using inheritance.
For lastpass, the closest parallel they might have to a deck is a password generator. Implementing that would seem like work. The deck stuff is all premature optimization for a single game, but they are checking your knowledge of inheritance, so just go along with it.
The last I'd probably implement as a container object Turnable<C> that adds an orientation state to any parametrized type, including Reversi disks.
I feel the card itself should be immutable as far as possible. It's state: orientation, owner, location and whether it's dog-eared should be kept separately.
If thats what they are asking for, implement it, programmers and their ego always trying to "LoL, DuM iNtErViEw QuEsTiOn".
There is so much to learn from a person by just seeing how they solve a simple problem like this one.
You might be surprised.
That's the first impression I get from an unknown company and I decided to trust it.
This company doesn't seem to follow the ways of the cult though, that's the concern.
It’s arguable whether a simple senior filter and “HR stuff” is a red flag or not, but how does it make this site worse?
However, your comment comes across as an attack intended to maybe silence his experience.
Your ego will be your downfall.
There is so much I can learn from a developer, junior OR senior by just seeing how they implement something simple like that. I feel like you have a full fledged case of Dunning Kruger effect. Since you don't know what exactly they were looking for, you brush it off to "LeL, LaST pAsS so DuM aSsEsMeNt".
https://www.reddit.com/r/1Password/comments/lkfg5p/what_happ...
Now that's not to say that something can't be sneaked into other work! But the bar is a bit higher than "take over a dependency"
2. Inject code in build to export user's passwords to remote server after update is installed
An offline password manager is updated a few times a year, and will go through OS repository distribution, with verification of the signature for changes. Or you can download the software from the source website and check the signature.
Several years ago the trendy thing to do for security was to get a USB-A security dongle and lock your important accounts with it. Nowadays, laptops from several major manufacturers no longer ship with a USB-A port, so if you need to log in again and don't have a USB-C dock handy, you're locked out until you can find one.
Either way, availability can be compromised by a hack due to passwords being phished and I think I'd prefer dealing with hardware tokens than the fallout of being phished or otherwise suffering credential compromise. That said at this point I probably wouldn't issue hardware tokens en masse until proper processes are in place to manage them (and their loss/breakage/etc) - it's certainly not solved to my satisfaction yet.
My layperson's armchair guess is that a successful attacker would probably seek to keep it quiet.
If you were a bad person, and you got access of tons of credentials from one of the major trust-us password managers, would you:
1. Focus on finding and looting big-payout cryptocurrency stashes, as quietly as you can (so you can keep doing it longer, before news gets out of how)?
2. Sell to a state actor to use for probably high-value purposes, while keeping it quiet?
3. Something else, and would that involve keeping it quiet, or making a big noisy mess?
1. State actors
2. For profit criminals
3. Teens for lulz and street cred
I guess the first group would probably keep it pretty quiet. The second would keep it quiet until they've abused the data as much as they want to, then sell the remainder on the dark web. The third would make a big noisy mess right away.
Sure sounds like they found passwords or keys in the development environment breach back in August, and nobody bothered to change those after knowing they were hacked.
EDIT to correct: Thanks to the link posted by u/voganmother42, this is indeed related!
This is frustratingly vague. This incident started 4 months ago, and you can't provide any details?
If it wasn't such a PITA to move off LastPass, I would do so. They got me.
Convincing my wife and colleagues to all switch simultaneously isn't feasible unless this data fiasco gets worse.
Since I don't feel 100% comfortable having my self hosted things on a public IP, I put it only on my LAN. For remote access (e.g. phone) I use wireguard.
It's really not. As the quality of their software declined severely starting around 4-5 years ago, I put off moving because I assumed it would be a huge hassle. It turned out to be surprisingly easy. I have since deleted my LastPass account and wouldn't trust that company to mop my floors.
Any compatible Android app?
Several, I personally like KeePassDX but Keepass2android is also there, possibly others I don't know about.
It also has autofill that comes up in any supported app when it recognizes a password field that it can autofill. Quite seamless.
It also took a little mucking around to install it's custom keyboard and I had to run some adb command to give it permission to auto-switch keyboards, but now it's setup it's pretty good.
You can open an entry in keepass2android, then it will auto-activate the keyboard and you get buttons so you can auto-type any field from that entry into anything.
On Windows I'm using KeepassXC and the KeepassXC browser extension. It hasn't been perfect, I had to manually enable simple http auth for that to work, and sometimes it seems to miss login fields.
Also I had to manually add the URL for some existing sites (I was using KeePassDroid only on Android before so the URL entries weren't filled).
There's no way I could find to go to a site, then I would like to just click a button and choose an existing entry to fill into it.
But once I've manually added the URL entries, it's pretty seamless and auto-recognizes that there are entries that it can fill.
Overall I'm very happy with the whole setup.
I at least know if someone broke into my physical safe.
This doesn't really make sense. These threats apply equally to people just memorizing and typing in their passwords into web forums. If the user's browser is compromised there is literally nothing to be done.
1. First off, who's to say LastPass will actually delete my data when I delete my account? Could I in practice be increasing my exposure by starting to use something different?
2. Bitwarden: They look cool but "In September 2022, the company announced $100M series B financing". In my experience, usually, financing = bad.
3. KeePassXC: I'm afraid the UX will be worse. But hey it's in my operating system repos, so perhaps I should just give it a try?
That is a bad idea and you shouldn't use a service with that requirement. Use something you can self host, or have the choice of DropBox/iCloud/etc for syncing.
You can self-host bitwarden using the opensource implementation of bitwarden server. It includes everything, even the pro features, and supports multiple accounts for the whole family for example: https://github.com/dani-garcia/vaultwarden
The KeePassXC browser extension doesn't have exactly stellar reviews. As for KeePassXC itself, I'm a little hesitant to use something that makes the UX so painful I have to copy the usernames and passwords.
That said, switching from LastPass to Bitwarden seems a little pointless: yes Bitwarden is a younger company and perhaps hasn't managed to mess up their product yet, but knowing life it's just a matter of time and then I'm at a worse place than where I've started.
> Every 6 months I hear about a breach at lastpass.
Have any led to leakage of users' passwords?
And it appears to be customizable how the Auto-Type types... meaning I don't have to copy-paste anything. Well gee...
Wrt Bitwarden, yes I know I can self-host a server, but, managing servers is a bit of a pain, especially for things which clearly need no server.
https://blog.lastpass.com/2022/11/notice-of-recent-security-...
There is already integrity checking for subresources: https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
Newcastle University had a proposal for website wide integrity checking: https://github.com/toreini/DOMtegrity
Note that only 7 people have starred it on Github.
TL;DR is short-term I wouldn't be freaking out of my password manager was hacked, but I would still definitely update all credentials at some point & treat it as an actual breach, and not an "oh no we were hacked but it's okay because zero-knowledge!".
Also how many times have they been hacked now? Who's still using last pass?
They lost user data and passwords and are lieing.
I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible.
You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across devices.
Which is pretty easy with SyncThing. Other services like Dropbox are also fine if you have a sufficiently high entropy password. The danger isn't in the "online", but a third party being able to decrypt your passwords.
Is SyncThing available for iOS? I thought it wasn’t but I’d love to be wrong.
But maybe I misunderstand the situation.
That keeps the whole database file synchronized, sure. But KeePass synchronizes at the level of each entry.
That's why you add that binary key file to the mix that you liberally distribute to all your devices. But that you carefully keep far off your sync platform. The danger of a weak password is when a device falls into the wrong hands, a compromised sync platform is much less of a concern (if the file is in the mix).
However I think this is a limitation of the app itself more than a limitation of the system in principle. As far as I can tell, the developer decided to only support a couple of the most popular cloud sync platforms. Maybe guess there is no consistent API for that sort of thing in iOS.
That said I agree with you I would never use a cloud-only store for passwords!
It is not fun having to type a 30+ character password consisting uppercase+lowercase letters, numbers and special characters on a mobile device.
But it has helped me to keep my phone clutter free, so maybe there's an upside to it too :)
I find that it's much faster to type an all lowercase password that's a bit longer to get the same strength.
For HN crowd that is likely easy. (I also use that solution)
I'd suggest using it in conjunction with Keepass2Android and KyPass(on iOS, someone mentioned Strongbox), although the Keepass2Android syncs and merges properly and the iOS does not.
In my comment I used KeePass to refer to the database and not the specific application I use to manage it.
This is true for many password managers that sync with the cloud. I use 1Password and I've made sure that I install apps on at least a couple of devices because the apps a local copy of the password data that can be accessed offline.
I've done that with another password manager that I used in the past too.
I used KeePass in the past and would likely still be using it if I didn't get 1Password free (free family account if your employer has a business account) and if I didn't need to have secure sharing with my wife.
Let me know if you know of a secure, convenient way to share password entries with another person using KeepPass that doesn't involve you sharing the your whole password database. I know you can have yet another password database that only contains shared records... but that definitely fails the convenience factor.
Sadly, once your use case becomes complicated and you need to share between devices, and potentially have partial sharing between people (e.g. your spouse, your parents etc.), it becomes a nightmare to manage. In particular trying to explain how sync is supposed to work with a third party on iOS is just pain.
I'm eyeing at self-hosted BitWarden instances, but then I kinda fear to someday be the one shooting myself in the foot and nuking everyone's literally life critical credentials...
When it comes to hosted options, they are hands down the best. Worth pointing out that they also have integrated 2FA, if you're satisfied with first and second factor living in the same spot.
It’s no longer “2FA” then.
In a local password manager, it doesn't work like that. A challenge-response mechanism can help there, but the cost/benefit analysis looks pretty different there, IMO.
If nobody is paying, they are probably the product.
[0] https://1password.com/security/
[1] https://www.troyhunt.com/have-i-been-pwned-is-now-partnering...
Curious as I may switch.
Curious as I may look at multiple options.
Use tailscale if you want to get fancy and keep it off the public internet or go the easy route and install fail2ban and expose it via public IP.
One should be extremely worried about it
So on one hand, I lose the ability to sync when I'm not on my home network. On the other hand, I don't change anything in my Bitwarden server _that_ often, and if I do, I can just quickly do a sync on whatever devices and I'm good to go. With the added benefit of not opening myself up to the outside world.
right now all my "services", which are not bitwarden-level sensitive, are all on the same network as whatever crap I bought at home depot. I have an edgemax router and there is a third NIC I've never used, so I guess I'd finally plug a switch in there! ok. next project I guess
> Use tailscale if you want to get fancy and keep it off the public internet or go the easy route and install fail2ban and expose it via public IP.
This isn't exactly a slam dunk, considering you now have to be knowledgeable about how to secure a machine that is on the internet and stay up to date with security patches which even tailscale itself isn't immune to: https://news.ycombinator.com/item?id=33695886
A top 1Password tip is that the business plans include free family plans for every member, so if you can get your employer to use 1Password then you’ll be able to get your personal account for free (which would include your family, too). A very underrated deal!
I recently logged back into my old LastPass account after 5 years and it was fascinating just how bad it is compared to 1Password.
Oh wow, thanks for that tip. My employer has 1Password Business and I had no idea about the deal: https://support.1password.com/link-family/
It doesn't do cloud syncing itself, but it lets you pick from a number of different providers (DropBox, iCloud, OneDrive, plus a few others) which you probably already use.
Not sure about 1Pass on Android, but Bitwarden works very well for me there (much better than Lastpass which afaik required a subscription to use the app)
https://www.passwordstore.org/
There's even a decent Android client:
https://github.com/android-password-store/Android-Password-S...
It seems to me that everyone stating that systems like this are terrible simply propose an alternative that is a hand-built version of the same solution.
If it's end-to-end encrypted, like it is for 1Password, I don't see what the issue is.
Generally it seems that there are two types of people - those that trust encryption and those that trust themselves just a little bit more.
In lots of threads like these the same statements repeat, pretty much similar to this exact thread.
Some people place encryption as the root of trust and so trust that any local encryption is good enough - because if it's encrypted then it's safe to go anywhere...right?
Some prefer to only trust local encryption that doesn't go anywhere, e.g. not synced non-locally to a cloud service. They do trust encryption, but their own stewardship of it they trust a little bit more.
Logically, both must trust encryption of they wouldn't both use it, but one trusts the implementation a little less. That person generally trusts their own systems, setup, skills and self to provide an additional layer of 'feel good' security. They trust the security of their setup and its supply chain over that of a third party. They trust their own 'defence in depth'.
Functionally the two approaches are more similar than either will admit, because unless you can secure the entire 'system' from transistor to human, all the 'prefer local' user is doing is shifting the point of attack and not necessarily understanding their 'defence in depth' might not be as deep as they think.
Most 'prefer local' users will usually point out that the shift of the point of attack makes it harder to achieve. That may have some truth, it may also not. It may actually be that a third party security focused service with many dedicated employees who are paid well and operate round to the clock to monitor activity might have a greater 'defence in depth' and a subsequently greater chance of spotting or preventing a supply chain attack over a single individual spread across many tasks (such as living a normal life and administering their systems in spare time).
The discussion usually then descends into opinion and there it stays, like a plant in the shade, never producing any useful fruit to it's keepers.
It really depends on the platform - but in short you'll either need a phone, or be locked into an ecosystem (browser, OS, etc) making using them on multiple devices & browsers difficult or impossible. A password manager supporting passkeys makes this easy as you can 1-click generate a passkey, and 1-click sign-in to services from any device or browser.
And: does using a third-party passkey manager open up passkeys to the same security issues as password managers? Specifically, more than remaining within the Apple-or-Google-supplied system?
Also what security issues with password managers? There's some potential concerns with extension-based over OS based systems, but if your device is compromised where someone can actually access memory then they'd both be equally void to some extent, AFAIK there's nothing seriously concerning security wise on a password manager vs keychain, etc.
> JOIN OUR NEWSLETTER
> Enter your email for updates from the LastPass Blog.
But I do keep it installed, because their poorly developed browser extension hijacks way too much on any page with any <input> elements on it. I need to keep it around to be able to test my own work to make sure LastPass isn't fucking things up for my coworkers.
It's something to do with how they inject their UI into the page. It's particularly bad if you're trying to make a responsive grid layout. I've seen several incidences of the LastPass extension completely obliterating an otherwise very well-behaved page, on both my project and other websites. And because it's happening in extension code, it's not immediately obvious what is going on. All you see is a blank page, or a page with the intended UI all smashed into the bottom rows of the grid layout. It's also a bit of a Heisenbug, as the LassPass code races your own to inject the UI.
I suspected Lastpass was lieing about how significant their security leak was back in August, considering my wife's account getting hacked and banned was pretty soon after the news hit.
I'd want to know what information they have gained access to.
Reply to @jeffbee: You basically have to have that threat model, because ordinary users are running dozens of untrustworthy processes on their machines. Real world security has to assume the user is not a security expert.
Yubico hardware stuff does work with both Bitwarden and BitLocker
It's the solution I will be transitioning to at some point.
Note, GitHub requires 2-auth fall of 2023 in case anyone forgot.
I liked 1Password for a long time because it gave you an option to sync with iCloud, Dropbox, FTP, etc. Then they started their own service like LastPass and started trying to push people to that. They got backlash initially and turned the other abilities back on but I'm sure they're trying to make it as difficult as possible to continue to use anything but synching to their server.
I've since moved to Keepass and sync it with my NAS
Would you know if they did? Would your provider know?
I would rather use the most popular password manager that's been audited, and never had a hack (1Password).
Then we have your "less well known" provider. They have probably outsourced their dev work to cheapest Indian firm they could find.
So I guess congrats on your data being public?
For a layperson, what's the best tips for what to do. Are passwords in Lastpass still safe or should we change all the passwords? Or simply change the master? Or should we migrate to something else?
I've thought about migrating before but frankly any password manager will have breaches...
Anything that gets them to use unique, strong passwords for everything vastly improves their general security, even if they are using a third party, commercial organization.
that's why it's baffling. The convenience is outweighed by the possible loss.
People get their credential compromised via shared passwords way more than compromises of Lastpass or Chrome or 1Password. Sure, it's a bigger risk if your manager is compromised, but for most people it's as much "eggs in one basket" as people only having one bank account which is probably true of nearly everyone.
it's even worse than that. The world's most common password is... password.
What's interesting on these lists is the presence of Dragon and Monkey - am I mistaken or is it due to CJK users entering a Chinese character that got translated somehow? Wouldn't that mean some of the most popular passwords out there are single unicode characters? Surely not...
[1] https://en.wikipedia.org/wiki/List_of_the_most_common_passwo...
Do you really think that’s safer?
The general population is not going to setup their own open source password manager solution. So going with an easy to use commercial password manager is better than not using one at all.
1. Have people manage their own secrets storage? Most people don't have the time or ability do this securely either. I'd rather pay someone else to secure infra, code, distribution, encryption, backups, etc. for me.
2. Reuse the same password on every site? One site gets hacked and now you're screwed.
3. Memorize a unique, long password for every site? Not feasible.
Third-party/commercial password managers are the best solution for most people, practically speaking.
Crypto keys are great but you can lose them and once shared they are keys to you kingdom.
Specific security devices are great but you need to remember to have them with you. They can get lost or broken so you need backups.
Google authentication is convenient but they can ban you. It is also a 3rd party to trust.
Passwords suck but might be the best of the worst. Advantages: password managers can be used to make password useless for other sites and people conceptually understand it.
It is quite a hard problem!
Obviously doesn't work for many sites cause people are still convinced passwords are good.
The main ways people are hacked are re-use of passwords and writing passwords down. If someone gets access to one of my passwords, trying it in other sites won't work. If someone finds the written parts of my passwords, that won't work either as they would need to know the secure part of the password that I memorize. I can even easily take the written part of my password with me if I want to use a password on a different computer.
The only issue with this technique would be if someone finds multiple passwords of mine, they might be able to figure out the scheme and brute force other passwords, but if someone already has multiple passwords of mine and is taking the time and effort to go after me individually then I figure I am probably screwed any which way.
U2FsdGVkX19mCN0qo7cyA5EfxgVqPQkygGlHqNgv1jM=
Guess it and post here and I'll supply you with the usernameA few jobs ago I needed some IT help and the guy asked me that. I told him my very vulgar password loudly. Then went back to my desk and changed it.
(I may be mistaken, but I do know it was absolutely the last time I gave a company true information for security questions).
Even if you're using real answers, you will be locked out of your account if you don't treat them like passwords. Eventually.
!%!%example.com%!%!
It was clear to me after I had to read such a security question answer over the phone to unlock an account the CSR was perfectly happy with "gibberish over the phone == gibberish in front of me", meaning my attempt to secure things made it less secure in the end.
There will be no reuse, because for Facebook it would be buddyfacebook or dugfacebook, or something else… but you will always be able to guess it in three tries. A computer system doing some kind of pentest isn't going to parse out the "facebook" or "lastpass". A human might, but that's why you rotate through three names. At the point where you have a human targeting your account and actually thinking about your inputs you are probably !@#$ed anyway.
…apparently.
could not login into the customer portal because he lost/forgot the password
could not perform the password recovery procedure because his answer for the security question is some nonsense like 'blade-purge-satin-dash'
*shrug_emoji*
I ran into one once that a 6 character minimum length for the answer.
> I ran into one once that a 6 character minimum length for the answer
This is a problem too, but at least it works if you manage to talk to a living person - even if you don't remember exactly how did you wrote something you can prove you know the answer for the security question. With 'cp359-qreor-534wej' as an answer you have no chance.
A few years later after the semester break I forgot my password. I had to email IT to reset it, and they replied "Please provide the answer to your security question: Dicks?". And I had to reply "Yes no problem, the answer is Dicks". It was an awkward email exchange, but in my defence I had immediately remembered the answer so it served its purpose.
I sadly write passwords down, but dream of a better option.
Response to @palata because of rate-limiting: The problem is people tend not to only put unimportant accounts in their password managers. They also put their bank and email passwords in there, and to my true horror: People have started storing their TOTP tokens in their password managers, which effectively reimplements single-factor authentication!
Maybe the best option is one of those physical access password managers like KeePass
The thing is that many services are now requiring TOTP in places where I don't want it, since I was already using a strong/unique password, and the TOTP requirement is effectively just to protect the service from having to deal with users who get their passwords stolen. If you're going to make me use TOTP where I don't want it, I'm going to automate its input.
My guess is this way of solving old problems may create new ones due to that pesky problem called human nature.
If so, at least bad actors won't have the incentive to cut off your finger or pull an eye out as with the other biometric authentication options :')
And to the OP, any shared secret that you cannot change in case of compromise is kind of a bad idea.