Not everything posted on HN has to be verified true. The decision calculus here seems strongly in favor of signal boosting it, so that people who need to can take defensive action, even if it turns out to be wrong.
Not everything posted on HN has to be verified true. The decision calculus here seems strongly in favor of signal boosting it, so that people who need to can take defensive action, even if it turns out to be wrong.
The big difference between the two examples is this: LastPass is known to have bugs. Huge amounts of data were stolen from them and we just found out that it was a lot more than we thought.
For all we know, they were storing passwords in the clear somewhere.
Trivia note: the first compiled language I used was PL/I, and the compiler was notoriously buggy and would crash on well-formed programs. Our teacher told us to put do-nothing statements in when this happened (`PUT SKIP(0);` if I recall correctly), and with some trial and error, those would fix it.
Yes. After their last major breach I exported all my data and deleted all my credentials and account with LastPass. Seeing the details of this breach, I'm super happy I did.
The thing that's bad, is that apparently their developers have access to (backups off) production data. That implies that their security infrastructure is not different from regular startups at all so all of their marketing is just bullshit. They didn't sacrifice developer productivity for security on this point, so they can't be trusted to have sacrificed anything for security at any point.
No it isn’t.
> What would you have the people who are using LastPass do, stop using it?
Yes.
> Because some crypto dude…
No?
https://www.cnet.com/tech/services-and-software/lastpass-say...
https://www.forbes.com/sites/daveywinder/2019/09/16/google-w...
https://www.cpomagazine.com/cyber-security/lastpass-2019-pas...
That's subjective and has no value in determining whether the post is true.
"Not everything posted on HN has to be verified true. The decision calculus here seems strongly in favor of signal boosting it, so that people who need to can take defensive action, even if it turns out to be wrong."
What? Proven true, no, any sort of evidence, yes. As for taking actions, there's a cost.
"I suspected someone used a 0day on me" is not exactly inspiring confidence
"Initially I imagined I was targeted by a 0day or rootkit"
which actually does not make sense, because it implies he thinks those two things are fungible. He's obviously not a security expert, but he's also obviously not totally technically incompetent.
Way to make yourself feel important. It's not that you made some terrible choices yourself, like using a known-insecure password manager SaaS, or putting real money into crypto. Nono, somebody pulled a 0day on me, what can ya do? Shrugs
Also the people talking about “burning zero days”… every time you use an exploit (ignoring the exact meaning of 0 days) it doesn’t become burned by the first person. The hacker could use it on hundreds of people before it’s discovered and patched by whatever software it targets. That could take months.
That together with others here claiming they have a LOT, makes me think they might have hot, cold, soft and hardware wallets.