LastPass breach gets worse
old.reddit.com
old.reddit.com
For example, it's clear backups were stolen, but they won't say how old the backups were, or what their retention policy is. So even if you changed your password to a stronger one, with more rotations, it may be that the attacker got hold of very old backups with weaker security. I've asked their support team for information about time windows of backups stolen, if they have a retention policy and whether it was adhered to, but they won't share that information. Instead we are left with a blog post that is more than a month old, no recent updates, and questions remaining unanswered. I'm a paying 'enterprise' customer, and they are meant to be ISO270001 compliant, so a retention policy should be a pretty simple thing to share.
Based on your understanding, does my master password length sufficiently mitigate the low-iterations, or is decryption a realistic possibility?
But it's probably easier to just change your passwords anyway. At this point I wouldn't be suprised if the story gets even worse somehow.
I have asked all of my team to change their passwords. We use LastPass via our parent company and will be switching off LastPass soon for our team. LastPass never would've been my choice, it was made before I joined.
But assume you're breached, change it all now, and ideally you're not going to stay with LastPass. Their communication sucks, which is just icing on the cake in this entire situation.
That reads like you're resetting credentials and then putting the new credentials back in LastPass, and then possibly maybe moving away from LastPass at some point in the future.
Given how little LastPass has disclosed, and the negligence we already know about, we should not only assume we're breached, but we should also assume LastPass is still storing critical data in cleartext, they don't have a "zero knowledge architecture", and their systems are still vulnerable to intrusion and exfiltration.
If you get lost and stuff seems too hard, if your replacement product lets you sort by age then just sort by oldest and hit 5 today. Hit 5 more tomorrow. Keep chipping at it. At this point you might as well change one every single day.
https://www.pcworld.com/article/430756/nifty-new-lastpass-da...
This is an old article, no idea if the feature still exists or not.
Luckily I had already switched over to Bitwarden, but I still had around 250 accounts to go through, although about 40 entries ended up being duplicates, defunct sites/products, or so old that the accounts were already deleted due to inactivity.
If you haven't started rotating all of your credentials already, this news should definitely get you started on it!
Thanks, LastPass!
> Our investigation to date has determined that a threat actor exfiltrated encrypted backups from a third-party cloud storage service related to the following products: Central, Pro, join.me, Hamachi, and RemotelyAnywhere.
Yes they have. They had a breach, and lied about it. You can't trust anything about them now. Assume a total breach and move on.
What if you closed your account 5 years ago, did they still have backups?
means that some auditor, met with someone that does not know anything, and checked boxes in a form.
Worst case: it’s entirely possible they don’t know.
Part of me wonders if this was an intentional strategy: Downplay during the initial media round then very quietly reveal this was a worst case scenario.
Personally I'm never touching them again - anecdotally everyone I know who was an individual customer has migrated away and inside companies lots of engineers have stopped adding new passwords.
If, for example, you deleted your account after the first report in August (a rational decision), you have no way of checking what iterations setting you had, now that people are talking about it.
It's also unclear whether you will receive any data breach notifications detailing the exact impact to your data, since your account is now deleted - do they keep a history for "post-fact" situations like this?
And of course, if you didn't keep a backup of your passwords before deleting your account, you'd have to reset everything to be sure.
Terrible, awful company with no respect for their users.
I’m sure LastPass tried really hard to protect data. But everything fails eventually. If there’s things that are life threatening or financially devastating then I don’t think I can afford to audit people sufficiently to trust them with the info.
This is also why I can’t imagine ever using Plaid/Mint/etc that require my bank credentials just to do minor stuff like make payments or read transactions.
These password managers are in a tough spot market wise as they aren’t smart enough to secure super important stuff and for unimportant things, iOS/chrome password management is pretty good. I don’t mind if my audible account gets rooted, but it would be very bad if my bank or brokerage gets rooted.
That's the fault of banks. We need open banking, with APIs using OAuth or similar with scopes or some way for per-action/item access.
Yup. I put everything in the password manager except primary email and bank/brokerage.
Not really.
Sure, but password managers available over the internet are especially vulnerable. They're major centralized honeypots given the data they handle, and leaks are probably worth millions on the black market. To think that any company could handle this responsibility is naive at best.
Password managers are an entire section of software that shouldn't exist. They're too confusing and a chore to use for the general public, even if users are educated about their importance, and would like to secure their accounts. Many non-technical people don't bother or care at all.
The way forward is to get rid of passwords altogether and make passwordless authentication the norm. There have been some usability improvements in recent years in this area, to the point where it could reach mass adoption, but the change needs to start with developers.
I was a LastPass user for many years, many years ago, and trusted them, but have since moved all my passwords offline. And I would very much like not to worry about maintaining accounts, updating passwords, etc. Ugh, what a chore.
My knowledge in this area is admittedly limited but shouldn't password managers be fully encrypting your data with a key only you have (like 1Password). The way I understood it was that these leaks shouldn't be a problem because the data is worthless without the master key. Although I guess LastPass wasn't doing it that way.
Entrusting _any_ company with the secrets to your digital life is a bad idea in general. I know that 1Password is the darling in this space, but breaches are a matter of time. They only need to mess up once. Their entire business reputation relies on being 100% secure, which is impossible. I'm not surprised LastPass is reluctant to share more information; they want this to go away as soon as possible so that business can continue as usual. It also wouldn't suprise me if there were other breaches that were never made public, at LastPass, 1Password, or any of these companies.
Is that an actual thing?! I'm only familiar with password managers that use the Internet to synchronize, i.e. it's still 100% possible to apply the cryptography such that the service vendor or anyone else cannot read your passwords stored or in transit.
I can maaaybe imagine password managers with a web interface that however still decrypts locally, client-side.
Password managers are currently a necessary evil, so if you must use them, use an offline one, and sync across devices via any other secure mechanism.
TLS has nothing to do with it. TLS is transport security, which is relatively useless for preventing the service provider to access your data.
I'm sorry to say this, but this is just word salad, including the "I'm not assuming it's compromised" bit.
> and entrust my most critical information with a 3rd party
The point is you don't need to do that, and can still sync over the Internet.
This sort of thing, will all encourage us to 'naturally' move towards a government backed, biometric solution. Which will of course be phone based, will hold your wallet, id and medical information, and will be provided to us by kindly corps such as twitter, google, apple, microsoft, meta, etc.
I think what's actually happening is that they're just really bad at security. Either every few weeks they discover something new or they still haven't successfully locked the attacker out.
I also think you are correct to a point, they are really bad at security so it is also possible that some of these things are just coming out also.
Seems like a poor strategy. This is like an infected wound that keeps on festering. A turd that will not flush. A house guest that won't take multiple hints it's time to leave. Better to just get it over with in one go; next week the news cycle will be something else and it will be over; now it's in several news cycles again and again.
So now I remember ~3 passphrases, instead of 1, and sleep much better at night.
Or simply a personal allow list of origins, with a happy green indicator prominently overlaid onto login forms on those origins you've saved -- doesn't even need username storage.
Maybe even a community-sourced allow list, but that would need some seriously trusted management (including purging upon domain registration expiry/transfer) but that would mostly duplicate the domain warnings that browsers already offer, anyhow.
I used LastPass for years and switched to BitWarden a couple of years ago. I did delete my LastPass account after switching, but I have zero confidence that they actually deleted my data.
Fortunately, my master password from back then is long and complicated.
I'm sure there are some very basic phishing attacks that just save whatever you entered, but... let's avoid trying to come up with "clever hacks" that only lend a false sense of security.
Just because one restaurant has a bad health inspection score and is constantly making everyone who eats there sick does not mean all restaurants are bad. People who just lump "password managers" into one group are fundamentally assuming that one bad password manager means that all password managers are automatically bad, we just somehow don't know it yet. Don't bother eating at restaurants ever again if you feel that way, I guess. I know people who have gotten sick eating at restaurants, but that doesn't stop me from finding good restaurants.
Most password managers have a very good security track record. Users creating and remembering their own passwords does not have a good security track record at all.
Better to use a completely offline password manager (which risks you losing your backups or getting into a conflicting sync state) than no password manager at all, but a password manager that actually encrypts all your data end to end (which LastPass does not) and requires a strong key to unlock (such as the 2SKD method, which again... LastPass does not) is extremely safe, even if you don't trust "the cloud", because you don't need to trust the cloud.
Why would you remove those bits of information and also not switch password managers too?
I went with unix pass installed inside of a FreeBSD jail. It's more complex than auto-filling with a browser plugin (though those exist), but as long as I can get an SSH terminal I can get to my passwords, and various other bits of data. You have to allow password login from sshd (which isn't ideal, but I was going for "access from anywhere I can get an SSH session), so your passphrase had better be good. And you need to have terminal discipline to be sure you clear the screen if shoulder-surfing is an issue.
But it has the advantage of knowing exactly what's going on at all times. And, for added benefit, there are only a handful of things you need to have printed out and stored in a safe or whatever so that your family can access all of the encrypted important stuff if you get struck by lightning.
> And, for added benefit, there are only a handful of things you need to have printed out and stored in a safe or whatever so that your family can access all of the encrypted important stuff if you get struck by lightning.
Presumably this print out includes an instruction manual for using FreeBSD, opening a terminal on a FreeBSD machine, launching a shell inside a jail, and accessing this "user friendly" software? Exactly how technical is your family?
Forgive my disbelief that this is an actual solution for anyone but yourself.
> but I have not much of an idea how everything works behind the curtain
You could choose to learn: https://1passwordstatic.com/files/security/1password-white-p...
Any good password manager documents this stuff very well. LastPass has a very shallow white paper that constantly refers to encrypting "sensitive data", but they never define what that sensitive data is, which is suspicious, and it turns out that LastPass doesn't encrypt everything, which everyone who cares about this stuff has known for years. In the 1Password document, they talk about how every item in the vault is encrypted, and every item contains various fields such as Title, URL, etc. 1Password encrypts everything.
1Password also talks about the benefits of using a user password plus a generated 128-bit "Secret Key" (2SKD), which is a security feature I strongly appreciate.
I never said, nor meant to imply, that it was user friendly. But, yes, showing a moderately intelligent person how to access it is easily done with a set of instructions, maybe a single printed page. Not "user friendly," but certainly usable. If I am a smoldering corpse, they can rescue whatever is stored there relatively easily. Since the software is ridiculously stable, the instructions will be equally stable.
It's not a universal solution by any means. I tossed it out there as an alternative. I'm sure you really love 1Password, and if it works for you, fantastic. I'm distrustful of any service in general, but maybe 1Password is 100% rigorous in all of their security measures. I have no idea, as I don't work there, or know anybody who works there. I'm relatively confident in mine, as I built every step of it (which wasn't much), and it has very few moving parts.
Is a hardware device, password never leaves device except when filling in form, requires hardware confirmation, and works as usb/bluetooth keyboard and is compatible with most everything.
Switch to 1Password. It takes ~5 min to export and import.
Doesn't cease to amaze me with what confidence people recommend these "Switch to 1Password", "Just use BitWarden". I switched to KeePassXC because it seems all the cloud-based password managers have the same endgame: get hacked.
> It takes ~5 min to export and import.
Only 5 minutes, and you've just doubled your attack surface area. Congrats.
If by going to a restaurant I'd have to commit to eating at that particular restaurant forever, I probably would choose to prepare food myself...
> a threat actor exfiltrated encrypted backups from a third-party cloud storage service related to the following products: Central, Pro, join.me, Hamachi, and RemotelyAnywhere
Lastpass is a GoTo product, so in general the multiple security breaches undermine confidence in all their products. Your password manager is not something you want low confidence in.
Lastpass was the first password manager I used, and when it sold to a scummy company like LogMeIn, I learned my lesson to just stick with KeepassXC.
It's the same database format, KeepassXC is a fork of KeepassX with more active development.
https://superuser.com/questions/878902/whats-the-difference-...
It makes me wonder if this is all a result of GoTo general culture permeating into Lastpass. GoToMeeting and Webinar feel hilariously outdated, and I think that people use them mostly because corporate inertia.
Initially, it was FAR AND AWAY the best and most reliable option for meetings. It worked well across platforms, and the screensharing -- especially the ability to see a participant's screen, not the host's screen -- was stellar. This was key for us; we're a small software company, so GTM sessions to help client IT install, or help a customer with a problem, or even get the system configured initially, were all our bread and butter.
Sadly, GTM over time has fallen prey to the same thing that ails lots of older products: it just keeps getting worse, and it feels almost deliberate. We do not give two shits about video, but they're pushing it hard. Sharing controls change revision to revision, which makes it harder for us to coach customers on how to use the tool. Lag and delay has become a real issue.
It's just super frustrating.
The thought of storing my passwords on a web/cloud-based service always struck me as the dumbest thing anyone could do as it would be only a matter of time until such a service was hacked.
I started using Zetetic after learning about them via a 2012 Black Hat conference presentation[2] where they took a bunch of password managers and STRIP came out on top. I figured if it was good enough for them, it was good enough for me. The product has only got better and better since 2012 (note that the presentation PDF is out of date in terms of security, they have of course changed hash and substantially increased rounds ! see their website for detail).
Their support is first-class too.
[1] https://www.zetetic.net/codebook/ [2] https://media.blackhat.com/bh-eu-12/Belenko/bh-eu-12-Belenko...
Additionally their support is really good. They added a feature on iOS version (and Android I assume) which copies the TOTP when you use codebook to auto fill a login. However it cleared the clipboard when the TOTP code expired which was sometimes too soon - I suggested they add a buffer of ~15-30 sec which most TOTP validators allow, giving the user a bit more leeway in pasting it. They added it in the next version.
Some cons though: They do lack Linux support. Syncing is manual (I think they mentioned the next big update will make it more automatic), and there aren’t any family/team sharing capabilities. For these reasons I would really only recommend it for tech-savvy individual use. I’ve recommended it to a few colleagues and they have had great experiences and continue to use it for several years now.
That is true although I understand this is simply down to lack of user demand for it[1].
There appears to be an UNOFFICIAL Linux tool called Read-Codebook[2] though...
[1]https://discuss.zetetic.net/t/codebook-for-linux/1063/26 [2]https://github.com/teracow/read-codebook
It solves issues Dropbox doesn't (like dealing with segregated networks), and doesn't solve issue that Dropbox does (like sending files to people).
https://github.com/bcpierce00/unison
edit: Also, KeepassXC!
+1 for keepassXC
- Unison is easier to use over ssh. With Syncthing, I need to forward a port or use the ssh client's proxy to get at the webgui.
- I find Unisons behavior more predictable and dependable than Syncthings. Maybe it's the Android port that's to blame here, but with Unison I start it on the CLI and it runs through to completion, done. With Syncthing, it seems to sync on it's own volition. I have configured Syncthing to run when my phone is connected to my WIFI. Sometimes it starts right away when my Android phone enters my WIFI, sometimes it takes a while, sometimes it needs a little prodding with the webgui to follow through on this or that folder.
- My Unison config consists of 3 lines. I recently had to reconfigure Syncthing on my phone, took me quite some time of carefully re-mating the app with my server for all folders with a ton of potentially out-of-sync content on both sides.
However is there any good way to use it with my phone? I do find it frustrating to have to type in passwords manually sometimes, even though it's not very often.
Previously she wrote her passwords down in a notebook.
I don't use 90% of the entries in my password manager on a monthly basis so anything that allows me to delay the password change on hundreds of accounts until I need to use the account again would be valuable.
at least this way they would have to prioritize
Bitwarden isn't much better, but they do have a cli technical users can cobble something together. (I ultimately decided to skip on Bitwarden also)
Time boxed to about 15 mins a day, it hasn't felt like too much of a burden. But also finding I can just delete quite a few, as my vault is over a decade old and many sites/services are now defunct
Will take another month or so, but have the more recent/crucial ones done already so worst case someone might crack my old digg password
I don't personally use Dashlane and cannot speak to its security.
Not to mention https://en.wikipedia.org/wiki/LastPass#Security_incidents
It was surprisingly easy- for all of LastPass's faults, at least they don't use shady vendor lock-in practices (like making data export needlessly difficult). And 1Password has a LastPass-specific import page, which made the migration dead-easy.
If one site is breached you have to go change your password everywhere. By using a password manager if one site is breached you just have to change that one password for that site. Using the same password everywhere is a real concern that should be avoided at all costs.
LastPass's breach is the exception to the rule. Generally speaking password managers have had a far better go of things than LastPass has.
By far, using a quality (LastPass is not one of them and frankly never has been) password manager is likely going to be the most secure thing that any average user uses every day.
This breach is much the same as the typical media stuff, hyperbole does no one any good. One bad thing happens and the sky is falling (hyperbole). No, the sky is falling for that app (LastPass) but not for every password manager. You have two really good options: Bitwarden and 1Password. I, personally, wouldn't touch any others that are cloud based. Local password managers are another matter, but they're simply a non-option for me and I'm not willing to give up the convenience, or the administration abilities that come with it in a business environment.
Or to just use the browser's saving functionality and never push your passwords online in the first place. They're probably only using one primary device like me; I generally don't log in to stuff on my phone, or personal stuff on my work laptop/work stuff on my personal laptop.
If their habits are like mine then these cloud password services are pretty pointless.
Also, with your setup, what happens if the computer with the browser containing all of the saved passwords is destroyed somehow?
I don't know if this has changed, but a few years ago the stored passwords in Chrome were stored unencrypted in a sqlite3 database. (on Linux, at least) I'd use an audited service such as Bitwarden or roll my own Keepass thing before using the browser's saved password feature. All it would take is one RCE exploit in a browser to expose your passwords.
This has already happened a few times over the past decade: I restore from local backups.
Also: https://ohyicong.medium.com/how-to-hack-chrome-password-with...
Passwords are still easy to obtain outside of Chrome, and apparently Firefox is just as easy.
By using the browser's saved password feature you are one RCE away from someone being able to automate the extraction of all of your passwords.
I'm pretty sure on Firefox if you have the master password set, they're actually encrypted, and has done that for a long time.
What's wrong with storing them locally on your laptop or on a piece of paper in your wallet?
Storing on a piece of paper is inconvenient because there are roughly 350 logins in my password manager.
Other password managers don’t have Last Pass’ long history of security concerns. They also have hardening against this specific scenario. For example, 1Password assumes they could be breached and includes a strong random key which is unique per-user so in an event like this the attacker would have to do a lot more work to break vaults:
My main gripe with LastPass is that they did not encrypt everything. Vast amounts of important information (email addresses, billing addresses, telephone numbers, IP addresses, website URLS [0]) were not encrypted on user's local machines with the master password, and subsequently have fallen into the hands of a malicious actor.
I would feel much better about LastPass if the security genuinely was safeguarded by a strong master password. But they've demonstrated that it's not.
Other password managers, as far as I can see, provide much greater protection in terms of encrypting everything. That's why I'd feel better about using them.
[0] https://blog.lastpass.com/2022/12/notice-of-recent-security-...
They showed red flags a long time ago!
This breach helped me learn why it is important to have strong passwords.
If you were a LastPass user at any point you should rotate all the credentials that touched that service.
But I had sensitive notes too, so IF my details got leaked then I am ruined either way.
A couple of weeks later they sent out a statement "clarifying" how their 2FA had a caveat. It was basically marketing bullshit glossing over the fact that they don't enforce 2FA locally (sorry, details are very vague in my memory now, but I remember it being a serious mis-implementation).
Clowns.
https://github.com/lastpass/lastpass-cli/issues/602
https://github.com/lastpass/lastpass-cli/issues/624
https://github.com/lastpass/lastpass-cli/issues/604
...their CLI tool is de-facto deprecated (unsupported) and has several unreliability issues (ie: `lpass ls/userls ...` reports differing amounts of values depending on when a user was added to the folder or not). Basically `lpass ls ... | xargs -n1 ...` cannot be trusted, and you can only get an accurate list of passwords (or users) from the actual GUI.
It makes automation, auditing, reporting, near impossible.
I doubt LastPass deletes my data when I delete my account. I even wonder if to comply with GDPR, they just disassociate the data from me so it can never relink, but keep the data so it can be used, sold, or rented.
The only sensible approach is to change every password on every site that you’ve ever stored credentials in LastPass for. Any attempt to change the passwords is just hoping hay their backups are better secured than their prod database (they are almost certainly not), and also that the data wasn’t popped before you changed them (which they almost certainly were, probably multiple times).
Delete your account, but revoke/update all those passwords asap as well. Since the site/url and email addresses were not encrypted, I’d be changing the email address on at least critical accounts as well where I can.
Assuming you aren't reusing passwords, you shouldn't need to track down every online store you once bought something from. But your should consider updating your passwords for bank accounts, Paypal, Amazon, Google and whatever else would be a major headache if it were compromised.
- Migrate your vault to a new password manager
- Rotate all your passwords and save the new ones in your new password manager
- Delete your Lastpass account
I have evolved a little on using software to track passwords though, and I'm using Unix Pass quite happily now. It's just a short bash script that is very readable, and uses GPG as a backend.
Edit: What's doubly nice is how elegantly it scales from a simple folder of gpg encrypted text files to a multi user synchronized git repository on everyone's phone.
But all that's optional, and only requires you to trust other tools that you already regularly depend on.
I just had my keychain corrupt last night while I was testing the SecItemAdd API. So keep that in mind, maybe make backups. I was pretty shocked that you can corrupt the keychain using just the API, the entire security process started to lock up too. I had to (manually!) delete the entire keystone and start from scratch. Luckily I don't rely on it much.
It is worth noting that after you back it up to a remote location, it may not be a very secure concept anymore.
There are all these "lol we blocked you for abuse, good luck doing anything :^) I guess complain on twitter lol" horror stories that I don't want to be locked down to one provider that does _everything_, the way Google or Apple does.
Even the fact that I have all e-mail at Google that can randomly ban me for "abuse" makes me scared, but I don't want to figure out how to move all my mail history to ProtonMail or AOL or whatever. I will need to have that as a risk.
For me, I find the Keychain to be too chaotic. I use 1Password.
1. I do not use the MFA capability of Keychain at all. Putting your MFA, username and password in the same store is fucking stupid. I have a hardware TOTP token. Backup codes for that are however kept in Keepass.
2. I keep an offline backup of everything. Never trust a cloud backup!
3. All vendors are ephemeral, regardless of their size. Everything I have I have a carefully planned exit plan for.
As other people have pointed out, your keychain is on disk, but if you lose the Mac and find out your MFA codes don't work or something (this does happen) then you're SOL. Keep a backup.
If you’re an Apple house, it’s a great solution.
Also, people can store notes on lastpass, did those get leaked too?
"that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data."
https://blog.lastpass.com/2022/12/notice-of-recent-security-...
The TL;DR is even with 100k+ iterations of PBKDF2 an attacker can crack a password with 40 bits of entropy in about 71 days if they had access to 200 modern GPUs. For comparison if there were only 1 iteration instead of 100k the same type of password could be cracked in 61 seconds.
50 bits of entropy changes things a bit. Now it takes 1 year instead of 71 days but if you're a high value target they can just ramp up the number of GPUs to reduce the time.
The difference between 40 and 50 bits of entropy for a password look like this:
40 bits: !climb33
50 bits: ClimbS1@
40 bits: any 9 lower case letters
50 bits: any 11 lower case letters
The takeaway I got is you're probably ok if you have a really good password (150+ bits) with 100k+ iterations but if I were using Lastpass personally (which I'm not) I would absolutely re-roll everything and never use the product again. I personally use a command line tool called `pass` which stores everything locally. This story interests me though because I am mildly involved with someone who is using Lastpass and I suggested they re-roll everything. I'm happy to see someone did the math, it's the exact information I wanted to know.The podcast show notes are on page 6 which has more numbers and practical examples: https://www.grc.com/sn/SN-905-Notes.pdf
The contents of the GitHub repo are of course encrypted with your own key, which you need to manually sync to your other devices.
After some time with pass, I switched to a more integrated solution, with KeePassXC on desktops and Keepass2Android on mobile, with sync via OneDrive.
Ended up on Bitwarden (Vaultwarden in my closet really) instead for web passwords. Admin passwords stayed in pass because I want to be sure I have them. Git is local to the device even if the server burns down.
...
> 50 bits of entropy changes things a bit. Now it takes 1 year instead of 71 days
I don't understand this. Going from 40 bits to 50 bits increases the size of the search space by a factor of 1024. Why does it only increase the search time by a factor of 5?
On the reference page I linked it mentions:
> Having 40 bits of entropy is approximately 1,000 times weaker than 50 bits since bit strength scales exponentially. In other words, random bits are worth a lot because each additional truly random bit, on average, doubles the time required to crack.
71 days vs 365 days is about a 5x multiple. I'm not sure how all of that ties together.
People will say you have to use one because you might reuse a password. If a hacker gets a hold of it they will have access to other accounts. Hopefully many use different emails and/passwords but even if they don't an attacker doesn't have a list of websites this works on and will try to login to major sites which usually alert the user. If your lastpass account has been hacked they know all sites large/small and will have an easier time stealing info/money from smaller sites with lower protections and can blackmail you because you saved your pornhub account (with a privacy email address) in lastpass.
People are going back 5 years trying to get information from a company they have no relationship with. This company kept your passwords after you left. Once you give them to lastpass they are no longer secured even if you decide to leave..10 years later coming in through that backdoor you left open.
When you need to admit a mistake or apologize, get it all out and be truthful about it. Effectively get it over and done with.
People do appreciate honesty, but will strike back with retaliation if they find out you only appeared honest. Telling a half truth is no better than lying.
contrary to popular belief, maintaining a file synchronized is not difficult.
This "breach" is just as good as assuming google or apple or any other bitwarden or any other cloud password manager is broken because they all work in the same way "we promise to keep it secure". this is different from storing a keepass file on the same google cloud because an attacker has to break into your cloud login first, then hope to find your keepass file. Then try to break that file.
as opposed to breaking into your google account and seeing the passwords or by breaking into bitwarden or 1password or something else.
if someone has a login to 1password of 10 people, there is good reason to assume there will be passwords stored.
Why? Quite easy actually - having random passwords is better than reusing the same everywhere. Random passwords are impossible to remember by a regular human, hence you need a password manager. Using a local file as a password manager poses a usability/availability risk (you have to sync it yourself, you have to back it up yourself, you have to make it available on all devices without putting it at risk, you have to secure it, etc.), hence cloud-based password managers are better for the average person, especially coupled with MFA for critical accounts (banks, email, etc.). If you're a highly technical or highly security conscious person, or under threat, the equation changes of course, but the recommendation for a cloud-based password manager isn't meant to apply to everyone, just most people.
A password manager makes it possible for the average person to have high length, completely random passwords for each and every site, and to have them available on all of their devices.
That makes it a lot less likely that people will do bad things like re-using passwords, having short passwords, or writing them down.
My LastPass account would have been in the breach, but as my vault was protected with 151,000 iterations and a very long password, it'd take an attacker a long time to be able to get to my Hacker News password, which they'd find was 50 random characters long and looked something like jtES^cqhPj3@&rgPW5#frmDpf#^gGyf3eRoPH#fUZWJQGNFJvW
They'd also find that I've since changed it!
In this context, the common alternative to LastPass isn't best practice, it's worst practice.
>"For those that may not have seen it, since instead of a new post they “updated” the one from November…Looks like it’s even worse than they first let on"
Can anyone say if they notified their customers that they had updated the original post?
https://duo.com/blog/duo-security-researchers-uncover-bypass...
It also doesn't doesn't help if there's any way around the MFA process. For example, could the attacker convince a minimum-wage support person / chatbot that you need to reset your MFA? Many companies skimp mercilessly on support costs and that makes this easier than it should be. I've even seen sites where your MFA can be reset using an email challenge!
I have not figured out where to store those backup codes though.
Under the circumstances, a staffing shakeup in the CISO office sometimes occurs in companies after this kind of accident.
Does anyone know what the situation is like inside LastPass headquarters?
After a previous LP incident I noticed a number of senior security officer positions advertised on the LastPass Careers site.
Which leads me to my point: If the password manager is properly used then why do we care if the encrypted databases were leaked?
Change the passwords yes, all of them, but if you're going to put the new ones back in to be re-exported by your adversary you may as well save yourself the time and stay with the already breached ones.
Sometimes it’s preferable to pay the professionals, especially if you’re not an expert. I’ve recommended LastPass to my grandparents for years because it’s better than using their grandkids’ names as passwords everywhere.
Really important stuff is of course handled in other ways..
All you have to do is go to settings > passwords and enter the pin and there they all are.
Sao if you use this, have a really good iPhone pin!
iPhone PIN ? Say what now ?
Only fools use PINs.
iPhones have supported keyboard entry for passwords for a very very very very long time now. And more recently, TouchID and FaceID, of course.
You can also configure iOS to erase after n incorrect entries.
At this point in time, you get what you deserve if you still use numeric PINs.
“Truly works” except for the one critical feature that is the sole reason people use it. It does not keep your passwords safe.
Doesn’t matter how nice their Windows app is, or how smooth the animations on iOS are, or how well it’s browser plugins work.
It fails at its only real task, safely storing your credentials.
1Password also actually encrypts your entire vault, and it uses a strong, generated secret key in addition to your password, so even if a user does not use a strong password, their vault would still be very hard to crack.