news.volyx.in

The situation at LastPass may be worse than they are letting on (twitter.com)

614 points by wyxuan · 1353 days ago · 414 comments on HN

Article summary

A user reported that four of their wallets were compromised, with the seeds stored in their LastPass vault. The seeds were encrypted and protected by a 16-character password. The user suggests that the situation at LastPass may be worse than they are letting on. The incident has raised concerns about the security of password managers and the potential risks of storing sensitive information online.

Main themes

  • password manager security
  • data breaches
  • encryption
  • two-factor authentication
  • online security risks
  • convenience vs security tradeoff

What commenters say

  • Storing sensitive information like seed phrases in a password manager is a risky practice that can lead to significant losses.
  • The security of password managers like LastPass is not sufficient to protect against determined attackers.
  • Two-factor authentication may not be enough to prevent unauthorized access to accounts, especially if the password manager itself is compromised.
  • Some password managers, like Bitwarden and 1Password, claim to offer better security features, such as end-to-end encryption and zero-knowledge proof.
  • The convenience of online password managers may come at the cost of security and privacy.
  • Users should be cautious when trusting companies with their sensitive information, as even secure systems can be vulnerable to breaches.
  • The design of password managers can impact their security, with some systems being more vulnerable to attacks than others.