news.volyx.in

Lastpass setting the delete account div to display: none (infosec.exchange)

460 points by detaro · 1352 days ago · 203 comments on HN

Article summary

The article appears to discuss LastPass setting the delete account option to display: none, making it difficult for users to delete their accounts. The comments suggest that this move may be related to a recent breach or security issue with LastPass. Users are expressing frustration and concern about the security of their data. The exact details of the article are unclear, but the comments imply a significant security concern with LastPass.

Main themes

  • LastPass security concerns
  • Password manager security
  • Corporate politics and decision-making
  • Data encryption and protection
  • Alternative password managers
  • WebAuthn and PassKeys adoption

What commenters say

  • Some users suspect that the CISO of a company using LastPass may be receiving kickbacks or has a personal incentive to downplay the security risks.
  • Others argue that the CISO's behavior can be explained by a desire to avoid blame for a poor decision, rather than any malicious intent.
  • There is a debate about whether LastPass encrypts all user data, with some users expressing concern about the potential for unencrypted data to be used for phishing or identity theft.
  • Some users are switching to alternative password managers, such as 1Password or Keychain, due to security concerns with LastPass.
  • The use of WebAuthn and PassKeys is seen as a positive development in password security, but more sites need to implement this technology.
  • Some users believe that corporate politics and the desire to avoid admitting mistakes can lead to poor decision-making and a lack of transparency about security risks.
  • The security model of password managers is evolving, and older models that left some data unencrypted are no longer considered secure.