news.volyx.in

What’s in a PR statement: LastPass breach explained (palant.info)

425 points by saikatsg · 1349 days ago · 285 comments on HN

Article summary

LastPass published an update on their breach, which some speculate was timed to minimize news coverage. The company's statement is criticized for containing omissions, half-truths, and lies, and for trying to shift blame to customers. The breach is attributed to LastPass's failure to contain the initial breach in August 2022. The company's security practices, such as not encrypting website URLs and using insufficient password protection, are also called into question.

Main themes

  • password manager security
  • breach response
  • Linux support
  • alternative password managers
  • design and usability
  • emergency access
  • local vaults and offline access

What commenters say

  • Some commenters are researching alternative password managers due to the breach.
  • LastPass's Linux support is criticized for being poor, while other password managers have better support.
  • There is a need for a comparison of password managers, including their security features and syncing capabilities.
  • Emergency access features should be considered when evaluating password managers.
  • Design and usability are important aspects of password managers that are often overlooked by developers.
  • Some argue that developers should not be expected to handle design decisions and that incorporating designers into FOSS projects is necessary.
  • There are concerns about the security of storing master passwords or encrypted derivatives in non-volatile memory.
  • Different password managers have varying levels of support for local vaults and offline access.