Latest info on LastPass data breach

I used Bitwarden without much issue for years, until I switched to 1Password due to my new employer at the time using it (and you get a free family account with a work account).

Imo, there's no comparison. 1Password is so much better. It was evident from the first few minutes of using it that it's a higher quality product.

Why is 1Password better and is it free?
 
Another alternative is NordPass. Added extra of getting a VPN too when using the paid version.
 
Another alternative is NordPass. Added extra of getting a VPN too when using the paid version.

reason why i want to go self hosted.I can implement my own vpn , as the only way to get access to the vault.
 
About 30 years ago I wrote down a little algorithm that the meatware between my ears was able to compute in around 15-20 seconds, all my passwords are different and computed from a master password with digit rotation, ASCII -> byte -> ASCII shifting and some other operations using the name of the company.

I'm sure given 100 or so of them it's possible to break the scheme easily, but it's good enough that I have differing passwords for everything without the need of a password manager.

D
 
They are likely one of the biggest targets because of the size of their user base.
Remember, all it takes is one insider on the take. It can happen to anyone. I don't believe they were MORE negligent than the rest... unless anyone has proof of that.
Not sure about the others but from what I've read LP don't encrypt the URL's as welll as not encrypting company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses

This is a big no no. A perfect target for phishing campaigns now. This is not looking good for LP, especially as the breach occured in August and they now release this info 2 days before Xmas when half of IT are on leave.

Since 2018, we have required a twelve-character minimum for master passwords.
And what about those before 2018 that had weak passwords. Their vault is now at risk.
 
Linky?
Everything in the vault is AES256 encrypted. I assume you mean their customer database though.

If you haven't changed your master PW since 2018 you have bigger issues.
You will be surprised how many people have never changed their passwords.

The customer database contained emails, phone numbers etc, and the vault also stored unencrypted URL's


The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs,
 
Right, this is the final straw. Time to switch away -after nearly a decade as a paying family customer.

Thankfully, everything as secure as possible. Increased everything that could be increased when I had set it up (so higher than their defaults) Using 2FA, etc for last pass sign-in on new devices, etc too - so hoping at least that the encrypted blob is secure. Master passwords changed once a year too.

What is best equivalent solution I can consider ? Mix of iOS, Android, Windows and Mac PCs

Edit: not wanting a keepass / cloud storage type solution (which would be ok for me), as my wife uses this too and at least with LP, it was easy for her to use. Don't want her to jump multiple hoops.

If you are mixing Bitwarden.

If you aren’t need look no further than Apple Keychain.
 
Should they be closing their doors? I mean this is a major fail considering what their speciality is.
If customer data was properly encrypted, and if the passwords were properly encrypted according to industry standards, then the only risk is an increase in phishing attacks using the data that the attackers were able to decrypt.

This definitely raises concerns about how LastPass configures their storage, though. And how well they migrated legacy users to use stronger passwords and policies since 2018.
 
whats an unencrypted url , http ?
By design LastPass will not encrypt the URLs that you have login details for in your account. These are the addresses of the links you visit in plain text.

E.g: https://www.reddit.com/login/

When you log into the app, or the browser extension, it will decrypt the locally stored password credentials and give you the ability to edit them.

But before you log in, the extension is able to alert you that there are saved credentials available for the site you are visiting.

So if you visit Reddit on a browser with the extension installed, LastPass will prompt you to sign in to the extension using your master password, to then log into the site with stored credentials.
 
About 30 years ago I wrote down a little algorithm that the meatware between my ears was able to compute in around 15-20 seconds, all my passwords are different and computed from a master password with digit rotation, ASCII -> byte -> ASCII shifting and some other operations using the name of the company.

I'm sure given 100 or so of them it's possible to break the scheme easily, but it's good enough that I have differing passwords for everything without the need of a password manager.

D
Yeah, so eight RTX 4090 cards can crack a complex 8-character password in 48 minutes.

And if the encryption scheme used has a weakness, your methodology won't be of much help.


God help you if your passwords are less than 10 characters in length.
 
Last edited:
Was trying out 1password yesterday

Likes:-
Modern
Multiple vaults
Relatively easy to bring in last pass credentials

Dislikes:-
You can't increase the security parameters if you want
No real technical info on how they really work behind the scenes


Can't find it there is 2FA auth method for sign in

I need to reimport all my secure documents like passwords again.

No ability to reprompt for master password for what you deem sensitive. E.g. I had that enabled for all banking and social media sites, and secure notes

Can't choose which countries I should be able to login from . This is quite useful if somebody doesn't know which country you use

No ability to select multiple things to update tags ,delete (using web browser)

Anyway,
 
Was trying out 1password yesterday

Likes:-
Modern
Multiple vaults
Relatively easy to bring in last pass credentials

Dislikes:-
You can't increase the security parameters if you want
No real technical info on how they really work behind the scenes


Can't find it there is 2FA auth method for sign in

I need to reimport all my secure documents like passwords again.

No ability to reprompt for master password for what you deem sensitive. E.g. I had that enabled for all banking and social media sites, and secure notes

Can't choose which countries I should be able to login from . This is quite useful if somebody doesn't know which country you use

No ability to select multiple things to update tags ,delete (using web browser)

Anyway,
I bought a lifetime 1password license before they switched to subscription. Earlier this year they stopped support for the lifetime license so it doesn't work on Chrome anymore. I switched to Bitwarden and while I preferred 1password as an app, I much prefer Bitwarden's pricing.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X