Page 1 of 2 1 2 LastLast
Results 1 to 15 of 19

Thread: LastPass password manager hacked-

  1. #1
    Fortis Fortuna Adiuvat Omega Man's Avatar
    Join Date
    Jan 2010
    Location
    Massachusetts
    Posts
    20,254

    Exclamation LastPass password manager hacked-

    World’s Most Popular Password Manager Says It Was Hacked-

    Via Bloomburg

    https://www.bloomberg.com/news/artic...-it-was-hacked

    OM
    "You can do good or you can do well. Sooner or later they make you choose". MI5
    Moderator Team.
    2009 F800GS 1994 TW200

  2. #2
    Registered User patm's Avatar
    Join Date
    Mar 2016
    Location
    Montreal, QC
    Posts
    571
    "
    The company doesn’t believe any passwords were taken as part of the breach and users shouldn’t have to take action to secure their accounts, according to a blog post on Thursday. "
    Just to be on the safe side I would change my password...
    Pat

    Ride Safe!
    '16 RT, '18 GSA

  3. #3
    I keep a list of my passwords for various sites in a secure physical location here, not on some cloud based server which can be hacked.
    The lion does not even bother to turn his head when he hears the small dog barking.

    https://www.youtube.com/user/azqkr

  4. #4
    Registered User rogerc60's Avatar
    Join Date
    Oct 2018
    Location
    Akron, OH
    Posts
    221
    I like Safe In Cloud. It syncs to all my devices, but they don't keep any of my data on their servers. Instead, my data is stored in my Google drive as an encrypted file, and it gets decrypted only on my local devices.

  5. #5
    YouTube Mechanic adamchandler's Avatar
    Join Date
    Apr 2016
    Location
    Hanover, NH USA
    Posts
    430
    Hilarious. I stopped using LastPass in 2010 the 2nd major time it was hacked. It proceeded to be breached at least 5 more times since then. When will people learn this company is not doing much to protect your passwords?

    Their Wiki page has a whole section devoted to security breaches - https://en.wikipedia.org/wiki/LastPass

    STOP USING LAST PASS.
    Social Media, Blog, YouTube | BMWMOA Lifetime Member | MOA Board Secretary | MOA Regional Coordinator | Former-Vermont BMW Club President

  6. #6
    Registered User czawade's Avatar
    Join Date
    Sep 2015
    Location
    Saskatoon, SK Canada
    Posts
    25
    While the number of hacks of LastPass is a concern (and of course they will be a target for hackers), they operate on a "trust no one" model. This means that even LastPass does not hold any of your passwords, including your master p/w.

    This is good and bad. The bad is that if you forget your master password, even LastPass can't retrieve it. Unless you created some onetime passwords, which LastPass recommends, you are SOL and your password store will be unrecoverable.

    The good is a case like this - hackers don't have access to your master password through LastPass, let alone your own passwords stored within.

    I have no affiliation with LastPass other than being a user. Frankly, while password managers are the best way of maintaining unique and random passwords for everything, they all could be a target of a hack. The fact that LastPass uses a trust no one model adds to its security for me. There are probably others doing the same, but none of them are 100% immune to clever hackers finding a way in.

    caz
    caz

    2015 R1200RT
    Success is 99% failure - Soichiro Honda

  7. #7
    Quote Originally Posted by czawade View Post
    While the number of hacks of LastPass is a concern (and of course they will be a target for hackers), they operate on a "trust no one" model. This means that even LastPass does not hold any of your passwords, including your master p/w.

    This is good and bad. The bad is that if you forget your master password, even LastPass can't retrieve it. Unless you created some onetime passwords, which LastPass recommends, you are SOL and your password store will be unrecoverable.

    The good is a case like this - hackers don't have access to your master password through LastPass, let alone your own passwords stored within.

    I have no affiliation with LastPass other than being a user. Frankly, while password managers are the best way of maintaining unique and random passwords for everything, they all could be a target of a hack. The fact that LastPass uses a trust no one model adds to its security for me. There are probably others doing the same, but none of them are 100% immune to clever hackers finding a way in.

    caz
    I'm of the mindset the only way my pwd's get hacked is if someone breaks into my house. Unlikely at best it's broken into, even more unlikely they'd be able to unlock the safe, even more unlikely they'd find the list under the carpet of one of the shelves./

    I trust no one with my passwords/acct log in's
    The lion does not even bother to turn his head when he hears the small dog barking.

    https://www.youtube.com/user/azqkr

  8. #8
    YouTube Mechanic adamchandler's Avatar
    Join Date
    Apr 2016
    Location
    Hanover, NH USA
    Posts
    430
    Quote Originally Posted by czawade View Post
    While the number of hacks of LastPass is a concern (and of course they will be a target for hackers), they operate on a "trust no one" model. This means that even LastPass does not hold any of your passwords, including your master p/w.

    This is good and bad. The bad is that if you forget your master password, even LastPass can't retrieve it. Unless you created some onetime passwords, which LastPass recommends, you are SOL and your password store will be unrecoverable.

    The good is a case like this - hackers don't have access to your master password through LastPass, let alone your own passwords stored within.

    I have no affiliation with LastPass other than being a user. Frankly, while password managers are the best way of maintaining unique and random passwords for everything, they all could be a target of a hack. The fact that LastPass uses a trust no one model adds to its security for me. There are probably others doing the same, but none of them are 100% immune to clever hackers finding a way in.

    caz

    I’ll approach this in a different way. While no method is 100% secure, there are other password companies out there that don’t get hacked every 12 months. That was my point.
    Social Media, Blog, YouTube | BMWMOA Lifetime Member | MOA Board Secretary | MOA Regional Coordinator | Former-Vermont BMW Club President

  9. #9
    Back in the saddle again mikegalbicka's Avatar
    Join Date
    Aug 2014
    Location
    Lakeland,FL
    Posts
    2,764
    LastPass users: Your info and password vault data are now in hackers’ hands
    Password manager says breach it disclosed in August was much worse than thought.

    https://arstechnica.com/information-...customer-info/

  10. #10
    Fortis Fortuna Adiuvat Omega Man's Avatar
    Join Date
    Jan 2010
    Location
    Massachusetts
    Posts
    20,254
    I just received an offer to sign up for LastPass.

    I think I will Pass.

    OM
    "You can do good or you can do well. Sooner or later they make you choose". MI5
    Moderator Team.
    2009 F800GS 1994 TW200

  11. #11
    Back in the saddle again mikegalbicka's Avatar
    Join Date
    Aug 2014
    Location
    Lakeland,FL
    Posts
    2,764
    Note: the following is only for computer geeks like me. All others ignore as it will sound like gibberish.

    About six months ago I investigated how to host my own secure password manager free of any monthly charges and with minimum investment in hardware and have been very happy with the results. This project would only be for those who are computer literate with some proficiency with Docker and Linux and some hardware skills as well.

    I had already learned how to set up a Raspberry Pi with Docker in order to run my own Unbound DNS server (forwarding to Cloudflare) and a PiHole network wide ad blocker. At the time I chose to use the Pi Zero 2 W (wireless only) because Pi supplies were quite limited due to supply chain issues. They have since recovered so many of the other models are now available and the new 5 was just announced. PiHole does a great job of blocking most ads on every device on your local network when set up in conjunction with your router/DHCP server. Besides the benefit of not being bothered with pesky advertising and thus not tracked web pages also load faster since those graphics/videos don’t load. Running your own Unbound DNS server with local cache also speeds up your DNS queries. Most of this project is outlined at the following links and is a combination of the two. Build your secure Pi first but do not install PiHole. Then install Docker and Portainer to help manage Docker containers. Then install Unbound and PiHole containers and configure.

    https://thesmashy.medium.com/buildin...e-f762dbcb66e5

    https://homenetworkguy.com/how-to/in...and-portainer/

    Since I already had this infrastructure running it wasn’t too difficult to add the Vaultwarden container to my Pi which is where you host your own secure password manager. I chose it because it supports the use of YubiKey hardware devices and makes use of the popular free Bitwarden clients on all your devices that need password provided access (Windows, most browsers, Android and iOS). When outside your private home network you connect via VPN to your router (I prefer ASUS running Merlin firmware) to access your password vault. All communication is heavily encrypted and is as safe as it gets and only in your possession. The following links were helpful.

    https://medium.com/codex/complete-se...i-24b59c3b02df

    https://github.com/dani-garcia/vaultwarden

    If you enjoy a challenge with very beneficial results at a very low price point you might want to consider something similar.

  12. #12
    Registered User kbasa's Avatar
    Join Date
    Mar 2003
    Location
    Sonoma County, California
    Posts
    12,721
    Apple password manager for me. Works great. OS native.
    Dave Swider
    Marin County, CA

    Some bikes. Some with motors, some without.

  13. #13
    Back in the saddle again mikegalbicka's Avatar
    Join Date
    Aug 2014
    Location
    Lakeland,FL
    Posts
    2,764
    Quote Originally Posted by kbasa View Post
    Apple password manager for me. Works great. OS native.
    Yep if you only have that ecosystem to support and don’t need any of the advanced features (password sharing with the wife for example) that a rich password manager offers it can satisfy your needs.

    I have resisted getting locked into one ecosystem especially since my IT career dictated that I would need to support all of them. Thus I have an Android phone, iPadOS tablet, Windows and Linux desktops and laptops.

  14. #14
    RK Ryder
    Join Date
    Sep 2005
    Location
    London, Ontario
    Posts
    3,499
    Quote Originally Posted by brownie0486 View Post
    I keep a list of my passwords for various sites in a secure physical location here, not on some cloud based server which can be hacked.
    Likewise.
    Paul F. Ruffell
    Retired and riding my RTs, the '87 K100 & the '98 R1100 !
    Knights of the Roundel #333

  15. #15
    Back in the saddle again mikegalbicka's Avatar
    Join Date
    Aug 2014
    Location
    Lakeland,FL
    Posts
    2,764
    “Quote Originally Posted by brownie0486

    I keep a list of my passwords for various sites in a secure physical location here, not on some cloud based server which can be hacked.”

    Quote Originally Posted by Paul_F View Post
    Likewise.
    That is exactly what this solution does for you. Likewise it gives you access to it from anywhere in the world.

    I also encourage you to have a backup in a separate secure location in case of fire or other disaster.
    Last edited by mikegalbicka; 10-01-2023 at 10:57 PM.

Similar Threads

  1. Sena Device Manager problems
    By jgoertz in forum Gear
    Replies: 7
    Last Post: 09-06-2020, 07:07 PM
  2. Replies: 3
    Last Post: 09-06-2008, 12:12 PM
  3. Replies: 18
    Last Post: 11-23-2006, 02:58 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •