Re: LastPass Vault Breached via Employee's Home Computer

The Stuff of Legend <Use-Author-Supplied-Address-Header@[127.1]> Wed, 1 Mar 2023 23:26:05 +0000 (GMT)
Newsgroups alt.computer.security,alt.privacy.anon-server
Organization dizum.com - The Internet Problem Provider
Message-ID <[email protected]>
On Wed,  1 Mar 2023 21:03:08 +0100 (CET), anonymous <[email protected]> said in 
Message-ID: <[email protected]>:

> On 28 Feb 2023, The Stuff of Legend
> <Use-Author-Supplied-Address-Header@[127.1]> posted some
> news:[email protected]: 
> 
>> On Tue, 28 Feb 2023 20:04:06 -0600, [email protected] said in 
>> Message-ID: <[email protected]>: 
>> 
>>> https://pjmedia.com/news-and-politics/gregbyrnes/2023/02/28/lastpass-v
>>> ault-breached-via-employees-home-computer-giving-keys-to-the-kingdom-t
>>> o-hackers-n1674308 
>>> 
>>> "Millions of LastPass users may be at risk after a major breach of
>>> the home computer of one of their top employees. This employee was
>>> only one of four people in the company with access to their corporate
>>> vault. The breach may have come through a home Plex media account,
>>> according to Ars Technica*, and appears to have been perpetrated by
>>> the same hackers who breached LastPass security on a smaller scale
>>> last August. At about the same time, Plex’s security was also
>>> breached."
>>> 
>>> *https://arstechnica.com/information-technology/2023/02/lastpass-hacke
>>> rs-infected-employees-home-computer-and-stole-corporate-vault/ 
>>> 
>>> This is wjy I don't use password mangagers.  I keep my
>>> passwords/phrases in a PGP file on my comp. 
>>> Yeah, I gotta copy paste after opening the PGP, but it is safer than
>>> using password "protector" dumbware like LastPass.
>> 
>> The problem isn't password managers, per-se -- the problem is relying
>> on a cloud- based provider like LastPass. BTW, using PGP is a *great*
>> idea for protecting your passwords and other confidential data,
>> especially if you use symmetric encryption to do so, using a
>> Diceware™ passphrase. 
> 
> Sucks when you die and your executor must settle your estate.  You just 
> handed a government the majority, if not all of your hard earned assets 
> because nobody could access your financials for lack of password details. 
> 
> The government doesn't care.  They will wait the seven years to gleefully 
> take your money.  Of course you won't care that your family was destitute 
> or even homeless because you're dead.

You must take me for a complete idiot. I've made appropriate arrangements, which
have been in place for quite some time now. 

>> Back in the day, in a moment of madness, I seriously considered using
>> LastPass, but ultimately what turned me off, and made me change my
>> mind, was the cloud- based nature of the service. I just don't feel
>> comfortable storing /any/ data in the cloud, regardless of its'
>> sensitivity. 
> 
> Oh come on.  You know India managed cloud resources are safe.  Just ask 
> IBM, HPE, Dell and Kyndryl.  They will tell you so.

I don't care what anyone says -- I simply don't trust cloud-based services, and 
that isn't going to change anytime soon. 

YMMV