If this is your first visit, be sure to
check out the FAQ by clicking the
link above. You may have to register
before you can post: click the register link above to proceed. To start viewing messages,
select the forum that you want to visit from the selection below.
I saw this today too. Pretty bummed about it, since of course I use it on both all the time. Everyone does, which is the point. But the service is so good, I already felt like I should be paying for it.
Ain't it like most people, I'm no different. We love to talk on things we don't know about.
Dig your own grave, and save!
"The only one of us who is so significant that Jeff owes us something simply because he decided to grace us with his presence is falafel." -- All-American
"I know that you are one of the cool and 'edgy' BYU fans" -- Wally
Been using Lastpass. Just got this email. Yeah, you have really gained my confidence here.
Dear valued customer,
We are writing to inform you that we recently detected some unusual activity within portions of the LastPass development environment. We have determined that an unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information. We have no evidence that this incident involved any access to customer data or encrypted password vaults. Our products and services are operating normally.
In response, we immediately initiated an investigation, deployed containment and mitigation measures, and engaged a leading cybersecurity and forensics firm. While our investigation is ongoing, we have achieved a state of containment, implemented additional enhanced security measures, and see no further evidence of unauthorized activity.
Based on what we have learned and implemented, we are evaluating further mitigation techniques to strengthen our environment. We will continue to update our customers with the transparency they deserve.
I got locked out of my LastPass back in November when my computer crashed and they had no way of recovering my password. I didn't have it written down (my mistake) and I could remember about 95% of it, but I couldn't remember it perfectly. It has been a PITA creating all new passwords, but i've just switched over to using the Keychain on my iPhone. Probably not as secure, but when my stuff gets leaked in an Apple data breach, at least Apple will have the deep pockets to make me whole.
Prepare to put mustard on those words, for you will soon be consuming them, along with this slice of humble pie that comes direct from the oven of shame set at gas mark “egg on your face”! -- Moss
There's three rules that I live by: never get less than twelve hours sleep; never play cards with a guy who's got the same first name as a city; and never go near a lady's got a tattoo of a dagger on her body. Now you stick to that, everything else is cream cheese. --Coach Finstock
Ain't it like most people, I'm no different. We love to talk on things we don't know about.
Dig your own grave, and save!
"The only one of us who is so significant that Jeff owes us something simply because he decided to grace us with his presence is falafel." -- All-American
"I know that you are one of the cool and 'edgy' BYU fans" -- Wally
The database with user names and passwords was hacked. Supposedly if you had a strong enough master password, the hackers won't be able to do anything with your portion of that hack.
The database with user names and passwords was hacked. Supposedly if you had a strong enough master password, the hackers won't be able to do anything with your portion of that hack.
Hmmmmmmmm.
Ain't it like most people, I'm no different. We love to talk on things we don't know about.
Dig your own grave, and save!
"The only one of us who is so significant that Jeff owes us something simply because he decided to grace us with his presence is falafel." -- All-American
"I know that you are one of the cool and 'edgy' BYU fans" -- Wally
The database with user names and passwords was hacked. Supposedly if you had a strong enough master password, the hackers won't be able to do anything with your portion of that hack.
I am going to change all of my important passwords just in case someone ever cracks my code.
"There is no creature more arrogant than a self-righteous libertarian on the web, am I right? Those folks are just intolerable."
"It's no secret that the great American pastime is no longer baseball. Now it's sanctimony." -- Guy Periwinkle, The Nix.
"Juilliardk N I ibuprofen Hyu I U unhurt u" - creekster
I am going to change all of my important passwords just in case someone ever cracks my code.
I think that's a reasonable approach. I haven't seen any reason to believe that anyone else will do better moving forward. But for the grace of God go they...
Keepass - encryption on the password DB file stored locally on my home computer with a 20 character master password and a separate key file.
Sync the encrypted DB to OneDrive. OneDrive itself is encrypted but OneDrive encryption doesn't matter that much. Don't sync the key file. If the attacker is able to obtain the encrypted DB from OneDrive or in transit somehow, they still need my master password AND the key file.
Sync the encrypted DB to my iPhone using the OneDrive app. Syncing is both ways such that changes I make on my phone are synced to my PC and vice versa.
Manually install a copy of the key file on my iPhone.
Keepassium app on my iPhone to unencrypt the DB using the master password and the and allow me to retrieve/add/edit passwords.
Also, I generally have 2-factor Authentication turned on for accounts that I care about like financial accounts. I've used both OKTA's and Symantec's authenticator apps. I'm currently on OKTA because that's what my employer uses. Both apps are free and they work pretty much the same way, generating a 6-digit code that changes every 30 seconds.
Pros:
Secure enough for most purposes. Not much will stop a well-funded attacker like a nation-state if they were determined to compromise you specifically, but it makes an attack on the front door difficult enough that it should keep out even your better-than-average script kiddies.
Free
Open-source, lots of extensions and integrations if that is your thing - read below.
Cons:
Doesn't have any default browser plugin thing where it will auto-fill my passwords. I personally don't care about this but some people consider this a must-have. But because KeePass is open source there are a ton of browser plugins out there available for it. There are also a ton of extensions and integrations such as bluetooth key exchangers, token/pin systems, all kinds of crazy stuff. My setup works for me so I don't bother with any of that stuff but if you really want to geek out on an open-source password safe you can go to town with KeePass.
Your granny might not have the technical skill to set it up although it's really pretty simple. My Art History college student was able to set it up with the OneDrive sync and the Keepassium app with zero assistance from me.
Comment