Who uses a password keeper?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • SCcoug
    Senior Member
    • Nov 2008
    • 7625

    #31
    Lastpass is changing up the free version to only work on your choice of either mobile or computer (desktop and laptop) not both.

    https://blog.lastpass.com/2021/02/ch...lastpass-free/

    Comment

    • falafel
      loves to talk on things
      • Mar 2009
      • 37928

      #32
      Originally posted by SCcoug View Post
      Lastpass is changing up the free version to only work on your choice of either mobile or computer (desktop and laptop) not both.

      https://blog.lastpass.com/2021/02/ch...lastpass-free/
      I saw this today too. Pretty bummed about it, since of course I use it on both all the time. Everyone does, which is the point. But the service is so good, I already felt like I should be paying for it.
      Ain't it like most people, I'm no different. We love to talk on things we don't know about.

      Dig your own grave, and save!

      "The only one of us who is so significant that Jeff owes us something simply because he decided to grace us with his presence is falafel." -- All-American

      "I know that you are one of the cool and 'edgy' BYU fans" -- Wally

      GIVE 'EM HELL, BRIGHAM!

      Comment

      • Bo Diddley
        Senior
        • Jul 2012
        • 18765

        #33
        Been using Lastpass. Just got this email. Yeah, you have really gained my confidence here.

        Dear valued customer,

        We are writing to inform you that we recently detected some unusual activity within portions of the LastPass development environment. We have determined that an unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information. We have no evidence that this incident involved any access to customer data or encrypted password vaults. Our products and services are operating normally.

        In response, we immediately initiated an investigation, deployed containment and mitigation measures, and engaged a leading cybersecurity and forensics firm. While our investigation is ongoing, we have achieved a state of containment, implemented additional enhanced security measures, and see no further evidence of unauthorized activity.

        Based on what we have learned and implemented, we are evaluating further mitigation techniques to strengthen our environment. We will continue to update our customers with the transparency they deserve.

        We have set up a blog post dedicated to providing more information on this incident: https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/

        We thank you for your patience as we work expeditiously to complete our investigation and regret any concerns this may have caused you.

        Sincerely,
        The Team at LastPass

        Comment

        • Donuthole
          Official Outgayer
          • Nov 2008
          • 25242

          #34
          I got locked out of my LastPass back in November when my computer crashed and they had no way of recovering my password. I didn't have it written down (my mistake) and I could remember about 95% of it, but I couldn't remember it perfectly. It has been a PITA creating all new passwords, but i've just switched over to using the Keychain on my iPhone. Probably not as secure, but when my stuff gets leaked in an Apple data breach, at least Apple will have the deep pockets to make me whole.
          Prepare to put mustard on those words, for you will soon be consuming them, along with this slice of humble pie that comes direct from the oven of shame set at gas mark “egg on your face”! -- Moss

          There's three rules that I live by: never get less than twelve hours sleep; never play cards with a guy who's got the same first name as a city; and never go near a lady's got a tattoo of a dagger on her body. Now you stick to that, everything else is cream cheese. --Coach Finstock

          Comment

          • Bo Diddley
            Senior
            • Jul 2012
            • 18765

            #35
            Anyone ditching LastPass for something else?

            Comment

            • falafel
              loves to talk on things
              • Mar 2009
              • 37928

              #36
              Originally posted by Bo Diddley View Post
              Anyone ditching LastPass for something else?
              No, should I? What happened?
              Ain't it like most people, I'm no different. We love to talk on things we don't know about.

              Dig your own grave, and save!

              "The only one of us who is so significant that Jeff owes us something simply because he decided to grace us with his presence is falafel." -- All-American

              "I know that you are one of the cool and 'edgy' BYU fans" -- Wally

              GIVE 'EM HELL, BRIGHAM!

              Comment

              • Bo Diddley
                Senior
                • Jul 2012
                • 18765

                #37
                Originally posted by falafel View Post

                No, should I? What happened?
                The database with user names and passwords was hacked. Supposedly if you had a strong enough master password, the hackers won't be able to do anything with your portion of that hack.

                Comment

                • falafel
                  loves to talk on things
                  • Mar 2009
                  • 37928

                  #38
                  Originally posted by Bo Diddley View Post

                  The database with user names and passwords was hacked. Supposedly if you had a strong enough master password, the hackers won't be able to do anything with your portion of that hack.
                  Hmmmmmmmm.
                  Ain't it like most people, I'm no different. We love to talk on things we don't know about.

                  Dig your own grave, and save!

                  "The only one of us who is so significant that Jeff owes us something simply because he decided to grace us with his presence is falafel." -- All-American

                  "I know that you are one of the cool and 'edgy' BYU fans" -- Wally

                  GIVE 'EM HELL, BRIGHAM!

                  Comment

                  • Jeff Lebowski
                    Corporate lackey for Jesus
                    • Nov 2008
                    • 69589

                    #39
                    Originally posted by Bo Diddley View Post

                    The database with user names and passwords was hacked. Supposedly if you had a strong enough master password, the hackers won't be able to do anything with your portion of that hack.
                    I am going to change all of my important passwords just in case someone ever cracks my code.
                    "There is no creature more arrogant than a self-righteous libertarian on the web, am I right? Those folks are just intolerable."
                    "It's no secret that the great American pastime is no longer baseball. Now it's sanctimony." -- Guy Periwinkle, The Nix.
                    "Juilliardk N I ibuprofen Hyu I U unhurt u" - creekster

                    Comment

                    • Bo Diddley
                      Senior
                      • Jul 2012
                      • 18765

                      #40
                      Originally posted by Jeff Lebowski View Post

                      I am going to change all of my important passwords just in case someone ever cracks my code.
                      I think that's a reasonable approach. I haven't seen any reason to believe that anyone else will do better moving forward. But for the grace of God go they...

                      Comment

                      • BigFatMeanie
                        Senior Member
                        • Nov 2008
                        • 7104

                        #41
                        My setup:
                        • Keepass - encryption on the password DB file stored locally on my home computer with a 20 character master password and a separate key file.
                        • Sync the encrypted DB to OneDrive. OneDrive itself is encrypted but OneDrive encryption doesn't matter that much. Don't sync the key file. If the attacker is able to obtain the encrypted DB from OneDrive or in transit somehow, they still need my master password AND the key file.
                        • Sync the encrypted DB to my iPhone using the OneDrive app. Syncing is both ways such that changes I make on my phone are synced to my PC and vice versa.
                        • Manually install a copy of the key file on my iPhone.
                        • Keepassium app on my iPhone to unencrypt the DB using the master password and the and allow me to retrieve/add/edit passwords.
                        Also, I generally have 2-factor Authentication turned on for accounts that I care about like financial accounts. I've used both OKTA's and Symantec's authenticator apps. I'm currently on OKTA because that's what my employer uses. Both apps are free and they work pretty much the same way, generating a 6-digit code that changes every 30 seconds.

                        Pros:
                        • Secure enough for most purposes. Not much will stop a well-funded attacker like a nation-state if they were determined to compromise you specifically, but it makes an attack on the front door difficult enough that it should keep out even your better-than-average script kiddies.
                        • Free
                        • Open-source, lots of extensions and integrations if that is your thing - read below.
                        Cons:
                        • Doesn't have any default browser plugin thing where it will auto-fill my passwords. I personally don't care about this but some people consider this a must-have. But because KeePass is open source there are a ton of browser plugins out there available for it. There are also a ton of extensions and integrations such as bluetooth key exchangers, token/pin systems, all kinds of crazy stuff. My setup works for me so I don't bother with any of that stuff but if you really want to geek out on an open-source password safe you can go to town with KeePass.
                        • Your granny might not have the technical skill to set it up although it's really pretty simple. My Art History college student was able to set it up with the OneDrive sync and the Keepassium app with zero assistance from me.

                        Comment

                        Working...