Unconfigured Ad Widget

Collapse

LastPass data breach...again!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • arrix
    Veteran Member
    • May 2012
    • 3942

    LastPass data breach...again!

    Two weeks ago, the password manager giant LastPass disclosed its systems were compromised for a second time this year.
    Two data breaches in one year? If you use this service, I think it might be time to look elsewhere for pw management.

    LINK: https://techcrunch.com/2022/12/14/pa...breach-notice/
    There is no week nor day nor hour, when tyranny may not enter upon this country, if the people lose their supreme confidence in themselves -- and lose their roughness and spirit of defiance -- Tyranny may always enter -- there is no charm, no bar against it -- the only bar against it is a large resolute breed of men.

    -Walt Whitman
  • #2
    TacFan
    Veteran Member
    • Jan 2006
    • 3021

    first place I would go to as a crook. A place where people store all of their passwords.

    Remember, you sacrifice security for convenience. Come up with a system in your head and use passwords for categories so you are not always using the same password everywhere.
    For Sale
    🔫 Pistols

    ☠ Rifles

    Comment

    • #3
      AtomicOrange
      Member
      • Jan 2013
      • 379

      Yeah, I tried a similar system years ago and could not get comfortable with it. Just did not seem right, so I abandoned that idea pretty quickly. Might have been Keypass?

      Edit: our cyber guy at work recommended plain old pencil and paper as the safest approach --nothing digital. I used a encrypted container for a while, but too much effort to maintain.
      Last edited by AtomicOrange; 12-25-2022, 8:20 PM.

      Comment

      • #4
        WoodTurner
        CGN/CGSSA Contributor
        CGN Contributor
        • Apr 2010
        • 286

        I like both Keepass and Bitwarden.
        Keepass if you don't want any cloud/remote access and are willing to spend the extra effort dealing with backups and transferring to other devices.
        Bitwarden if you want to host your own server or want a paid cloud solution (as well as the potential downsides that come with that, see OP)

        Should also have 2FA on any important accounts.

        Comment

        • #5
          nate76239
          Senior Member
          • May 2013
          • 1627

          They use last pass at my job but I had never signed up to use it fortunately. We got an email about the breach recently.

          Comment

          • #6
            rodralig
            CGN Contributor
            • Apr 2016
            • 4262

            Abandoned LastPass years back...

            I now use 1Password for my PW management across devices/browsers, etc.


            _

            WEGC - Shooting at 10-yards VS 20-yards - https://www.youtube.com/watch?v=h7mdbNZ4j9U

            Comment

            • #7
              Cowboy T
              Calguns Addict
              • Mar 2010
              • 5725

              KeePass is a good solution. There are versions for MS Windows, Mac OS, and GNU/Linux. Since KeePass and its derivatives are Free Software under the GNU GPL, the issue of backdoors is severely mitigated.
              "San Francisco Liberal With A Gun"
              F***ing with people's heads, one gun show at a time. Hallelujah!
              http://www.sanfranciscoliberalwithagun.com (reloading info w/ videos)
              http://www.liberalsguncorner.com (podcast)
              http://www.youtube.com/sfliberal (YouTube channel)
              ----------------------------------------------------
              To be a true Liberal, you must be 100% pro-Second Amendment. Anything less is inconsistent with liberalism.

              Comment

              • #8
                high_revs
                CGN/CGSSA Contributor
                CGN Contributor
                • Feb 2006
                • 7629

                i only use it for non-financial stuff and my logins i use thre don't "keep" the payment card. as a best practice in case those vendors i use also get hacked, don't keep credit cards online. i go about maybe 4-5 different user names and 4 key passwords with minor variations (depends on each site's password rules). it's easy enough to key in the credit card if you're making a purchase.



                they do say.. still need the master key from the user to unlock the passwords.

                Comment

                • #9
                  WoodTurner
                  CGN/CGSSA Contributor
                  CGN Contributor
                  • Apr 2010
                  • 286

                  Originally posted by high_revs
                  i only use it for non-financial stuff and my logins i use thre don't "keep" the payment card. as a best practice in case those vendors i use also get hacked, don't keep credit cards online. i go about maybe 4-5 different user names and 4 key passwords with minor variations (depends on each site's password rules). it's easy enough to key in the credit card if you're making a purchase.



                  they do say.. still need the master key from the user to unlock the passwords.
                  That's a terrible plan.

                  Comment

                  Working...
                  UA-8071174-1