TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

LastPass password vaults crackable for $100, alleges 1Password

55 pointsby nonoespover 2 years ago

6 comments

hacymover 2 years ago
Strange that the article doesn’t specify the $100 for what… I assume computing power.<p>Headline reads as someone is offering as a service. Anyone else read it like that?
评论 #34210684 未加载
评论 #34210470 未加载
评论 #34210423 未加载
TechBro8615over 2 years ago
Can anyone explain why all the emphasis on hashing algorithms? Can&#x27;t the attacker just treat the encrypted vault like a black box and brute force passwords against it? Or is there some additional key material that needs to be guessed along with the password?<p>For example, if the master password is one of the 100k most common passwords, can the attacker loop through those passwords and attempt to open the vault with each? So there would only be 100k iterations required? Or does each check need its own set of iterations?
评论 #34213063 未加载
评论 #34213081 未加载
infinitedataover 2 years ago
Could LastPass be an intentional backdoor from some Government or entity?
评论 #34211902 未加载
评论 #34213968 未加载
ostenningover 2 years ago
Can anyone recommend some “offline only” password generation tools? I don’t see why passwords need be stored on a server at all. Something with mobile support would be ideal
评论 #34211779 未加载
评论 #34213219 未加载
评论 #34211953 未加载
评论 #34211734 未加载
评论 #34211755 未加载
评论 #34211712 未加载
jeffybefffy519over 2 years ago
This blog post is the biggest load of shit I have read in a while, it jumps all over the place and does not deliver the message that it is trying to do. Instead it demonstrates arrogance by the author.<p>The difference between being breached and not being breached is huge and this authors mindset about 1passwords security would change a lot if he was in Lastpass shoes.
sufficientover 2 years ago
Goldberg&#x27;s answer &quot;The 1Password Secret Key may not be the most user-friendly aspect of our human-centered design...&quot; is unfortunately true.<p>We experienced a lack of understanding on the user side that this secret key needs to be printed and stored safely. It feels like a huge barrier for the adoption of 1Password for non-IT affine people.<p>This and other challenges led us to develop heylogin which does not require a master password and has no secret key that needs to be printed. Instead we generate cryptographic keys using the user&#x27;s smartphone. For providing your desktop browser temporary access to passwords you simply confirm on your smartphone. This feels similar to modern SSO solutions but is technically a password manager.
评论 #34212979 未加载
评论 #34213550 未加载
评论 #34212186 未加载
评论 #34212373 未加载