TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

LastPass users locked out due to MFA resets

179 pointsby jonathanzufialmost 2 years ago

28 comments

8organicbitsalmost 2 years ago
&gt; The forced logout + MFA resync events are taking place as we increase all customer&#x27;s password iterations.<p>Typically you just need to wait for a user to log in, then validate the password against the old hash and create a new stronger replacement hash. Ending all sessions is a good way to log everyone out and force that. But I&#x27;m confused.<p>If weak password hashes were leaked, then the passwords need to be changed too. Increasing the rounds doesn&#x27;t prevent attacks on the previously leaked weak hashes. Maybe they expect everyone already did that but some people did it before they increased the hash rounds?<p>The MFA reset shouldn&#x27;t be related to the increase in hash rounds, those are unrelated. So they must suspect the MFA seeds were also stolen, but aren&#x27;t saying it, right?
评论 #36470045 未加载
评论 #36467818 未加载
palataalmost 2 years ago
Genuine question: why are there still LastPass users?<p>I mean, if you have a password manager, it means that you somehow care about your passwords. If you have LastPass, it means that you chose something that was not the default Google Wallet or Apple whatever-it-is-called.<p>Are there so many LastPass users who haven&#x27;t followed the news in the last 2 years?
评论 #36467787 未加载
评论 #36469032 未加载
评论 #36467681 未加载
评论 #36468976 未加载
评论 #36467982 未加载
评论 #36467674 未加载
评论 #36469762 未加载
评论 #36469271 未加载
评论 #36467870 未加载
评论 #36468196 未加载
skrausealmost 2 years ago
I recently discovered Vaultwarden (<a href="https:&#x2F;&#x2F;github.com&#x2F;dani-garcia&#x2F;vaultwarden">https:&#x2F;&#x2F;github.com&#x2F;dani-garcia&#x2F;vaultwarden</a>) and love it. It&#x27;s basically single Rust binary (self-compiled: <a href="https:&#x2F;&#x2F;github.com&#x2F;dani-garcia&#x2F;vaultwarden&#x2F;wiki&#x2F;Building-binary">https:&#x2F;&#x2F;github.com&#x2F;dani-garcia&#x2F;vaultwarden&#x2F;wiki&#x2F;Building-bin...</a>) with a SQLite3 database running on my own server, implementing the Bitwarden server API. I can use all the official Bitwarden apps on my phone and desktop, but have the backend and backups under my own control.
评论 #36468555 未加载
评论 #36472559 未加载
评论 #36468101 未加载
makachalmost 2 years ago
1Password is probably the best kept secret when it comes to password managers. I don’t understand why not more IT professionals advocate this software.
评论 #36467981 未加载
评论 #36469083 未加载
评论 #36468066 未加载
评论 #36471200 未加载
评论 #36470077 未加载
ClumsyPilotalmost 2 years ago
I don&#x27;t like any of this. Your passwords need to be with you, not rely on a server.<p>I use keypass, it stores all passwords in a file, encrypted. The file can be stored in Onedrive&#x2F;Dropbox&#x2F; etc.<p>But the point is, if all the aervers in the world go down, I have all my passwords in a local copy. There is also an android app.<p>You can even edit the database file independantly on desktop and on mobile and it will be able to merge two cobflicting files<p><a href="https:&#x2F;&#x2F;keepass.info&#x2F;download.html" rel="nofollow noreferrer">https:&#x2F;&#x2F;keepass.info&#x2F;download.html</a>
评论 #36468388 未加载
评论 #36468549 未加载
评论 #36469800 未加载
评论 #36468903 未加载
account-5almost 2 years ago
I genuinely don&#x27;t know why people don&#x27;t use offline databases like keepass. The conveinance of online password management is not worth the hassle they can cause. All be it lastpass appears to be tge worse!
评论 #36468940 未加载
评论 #36470030 未加载
评论 #36470652 未加载
评论 #36470750 未加载
causality0almost 2 years ago
Why would LastPass let you &quot;unsubscribe&quot; from critical security emails like &quot;hey you&#x27;re gonna be locked out&quot;? Or have they tied critical emails to marketing garbage emails in their communication preferences?
semiquaveralmost 2 years ago
I recently had to start using Lastpass for work and I am absolutely mind-boggled at what an all-around terrible piece of software it is. I have my complaints about 1Password but those are peanuts compared to the mile long list of show-stopping bugs and UX problems I experience every day with LP. Irredeemable garbage.
AlbertCoryalmost 2 years ago
I don&#x27;t use a password manager. You shouldn&#x27;t, either, probably, unless you want to share passwords with a group or something.<p>I have a file of hints which are only meaningful to me. Even if a malefactor got hold of the file, it wouldn&#x27;t help them. (no, I&#x27;m not going to give examples; if you can&#x27;t think of some combinations of characters that only you can remember, then fine, use a password manager). I&#x27;m always thinking of new ones, too.<p>You don&#x27;t need a unique one for every site, either. Having 15 or 20 that you choose at random means that an invalidated one doesn&#x27;t affect <i>everything</i> you do.<p>Occasionally, the Hint file has an actual gibberish password with no hint, where I have to copy&#x2F;paste it. I think this is fine once in a while.<p>All I really have to remember is the password for the place where that file is stored, and my email&#x27;s. Often it happens that my stored hint doesn&#x27;t work (maybe I forgot to update it), but every site has a Forgot Password link.
评论 #36469455 未加载
评论 #36470801 未加载
评论 #36469991 未加载
评论 #36469463 未加载
评论 #36469945 未加载
AdmiralAsshatalmost 2 years ago
I jumped ship to Bitwarden at the beginning of the year, and haven&#x27;t logged into LastPass in some time, although I forgot to delete my vault and account.<p>I suppose there&#x27;s some assurance that if I&#x27;m indefinitely locked out of the account then at least hackers are, too?
评论 #36469023 未加载
digdigdagalmost 2 years ago
Why anyone would continue to use their service after their amateur hour operation was revealed is beyond me. That&#x27;s not to say their competitors are guaranteed to be better. Really, you shouldn&#x27;t depend on any offsite service for password management. Use something like Pass (<a href="https:&#x2F;&#x2F;www.passwordstore.org&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.passwordstore.org&#x2F;</a>), self-hosted bitwarden or at worst, GPG encrypted text files (which is essentially what Pass does).
Obscurity4340almost 2 years ago
Hate to say it but these remaining users were and are fools for not having jumped ship like yesterday. This is not a serious + competent password manager product&#x2F;company. Hopefully they had backups or they are in for a world of hurt dealing with the worse mess of being stuck in such an absurd loop.
评论 #36467753 未加载
评论 #36467750 未加载
评论 #36468023 未加载
esskayalmost 2 years ago
More fool anyone silly enough to still be using LastPass.
dav1appalmost 2 years ago
I was an user of LastPass. Happly switched to Bitwarden.
sowbugalmost 2 years ago
It&#x27;s scary when a company ships a security feature with a buggy &quot;happy path,&quot; because it generally means the engineers who built it don&#x27;t follow personal best security practices themselves.<p>An example is whether a website&#x27;s login form works with browser autofill. If it doesn&#x27;t, it probably means the person who built that page doesn&#x27;t use browser autofill, which means they probably use the same password on all their personal accounts, which is terrifying. (Bad example for a product that&#x27;s supposed to replace the browser&#x27;s built-in password manager, but you get the idea.)
remote_phonealmost 2 years ago
I still use my licensed 1Password version from like 10 years ago. I share passwords over Dropbox to my other computers and I cut and paste passwords. It’s not hard at all and I don’t have to pay a subscription.
评论 #36469869 未加载
anonym29almost 2 years ago
No matter how many compromises, how many DoS events &#x2F; lockouts, or how many other times internet-based password managers royally screw up, it never ceases to amaze me how people continue to trudge back to these sorry services.<p>&quot;It&#x27;s so convenient!&quot; &quot;I don&#x27;t like having to manually sync between devices with &lt;100% local password manager&gt;!&quot;<p>Convenience addicts making excuses for their next hit of convenience... no matter how severely convenience harms them.
评论 #36469577 未加载
IG_Semmelweissalmost 2 years ago
Ok. I&#x27;ll take the advice here. I am a time-constrained Lastpass user. I&#x27;m aware of the issues but not thw seriousness. I will abandon the platform now, but I could use your help:<p>1- is industry gold standard 1password or bitwarden ? Key requisite: edge or FF browser extension. (I dont use mobile password management apps and will never do so)<p>2 - in light of the LP breaches. Do I change all my pw accounts, the master LP account, or both??
评论 #36468520 未加载
评论 #36467908 未加载
sashank_1509almost 2 years ago
Started with LastPass, switched to Bitwarden like 6 months back. It’s brilliant, it works and I never need to touch LastPass again
justincliftalmost 2 years ago
The problem of needing a current login session in order to access support is a fairly common failure mode in some organisations.<p>Strangely enough, some places don&#x27;t fix it when they learn about it. I&#x27;m not sure why though, as that makes no sense to me.
wryoakalmost 2 years ago
One reason I left LastPass was because it kept bypassing 2FA (or incorrectly presenting it when it for whatever reason wasn’t required) - I could just press cancel and then there all my passwords were. The macOS app was … wild
paultopiaalmost 2 years ago
the blame the user responses reported in this story are just hopeless. Also, as far as I can tell, untrue: I cancelled my lastpass subscription after the last horrific breach and migrated to a new password manager while changing my critical passwords, but every once in a while I have to use lastpass to dig up an old unimportant password for something that didn&#x27;t make the list for immediate changes... and I&#x27;ve never seen any kind of message about resetting MFA.
Whatarethesealmost 2 years ago
It&#x27;s just issue after issue with LastPass. Is it just apathy that is keeping people using them? There are much better options out there that are cheaper and better.
nicetryguyalmost 2 years ago
I don&#x27;t even let Chromium &#x2F; FF save my passwords what a genuinely horrible idea. Get off my lawn!!!
评论 #36467930 未加载
评论 #36467984 未加载
jrm4almost 2 years ago
To borrow a refrain from crypto; &quot;Not your keys, not your passwords.&quot;<p>Hope people don&#x27;t fall for the stupid thing that Google&#x2F;Apple et al are trying to do, either.
jmclnxalmost 2 years ago
I do not understand why people need to use these things, maybe they make it easier and more secure for Cell Phones ? I never use my Cell Phone for anything Finance or Medical Related.<p>But for me, I keep an encrypted text file and get the passwords my using emacs or vim. I generate passwords using:<p>tr -cd &quot;[:alnum:]&quot; &lt; &#x2F;dev&#x2F;urandom | fold -w 16 | sed 10q<p>and with the result I may replace 1 character with what they call a &quot;special character&quot;. To me that avoids a lot of worry.
评论 #36467843 未加载
评论 #36467720 未加载
评论 #36467741 未加载
评论 #36467752 未加载
评论 #36467732 未加载
评论 #36467711 未加载
评论 #36467754 未加载
friendlypegalmost 2 years ago
The entire website is written in PHP. I have nothing against the language, but it&#x27;s a major red flag when you would expect it to be using Java instead like most bank and government websites do.
评论 #36467673 未加载
评论 #36467640 未加载
评论 #36467635 未加载
bob1029almost 2 years ago
I am completely over the idea of storing secrets inside of one of these 3rd party systems. I&#x27;ve currently got a team member writing an internal secret storage app for our organization.<p>Creating a SQL schema with a &quot;Secrets&quot; table and maybe some audit logging and organizational extras should take a seasoned developer ~30 minutes. Throwing a CRUD web app on top of this and making it accessible to your employees - maybe another day or 2.<p>I really don&#x27;t know why you&#x27;d risk this sort of stuff with a 3rd party. It just boggles my mind. What are they doing that you can&#x27;t do? Even a 3 person startup can probably find time around a weekend to knock this out once and for all.<p>Edit: clearly I missed an important point. We don&#x27;t care about browser integration. I am not going for 1:1 feature replacement. If you seriously believe &quot;a safe place to keep internal text&quot; is an extremely hard problem that absolutely must be outsourced, I don&#x27;t know why you would even be involved in technology.
评论 #36467677 未加载
评论 #36467708 未加载
评论 #36467801 未加载
评论 #36467696 未加载
评论 #36468313 未加载
评论 #36467771 未加载
评论 #36467733 未加载
评论 #36467824 未加载
评论 #36467869 未加载
评论 #36469047 未加载