TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

LastPass requesting password reset after facing unknown anomaly

111 点作者 sathyabhat大约 14 年前

15 条评论

twodayslate大约 14 年前
I am perfectly fine with them being paranoid. They should be. They are being paranoid for me. They are doing a good job protecting the user.
评论 #2516168 未加载
mbreese大约 14 年前
I'm curious about why they have an Asterix server on the same network as their database... is there a voice authentication feature, or are we just talking about their office phones?<p>Either way, they seem to be taking this seriously, even if they are just being overly paranoid, I find it comforting.
andrewcooke大约 14 年前
i'm surprised by the reactions here. maybe i am misunderstanding the blog post, or maybe others are?<p>as far as i can see they are being extremely paranoid. they seem to be monitoring (and following up on!) traffic flow, which is itself pretty impressive, are flagging this even though they have no other error signs, and have done a good enough job in their implementation that can say, without any more details, that the only risk is via brute force cracking.<p>i use keepassx locally, but my take on this is that they are way better than average. this kind of report would make me use a company, not switch from them.
jonursenbach大约 14 年前
Not happy that I'm finding this out via a blog post and not an email.
评论 #2516178 未加载
kjetil大约 14 年前
Nice to see a company so transparent about situations which could easily have been hushed down.
评论 #2516392 未加载
pstack大约 14 年前
Interesting, it isn't prompting me to do any such thing.<p>Anyway, since many are mentioning 1Password - I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows.<p>Also, since I use two-factor authentication, I wonder if that's the reason they have not asked me to change my password?
评论 #2516907 未加载
评论 #2516895 未加载
kitcar大约 14 年前
Wow, Lastpass won't let me login to my account now, and doesn't throw any error message whatsoever. When I try to change my password it says I can't because I don't have their browser plugin. Wacky, this is quite frustrating
评论 #2516843 未加载
alanh大约 14 年前
Result of me trying to log in to delete my account, just in case (having switched to 1Password): <a href="http://cl.ly/3T0B2W09262N3k2j2U3k" rel="nofollow">http://cl.ly/3T0B2W09262N3k2j2U3k</a>
dfischer大约 14 年前
So I just started using 1password and was thinking of lastpass. I'm still trying to figure out which is better. Anyone have any comments?
评论 #2517371 未加载
评论 #2518017 未加载
tomjen3大约 14 年前
That's not very smart considering that a lot of people won't be able to lockin to their email to verify their emails because they don't have access to the login details of their email because they haven't verified it.<p>And why the hell didn't they use scrybt in the first place? For a company so paranoid, that seems to border on neglect.
评论 #2516356 未加载
评论 #2516594 未加载
mike-cardwell大约 14 年前
That's the final straw for me. Just exported my login details, emptied out my lastpass vault and uninstalled the addon. Will stick to storing my login details in a Dropbox distributed GnuPG protected flat file. Less convenient, but at least I'm not reliant on a third party.
评论 #2517488 未加载
评论 #2516956 未加载
jojo1大约 14 年前
IMHO everyone who is using such a service is a moron.
评论 #2518039 未加载
maguay大约 14 年前
Suddenly, I'm glad I switched to 1Password.
评论 #2516336 未加载
crocowhile大约 14 年前
Does anyone know if there is a way to encrypt my lastpass db using both a password and an RSA private key?
kmfrk大约 14 年前
Let this be a reminder to LastPass to include a password expiration date by default.
评论 #2516700 未加载