More than $35 million has been stolen from over 150 victims since December — ‘nearly every victim’ was a LastPass user::Security experts believe some of the LastPass password vaults stolen during a security breach last year have now been cracked open following a string of cryptocurrency heists

You are viewing a single thread.
View all comments
161 points

Bitwarden or keepass ftw

permalink
report
reply
70 points

I dumped LastPass for Bitwarden a few years ago. So glad I did.

permalink
report
parent
reply
4 points

Same! Thinking i coulda been a victim in this attack is scary!

permalink
report
parent
reply
52 points

Selfhosted for extra win!?

permalink
report
parent
reply
18 points

Any recommendations on how-to?

permalink
report
parent
reply
34 points

KeepassXC (desktop)/KeePassDX(mobile) on top of something like Syncthing or Nextcloud.

permalink
report
parent
reply
27 points
*

Vaultwarden is what I use: https://github.com/dani-garcia/vaultwarden/

Their wiki is pretty good assuming you’re comfortable with Docker.

Back before I self-hosted, KeePassXC for desktop and Keepass2Android for mobile (along with Synching to sync the database) got the job done.

permalink
report
parent
reply
11 points

It doesn’t have to be difficult.

  1. Download keepass to your computer.

  2. Keep the save file on a USB or private cloud backup.

  3. Done!

As you get more comfortable with it, you’ll start using it in more complex ways. Like having a phone app, connected to a self hosted network. But keep it simple for now.

permalink
report
parent
reply
6 points
*

If you wanna use KeePass, you just have to store your database in some secure location. It can be on your local drive or in the cloud, any location you trust really.

permalink
report
parent
reply
2 points

Vaultwarden!

permalink
report
parent
reply
4 points

Self-hosted with yubikey 2fa. Even Santa Claus can’t see my info 😎

permalink
report
parent
reply
1 point

I should get around to doing this… But it scares me haha.

permalink
report
parent
reply
12 points

So what makes Bitwarden better than LastPass if you’re using Bitwarden’s hosted option (I know you can keep it locally).

permalink
report
parent
reply
24 points

From what I remember (take this with a grain of salt since it’s all from when the big LastPass breach happened,) LastPass didn’t actually encrypt your entire vault. They only encrypted the passwords. The rest of the vault, (which would be comprised of usernames and the sites that are associated with them, notes, images, etc) were unencrypted. So even without cracking any vaults, hackers got access to gigantic lists of usernames and their associated email addresses. That’s valuable in and of itself, because it allows them to spear-phish those users.

For example, you may not fall for a regular phishing scam. But you may fall for it if the email has your username and recovery info in it. Because they know every email you’ve used to sign up for something and all of your different usernames that you used on that site, so they can craft convincing phishing emails that are specifically tailored to you.

It also allows them to search for specific users. Maybe there is a user on a crypto forum who is particularly noteworthy. Their username is already known on the site, and hackers are able to cross-reference that with the list of known usernames/emails and see if that user’s vault was part of the breach. If it was, they can focus on breaching that one user’s vault, instead of aimlessly trying random vaults.

permalink
report
parent
reply
7 points

That’s valuable in and of itself, because it allows them to spear-phish those users.

I’m sorry, this is the first time I’m hearing the term spear-phish and I love it. It’s hilarious.

permalink
report
parent
reply
6 points
*

LastPass didn’t actually encrypt your entire vault. They only encrypted the passwords. The rest of the vault, (which would be comprised of usernames and the sites that are associated with them, notes

Wait a moment… now I wonder how many people kept their crypto wallet recovery word lists as notes instead of as passwords.

permalink
report
parent
reply
22 points

I’m not 100% but I think Bitwarden actual encrypt the entire ‘password object’. So the url, username, password, and any notes. Lastpass didn’t/doesn’t encrypt the url so if anyone gets access to the vault, they have a list of websites where the person will have an account and can more accurately send phishing emails.

permalink
report
parent
reply
1 point

It encrypts the entire vault iirc, not the objects themselves. The only thing a breach cound gain access to is the encrypted vault, the hashed master password and the master email.

permalink
report
parent
reply
-5 points

There’s no such thing as an impenetrable password manager. I keep my most secure passwords in my head, and so should everyone.

Even if the software were perfect, people aren’t. Anyone can be fooled under the right circumstances. It’s better to expose one service than all of them at once.

permalink
report
parent
reply
4 points

Your head cannot be securely backed up, and you are not resistant to major thread actors (torture, and so on)

permalink
report
parent
reply
2 points

2fA is an important element too.

permalink
report
parent
reply
1 point

How would someone steal my password and my physical yubikey for 2fa?

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 18K

    Monthly active users

  • 12K

    Posts

  • 553K

    Comments