HN user

rosnd

27 karma
Posts1
Comments239
View on HN

Remember that last pass has just been caught lying about their security, and you can't trust what they say.

I'm curious, what were they caught lying about?

What proof do you have that last pass uses that encryption scheme? Is there any evidence to suggest that it meets rigorous standards?

LastPass has been extensively reverse engineered. There are, for example, public Defcon talks about it.

Changing passwords in the face of a breach like this is standard practice and is the only logical step forward.

This is not logical at all.

You cannot trust last pass security from this point forward.

Why not? Because they disclosed a breach?

If you don't trust LastPass to encrypt your passwords properly, why would you use it at all?

That exact kind of thing happens constantly

Like when?

And of course, the nature of the concern here involves us not knowing that LastPass was fucking up.

What do you mean? The cryptography used by LastPass is very well understood.

Your encrypted data is compromised, it is in the hands of an attacker who really wants to decrypt it. You're pinning all of your digital security on encryption holding against an active attacker.

Well, yeah. Just like you leak your encrypted password to the internet every single time you log into a website.

What if there is an undiscovered or undisclosed vulnerability in the encryption?

lmao, if aes-256-cbc is broken then LastPass is probably the least of anyone's concerns. This happens to also be one of the more difficult AES modes to screw up.

What if last pass isn't using encryption as secure as they claimed?

Shit, if that was a real concern you would have to be a complete idiot to use LastPass in the first place.

Only the encrypted randomized passwords were leaked. Unless you knowingly used a bad password for your cloud-based password manager, you're fine.

If you did use a bad password for the cloud based password manager, you're the walnut. The whole sales pitch is that lastpass can't fuck you as long as you have a reasonable password protecting your vault.

rather that introducing new remotely accessible attack surface to the kernel in 2022 when we know it's likely unsafe is silly.

This is the worst possible take on this.

Building an SMB server in the kernel because "well, NFS was secure eventually" overlooks the fact that NFS shouldn't be in the kernel either.

The way Linux works, NFS unfortunately has to be in the kernel to achieve reasonable performance.

I mean, various laws covering unauthorized access to computer systems seem like they would be directly applicable here.

https://www.cps.gov.uk/legal-guidance/computer-misuse-act

There must be knowledge that the intended access was unauthorised; and

Check? If not currently, Netflix could trivially ensure that this is the case by just adding a banner on the login page.

There must have been an intention to secure access to any program or data held in a computer.

Check.

What does that look like? Stolen parts will always be cheaper.

The warehouses full of people in Shenzhen tearing down millions and millions of stolen iDevices would still be chugging along, inserting stolen parts into the supply chain.

Apple enforcing DRM on parts is very much a pro-consumer move, steadily taking us towards a world where a stolen iPhone will be worth nothing.

Who the fuck are those people overdosing on crack cocaine, and how? This is literally one of the most difficult drugs to dangerously OD on.

You can't snort crack, you can't IV crack. You can only smoke crack, the onset is super fast and doesn't encourage you to rapidly redose. Dosage tends to be limited by your lung capacity.

Maybe with some very impressive lung capacity?

It's easy to overdose on Cocaine HCl using any of the popular RoAs. Insufflated, the onset is very slow, enabling you to take way too much before you actually start to feel the effects. Intravenously, your dosage is not limited by your lung capacity as it would be while smoking crack.

It sounds like banning an Uber account would qualify

In addition, processing can significantly affect an individual if it influences their personal circumstances, their behaviour or their choices (for example an automatic processing may lead to the refusal of an online credit application).