Which password manager do you use?

Here’s LastPass’ info: About Password Iterations - LastPass Support

It’s not entirely correct, though. While their current default may be 100,100 iterations, mine was still set at the old 5000 level because I didn’t hear/know about the need to change it back when it was discussed (as mentioned earlier by @stusser ).

Here’s some extra detail: PBKDF2 - Wikipedia

I increased my personal one from 5000 to the better 310,000 now recommended. But yeah, I didn’t even know this was a thing, being that cryptography isn’t my wheelhouse.

I mean, my passwords alone are usually long enough and random enough that dictionary attacks aren’t going to work, but if they can decrypt my vault, which they now have unlimited time to do, and view the passwords, well, that’d be a problem. I don’t think it’s likely in my case, but I changed many of my passwords as a precaution, and I’ll keep changing them until they’re all done.

Hopefully 2023 will be the year companies start adopting passkeys and we can do away with passwords forever.

Just went through all my passwords, and a good couple dozen are for websites that don’t even exist anymore. Gotta do better about cleaning those up I guess.

I must have had hundreds of passwords in LastPass and I just went through them all and changed the ones that were for things that still exists. It must have taken me 11 hours. I deleted that account.

I hope I can trust Google to keep my passwords safe.

I’ve been trying to migrate to 1Password for the past 7 days. The number of issues I’ve had, their support is 2-3 days to respond, their instructions online suck balls and I have grown so frustrated. I don’t understand how a company can try to “pare down” instructions to the point where it’s just not obvious.

I’m at a point where I need to decide to just fucking bail and go and try bitwarden.

My god if 1Password had a decent UX person to review their shit, they wouldn’t be receiving my ire.

I know I’m getting off Lastpass and I thought 1Password would be a good choice but my god they make me hate them with the burning passion of a thousand suns.

What kinds of issues have you had? Issues importing a Lastpass export? Have you seen this page? (Last posted in this thread by mono in 2016, according to Discourse!)

I remember all kinds of steps from way back them, which I believe included community created conversion utilities, and multiple intermediary steps between the export and import. It’s much simpler these days.

I’m currently on 1Password, but have moved between Lastpass/Bitwarden and 1Password a number of times over the years. Never ran into anything too daunting. However if you’ve already made the move to Bitwarden, I’d stick w/ that @Tman . My only issue w/ Bitwarden is that the Android app (with my 2800 item vault) is a bit sluggish compared to the other products. Works fine on my vault w/ iOS devices.

The slow trickle of revelations continues.

https://www.goto.com/blog/our-response-to-a-recent-security-incident

Lastpass passwords are encrypted not hashed, so they must be talking about Logmein or other products there.

Stories like this kill me.

I don’t know why anyone would stay on LastPass once they’re aware of these stories.

“Their lack of opsec is SO relatable!”

Just a note for those of you who only read the headllines, they got into the Developer’s home PC b/c they hacked PLEX and installed a keylogger.

So there’s a risk if you’re running PLEX. No word from them on if they were recently compromised (they were hacked in Aug 2022 and 30 million accounts were compromised).

To be fair, it’s all related information about the 2022 breach. That being said I did cancel my subscription and moved to Bitwarden it was so easy.

As a DevOps related person trying to advocate working from home this is not going to help my case.

As someone who runs a Plex server at home, I hope they release more details about how this hack was accomplished.

Probably a zero day.

I run Plex in a container in an untrusted VLAN to segregate it. Everybody should either do that or even better, a VM.

The thing where LastPass didn’t encrypt the actual URLs is insane. It’s so easy to ID anyone who had a personal web site in their own name.

Posted this in the other thread. But if anyone is still using LastPass a new security bulletin just dropped

Oh wow, they got the 2FA seeds. That’s extremely bad.

Not if you don’t have TFA turned on! </taps head>