988
submitted 10 months ago by [email protected] to c/[email protected]

More than $35 million has been stolen from over 150 victims since December — ‘nearly every victim’ was a LastPass user::Security experts believe some of the LastPass password vaults stolen during a security breach last year have now been cracked open following a string of cryptocurrency heists

you are viewing a single comment's thread
view the rest of the comments
[-] [email protected] 96 points 10 months ago

Switched to bitwarden as soon as they tried to charge a sub for multiple devices, I see that was the right choice

[-] [email protected] 28 points 10 months ago* (last edited 10 months ago)

Are you not worried your vault is still on their servers? I feel most companies don’t delete shit. Most have ways to get around it saying they keep some info for taxes, accounting, etc.

I wouldn’t sleep well knowing my passwords were on there at any given time.

[-] [email protected] 23 points 10 months ago

You can host a bitwarden vault yourself. They open sourced and audited. So, trustworthy that there's no back door somewhere to some degree.

[-] [email protected] 21 points 10 months ago

I suspect they're referring to LastPass?

[-] [email protected] 3 points 10 months ago

Ah, make sense. I thought they asked about using Bitwarden's server.

[-] [email protected] 8 points 10 months ago

So just change whatever passwords you had saved to LastPass. That would mitigate any issues, right?

[-] [email protected] 3 points 10 months ago* (last edited 10 months ago)

Pretty much. Though also any security questions or other private info you have saved, some of which is much more annoying to protect.

Though one annoying thing is that even if you change everything, what they find might help them social engineer an attack.

I second Bitwarden, BTW. Best password manager I've used.

[-] [email protected] 1 points 10 months ago

Just. It’s not an insurmountable problem, but I wouldn’t be happy changing the login details, one by one, on the some 80 websites I have in my vault.

Not to mention if you’re using an email anonymizer, you’ll have to regenerate new emails for them all too. I guess you could do it on demand, but knowing my batch of emails in floating around the dark web doesn’t sit well with me. Worse yet if it’s your actual email, then they have that now.

[-] [email protected] 1 points 10 months ago

Your username gives me PTSD for past Hades speedruns and I hate it.

[-] [email protected] 1 points 10 months ago

It's e2e and the code to do so is opensource, and you can always host Vaultwarden yourself.

[-] [email protected] 11 points 10 months ago

same here. nuked my lastpass account and switched everything over to bitwarden. their paid offering was worse from the competition and now i’m very glad i moved from them

[-] [email protected] 2 points 10 months ago

Was it a huge pain in the ass moving over or fairly painless? I need to do this.

[-] [email protected] 1 points 10 months ago

Not painless at all. IIRC, I just exported from LastPass and imported (without change) to BitWarden. It worked fine.

this post was submitted on 07 Sep 2023
988 points (99.0% liked)

Technology

55744 readers
3701 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS