Ramblings of an old Doc

 

Thanks for the ‘heads up!’, Hankers.

 

Because many in the Community have expressed interest in and use LastPass to keep and secure their passwords, this is a quick ‘heads up!’ to everyone.

Martin Brinkmann, a journalist and owner of ghacks.net  (an extremely reputable German IT Security News Site) published an article about a self reported  “anomaly” at LastPass.

This is important as it is being treated by LastPass as a possible breach and reported as such.

I very much agree with Mr. Brinkmann that this is responsible behavior, especially when compared to the ‘cover up’ behavior we’ve all seen from other large corporations whose “personal reputation” interests superceded their concern for their customers’ security.

You can read more at Mr. Brinkmann’s site:

http://www.ghacks.net/2011/05/05/lastpass-security-breach/

and at Lastpass:

http://blog.lastpass.com/2011/05/lastpass-security-notification.html

================================================================================================

 Update:

Lifehacker has a nice article about "non-Cloud" alternatives to LastPass:

http://lifehacker.com/5799036/the-best-password-utilities-that-dont-store-your-data-in-the-cloud

 


Comments (Page 1)
2 Pages1 2 
on May 05, 2011

I think it's never a good idea to save passwords online.

I use the app KeePass, it's pretty easy to use and it's save.

on May 05, 2011

Seems I wrote about this before. I never trusted this method.

on May 05, 2011

Thanks for the tip.  Master password changed.

on May 05, 2011

My password is 27 characters long, they would be hard pressed to brute force it. Still it's better safe than sorry.

Thanks, Doc and Hankers.

on May 05, 2011

How ironic, I decided to be cautious about this and change and back up my passwords on lastpass. Imagine my luck that not only does Firefox and the lastpass extension fail to change my password but also failed to backup my passwords and I have now lost everything I had on the site. Lucky for me I tend to have more than one backup thru different methods and so I still have my websites and passwords although there is a chance a couple may not be updated but that should not be a problem. As of this moment I will no longer use Lastpass as I am very disappointed how difficult it was to export a backup and even harder to import it.

I will now try keepass instead. Thanks for the tip.

on May 05, 2011

Good call, thanks.

I only registered a couple of days ago, which makes me question my decision. Need to look into KeePass then.

 

On a side note, someone in this thread, I'm not naming any names, stole my self-stolen avatar. Is there no honor among thieves these days?

I'm red with rage!

on May 05, 2011

RedOrbs
On a side note, someone in this thread, I'm not naming any names, stole my self-stolen avatar. Is there no honor among thieves these days?

 ....up the irons, mate!

on May 05, 2011

How do you change your master password? I can't seem to find the option.

-Side note, I'm not too worried because I only manage passwords to sites I don't care about with lastpass.

on May 05, 2011

I use to work for the State Dept of Ed.  One of the Asst. Superintendents was probably brilliant in his field, but lacked any technical sense.  So if we had to work on his computer, we merely looked at the side of his monitor where his password was written down (along with his login ID).

He may have had a more secure method than any online method used today.

on May 05, 2011

G3mpi3
How do you change your master password? I can't seem to find the option.

-Side note, I'm not too worried because I only manage passwords to sites I don't care about with lastpass.

http://lastpass.com/support.php?cmd=showfaq&id=375



on May 05, 2011

I store my passwords in MY memory, it's harder to hack

on May 05, 2011

Wait a minute. If they steal my identity do they also get my degenerative back pain as well? And my mom-in-law who I love SO VERY MUCH that has been living in my recliner since Christmas? And ALL the f*cking issues that come with having Skinhit as my arch-nemesis???????? There is potential for something good to come out of this, right?

on May 05, 2011

PoSmedley
Wait a minute. If they steal my identity do they also get my degenerative back pain as well? And my mom-in-law who I love SO VERY MUCH that has been living in my recliner since Christmas? And ALL the f*cking issues that come with having Skinhit as my arch-nemesis???????? There is potential for something good to come out of this, right?
 

For anyone else, I'd say probably.

Not for you, Smedley.   

*where's that third finger 'smiley' when I need it?  [e digicons]:karma:[/e]

on May 05, 2011

DrJBHL
For anyone else, I'd say probably.

Not for you, Smedley.

You're just jealous cause no one WANTS to steal YOUR identity.  I, on the other hand, am just that fucking awesome.

on May 05, 2011

Lifehacker has came up with

'alternative password solution that doesn't store your passwords on someone else's servers'.

If anyone would like to have a look, http://lifehacker.com/5799036/the-best-password-utilities-that-dont-store-your-data-in-the-cloud

2 Pages1 2