home.social

#breech — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #breech, aggregated by home.social.

  1. Fool me once, shame on you.
    Fool me twice, shame on me.

    I only know of two customers of mine that were stupid enough not to abandon #LastPass after the last debacle. And then to add insult to injury they made everyone with multiple devices "upgrade" to their non-free tier.

    What's the point (there isn't one) of having a cloud based vault if it doesn't sync between your devices? You can just back up your vault onto a 5¼" floppy and store it in a drawer or safe deposit box, right?

    Well, I told everyone to switch to #kdbx or #VaultWarden a very long time ago.

    But what's wrong with BitWarden?

    I personally sync using my own private cloud resources and a couole of other options as well. I use kdbx - in particular, that means #KeePassXC and #KeePassDX. Only I know where those so-called "vaults" are. Even though a kdbx file is relatively secure, this keeps the attack surface as small as possible.

    And that's what's wrong with #BitWarden, and a big reason why LastPass got #whacked - because the bad people already know where everyone's most sensitive shit is kept.

    With VaultWarden, which is what I recommend for most folks, only you know where you keep your password stores. Even with a public provider of VaultWarden there's a bunch of them, ask over the place; so the evil-doers, even if successful, will have a much harder time for less of a reward - they gained access to EVERYONE'S LastPass #vaults!

    Because they're all kept in one, single, well known place.

    As Colonel Walter Kutz lay dying in the mud, his only utterance was, "Oh, the horror!"

    The best part about a #KeePass (kdbx) or VaultWarden solution? They're 100% #FOSS!

    https://thehackernews.com/2023/01/mitigate-lastpass-attack-surface-in.html?m=1

    https://www.pcmag.com/news/lastpass-faces-class-action-lawsuit-over-password-vault-breach

    https://cointelegraph.com/news/lastpass-data-breach-led-to-53k-in-bitcoin-stolen-lawsuit-alleges

    #tallship #passwords #Privacy #security #breech

    .