Lastpass was down today apparently.


Recommended Posts

Not understanding the complaints here.. There are always going to be issues that might cause a problem with access to online services outside the control of the company providing the services. Be it an isp issue for some users, be routing issues outside control of the company providing the services, be it DC issues where company provides services. From their blog post it sure seems like they are on top of the issue.

If you use the browser ext, it would not been an issue you would of just used your offline cache. If your not using browser ext then you clearly are not using the tool as designed, but you could always access your passwords with the use of their offline tool https://helpdesk.lastpass.com/lastpass-on-the-go-2/lastpass-pocket/

As to the debate of printing out passwords. While this might be useful in a company, old company we did it when we changed all the local admin accounts. But these passwords were never used, and I was really the only one that knew what they were changed too. They were locked in the safe at the facility that you even needed controlled access to even get to the safe, and then you needed the safe combo.

As to printing out your personal passwords and putting in safe at a bank, this clearly makes it a pain to change passwords and update your backup list. You might be better off just storing this backup hard copy at your location.

Is printing out passwords and leaving them on your desk a bad idea - sure!! But if your going to print out your passwords as part of a emergency DR or Backup I don't see a problem with it - as long as this hardcopy is stored securely with controls on who has access. The pain here is keeping this list updated when you change your passwords.

Is printing out passwords and leaving them on your desk a bad idea - sure!! But if your going to print out your passwords as part of a emergency DR or Backup I don't see a problem with it - as long as this hardcopy is stored securely with controls on who has access. The pain here is keeping this list updated when you change your passwords.

 

The_fonz_thumbs_up.jpg

Do yourself a favour and just use KeePass.

 

But. KeePass is horrible. almost as horrible as roboform... so... no.

So I'm guessing you do not regularly change any of your 350 passwords?  There's some good security.

 

Changing passwords frequently or even regularly does not inherrently make them safer or more secure. it's a fallacy. in fact regularly changing password are more likely to make them less secure. 

Changing passwords frequently or even regularly does not inherrently make them safer or more secure. it's a fallacy. in fact regularly changing password are more likely to make them less secure.

Agree 100% with this statement, the only time passwords to be honest need to be changed is if there is a chance they have been compromised. Person leaves or is no longer authed to access something that they might have passwords for, etc.

The one good reason to change passwords on a reg basis is if there is chance that over a period of time passwords are exchanged with people that shouldn't have them.. Let say for example a tech your working with is given a password, now normal controls should mean this password is then changed right after his access is no longer required. But this process may or may not happen. If that is the case then a reg change to the passwords could now remove that unauthed access.

Changing passwords say every 90 days for the sake of changing them agreed is a bit of fallacy, and forcing users to change their password every X days for no reason other than changing it doesn't buy you much security. If your worried about someone brute forcing the password then you should make it very frequent that the passwords need to be changed, etc. Better security would be lock out policies that require manual unlock by someone who will look into the reason for the lock out. Control on how many attempts per second, alerts on such attempts, etc. etc.

If the password is secure, and has controlled access to has it.. Say only YOU!! Then changing it on schedule can be more pain and could even be debated that the process could cause lost hours, lock outs, people writing them down be cause they can't remember it because they have to change it so often, etc.

Now in light of such things as a site you visit has been compromised, or things like heart bleed that come to light or hackers have a billion accounts, etc. It might be a good idea to not only change your passwords but re-evaluate the overall security of your passwords. If using a tool like lastpass they have a built in security scan that will list all your sites that have duplicate passwords, score on security of them, are you using multifactor, etc.

Since your not having to type these passwords with such a tool, make sure that all your passwords are using max length a site allows for - make sure your sites are not using duplicates, etc.

Every single time I had to change all the local passwords I would bitch about how it was a pointless waste of time - they are all 20 characters long, they are not even used (so no chance of leakage by someone watching them be typed in or exchanged with people who then leak them since they are locked in a safe and nobody knows them in the first place). You have to gain access to a controlled room to even use them since they are "local" you can not even use them across the network. But they had to be changed just the same for "audit" reasons..

Interestingly Lastpass being down exposes what Is pretty much a massive flaw in their multifactor setup in that if you permit offline login you can completely bypass multifactor authentication.

 

Expalin more, is it some sort of exploit?? I just tested, switched off router and couldn't login to lastpass (browser extension) without inserting my yubikey.

Changing passwords frequently or even regularly does not inherrently make them safer or more secure. it's a fallacy. in fact regularly changing password are more likely to make them less secure. 

 

Very true, too many people equate "frequent change" with "secure". Although, frequent password changes carry no risk in reduction of security if you're already using a password manager. It just becomes merely inconvenient for very little gain.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • My Photos app is version 2026.11050.1001.0 and it remembers the window size and position. My Snipping Tool is version 11.2602.49.0 and it can capture the taskbar.
    • MusicBee 3.6.9668 by Razvan Serea MusicBee is an application geared toward managing extensive music collections, easy to use and with a comprehensive feature set. It makes it easy to organize, find, and play music files on your computer, on portable devices, and on the Web. It provides playback of a wide range of audio formats, smart playlists with the ability to discover and play new music from the web, advanced tag editing with automated artwork and tag look up, folder monitoring, automated file re-organization, portable device synchronization, and secure CD ripping with AccurateRip verification. MusicBee features: Supported formats: MP3, AAC, M4A, MPC, OGG, FLAC, APE, TAK, WV, WMA and WAV. Audio CDs: Audio CD playback and ripping (with CD-Text capabilities) is supported. CD tracks can be ripped (in fast or secure mode) as individual files or as a single album with embedded cuesheet. Conversion: Conversion from and to all supported formats as metadata are preserved. Synchronization of tags only (in case that the output file already exists) instead of reencoding is possible. ReplayGain support: both playback and calculation. File Organization: Organization and renaming of music files into folders and files based on tag values such as artist, album, name, track number, etc. that can be specified. MusicBee can do this automatically for all files in a music library or the user can choose the files or folders themselves. Web Browsing: Browsing of the web using Mozilla's XULRunner environment. Scrobbling: Tracks played from MusicBee can optionally be scrobbled to Last.fm. Customizable user interface layout. Customizable keyboard shortcuts. MiniLyrics support Download: MusicBee 3.6.9668 | MusicBee Portable | ~9.0 MB (Freeware) Download: Windows Store Edition View: MusicBee Home page | Release Notes | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • On xiaomi hyperos there's also an option to disable google assistant. I've got everything disabled. Only thing I do have installed is a web wrapped for duck.ai which claims to let you use various AIs anonymously
    • I need to understand the rationale of not shipping all of these K2 improvements in a single update/release. It's giving "we will fix Windows 11 but no commitments". It seems to me that they just announce these improvements just to appease the community.
    • The term "RTM" is long gone starting with Windows 10. Every current release is a GA build. This is the result of MS making Windows as a Service (WaaS).
  • Recent Achievements

    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      520
    2. 2
      +Edouard
      185
    3. 3
      PsYcHoKiLLa
      87
    4. 4
      Michael Scrip
      81
    5. 5
      Steven P.
      73
  • Tell a friend

    Love Neowin? Tell a friend!