Hacker News new | past | comments | ask | show | jobs | submit login

What proof do you have that last pass uses that encryption scheme? Is there any evidence to suggest that it meets rigorous standards?

Remember that last pass has just been caught lying about their security, and you can't trust what they say.

Calling other people idiots just makes you look like an uninformed asshole, so stop that. You're wrong, and you're trying to justify yourself rather than just back down.

Changing passwords in the face of a breach like this is standard practice and is the only logical step forward. You cannot trust last pass security from this point forward. Whether or not you should have trusted them in the first place is irrelevant in the extreme.

Last pass users should change their passwords, period. Telling those users that they're idiots who shouldn't have trusted them to begin with makes you look foolish and toxic.

Do better.




>Remember that last pass has just been caught lying about their security, and you can't trust what they say.

I'm curious, what were they caught lying about?

>What proof do you have that last pass uses that encryption scheme? Is there any evidence to suggest that it meets rigorous standards?

LastPass has been extensively reverse engineered. There are, for example, public Defcon talks about it.

>Changing passwords in the face of a breach like this is standard practice and is the only logical step forward.

This is not logical at all.

>You cannot trust last pass security from this point forward.

Why not? Because they disclosed a breach?




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: