Hacker News new | past | comments | ask | show | jobs | submit login

If you had your recovery keys stored in a note on lastpass you might have wanted to rotate those as well recently.

Yeah, in theory those recovery keys should still be secure, but you know for certain that a hostile attacker has the encrypted secure note, and without any confidence in lastpass it makes sense to change them as well.

Unfortunately this means you look exactly like someone doing an account takeover and changing the password and recovery keys on the account.




Thanks for the heads up.

I don't use lastpass, but if I did I wouldn't have to because this "Just to be safe" process also reset/removed the recovery keys.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: