back

by Obscurity4340·3y ago·view on hn ↗
Lastpass needs to be kicked until its dead. You don't get do-overs with mistakes of this magnitude.

Their customers (if they are responsible) basically need to go through everything and setup a new password + maybe add 2FA (+ re-input all of this in a new platform). That could be for hundreds of accounts. Giant pain in the ass and they still have to worry about their vaults being out in the ether or sold on the Dark Web and hacked in some distributed way.

1 comments
There are definitely ways to export passwords from what I have read though I don't think there are convenient ways to import.

I use LastPass families with my wife so my rough plan is to:

1. Evaluate 1password, bitwarden, etc. for feature parity 2. Rotate highest value passwords like email, financial, critical things without MFA, etc. 3. Prune and unused junk 4. Export from LP and import into it's replacement 5. Cancel LP

I guess maybe 2 will come after 4 since I'd like to avoid adding any new PWs into LP.

I am not even that angry they got hacked but mostly angry about how they handled the encryption cycles of legacy users (5000 vs the current 100100) and that hackers were in their systems for many months and could exfiltrate customer vaults without them noticing.