91
Lounge / Re: What's on your mind?
« Last post by splerdu on September 09, 2023, 03:55:55 PM »LastPass, the gift that keeps on giving:
https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/
Password managers are teh suck. Why trust someone else with your security and not just use a GPG-encrypted text file and your own storage (local or cloud based) of choice? That way you can be secure in the knowledge that it's being sent securely (since you encrypt it yourself before uploading/updating), and that the app can't just get hijacked and updated to an insecure state in case the developer loses his keys or something.
https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/
Quote
Since late December 2022, Monahan and other researchers have identified a highly reliable set of clues that they say connect recent thefts targeting more than 150 people, Collectively, these individuals have been robbed of more than $35 million worth of crypto.
Monahan said virtually all of the victims she has assisted were longtime cryptocurrency investors, and security-minded individuals. Importantly, none appeared to have suffered the sorts of attacks that typically preface a high-dollar crypto heist, such as the compromise of one’s email and/or mobile phone accounts.
“The victim profile remains the most striking thing,” Monahan wrote. “They truly all are reasonably secure. They are also deeply integrated into this ecosystem, [including] employees of reputable crypto orgs, VCs [venture capitalists], people who built DeFi protocols, deploy contracts, run full nodes.”
Password managers are teh suck. Why trust someone else with your security and not just use a GPG-encrypted text file and your own storage (local or cloud based) of choice? That way you can be secure in the knowledge that it's being sent securely (since you encrypt it yourself before uploading/updating), and that the app can't just get hijacked and updated to an insecure state in case the developer loses his keys or something.