In this video I discuss the recent security incident where LastPass got hacked and had their proprietary source code and company information stolen, I also discuss a better, safer alternative to LastPass called KeepassXC which gives you control over your passwords as well as how you can sync your keepass database with syncthing. LastPass blog post https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/ ₿💰💵💲Help Support the Channel by Donating Crypto💲💵💰₿ Monero 45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436 Bitcoin 3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV Ethereum 0xeA4DA3F9BAb091Eb86921CA6E41712438f4E5079 Litecoin MBfrxLJMuw26hbVi2MjCVDFkkExz8rYvUF Dash Xh9PXPEy5RoLJgFDGYCDjrbXdjshMaYerz Zcash t1aWtU5SBpxuUWBSwDKy4gTkT2T1ZwtFvrr Chainlink 0x0f7f21D267d2C9dbae17fd8c20012eFEA3678F14 Bitcoin Cash qz2st00dtu9e79zrq5wshsgaxsjw299n7c69th8ryp Etherum Classic 0xeA641e59913960f578ad39A6B4d02051A5556BfC USD Coin 0x0B045f743A693b225630862a3464B52fefE79FdB Subscribe to my YouTube channel http://goo.gl/9U10Wz and be sure to click that notification bell so you know when new videos are released.

First question right off the bat for anyone concerned: Lastpass claims that master passwords and encrypted user data was never compromised. See: https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/

Dhadelis
link
fedilink
29M

The same (and much worse) could happen to Bitwarden, at the end password manager services have highly valuable assets and malicious actors will try to attack them. When using a local password manager like KeePassXC, there’s not a single server storing thousands of passwords databases, just one stored locally and off-line in your computer, significantly reducing the risk.

Helix 🧬
link
fedilink
11
edit-2
9M

KeePassXC >> KeePass, IMHO

dreamLogic
link
fedilink
6
edit-2
9M

Again? This is at least two times now. I switched to Buttercup because they just use a file you upload to any cloud service (you can even set up your own webdav if you don’t want any company having that file).

Edit: Oh I see. This hack is worse, last time I heard it was leaked passwords and emails.

down daemon
link
fedilink
169M

Bitwarden is a good option

Dhadelis
link
fedilink
19M

Password manager services have highly valuable assets (thousands of passwords databases) and malicious actors will try to attack them. You’d be better using an off-line and local password manager like KeePassXC.

bkrl
link
fedilink
99M

Only offline a database is safe.

Just make sure you back it up to multiple places, and keep the backups up to date.

Helix 🧬
link
fedilink
49M

Yeah, that can easily be done by Syncthing. It’s basically online, but if you set up your own discovery server and disable relays for syncing, there’s virtually no way apart from completely breaking TLS to get the data.

Create a post

Confidentiality Integrity Availability

  • 1 user online
  • 1 user / day
  • 4 users / week
  • 9 users / month
  • 36 users / 6 months
  • 2 subscribers
  • 183 Posts
  • 182 Comments
  • Modlog