Jump in the discussion.

No email address required.

>All lastpass credentials available as a torrent

The article doesn't say anything about a torrent. AFAIK the database was stolen but it wasn't published by the hackers, which is why haveibeenpwned.com doesn't have it.

Jump in the discussion.

No email address required.

Here is the source for my torrent claim

https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/j7vvd0v/?sort=controversial

Also, it associates website usernames with your email and if you have an email or username that associates to your real identity it can be used to purge you for wrongthink

Jump in the discussion.

No email address required.

Kiwifarms gets a new source to point and laugh

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

bangers


thread that's nothing but a link

hmm...

Jump in the discussion.

No email address required.

Its getting engagement tho. Also this one was a psa

Jump in the discussion.

No email address required.

>i was just trying to start a conversation

Jump in the discussion.

No email address required.

"All lastpass credentials available as a torrent?"

Jump in the discussion.

No email address required.

Finally someome said it

Jump in the discussion.

No email address required.

:marseyropeyourself2#:

Jump in the discussion.

No email address required.

Self-promotion is acceptable on HN SN. We're all tech-dude startup founders here.

Jump in the discussion.

No email address required.

:siren:BARD BOT ALERT!:siren: Reset the counter! Current counter was: 0 days 00 hours 16 minutes and 59 seconds

Record is 1 days 03 hours 34 minutes and 29 seconds by Shreddedmanlet

longest streak broken in the last 7 days was aminobastard which was 0 days 15 hours 03 minutes and 21 seconds

███████████████████████████████████ 70 02-03
██████████████████████████           51 02-04
███                                 6  02-05
███████████                         22 02-06
█████████                            17 02-07
██████████                           19 02-08
█████                               10 02-09

Best friend is ACA with 83 mentions

rdrama is currently running at 177.855 µBardyhertz with 2343 total mentions since 2022-09-24

Jump in the discussion.

No email address required.

Today I will give a startup company all of my passwords so they can store them on the cloud

:#marseyclueless:

Jump in the discussion.

No email address required.

lmao this is why i use a local keepass db for my passwords

imagine giving a website your credentials to everything

Jump in the discussion.

No email address required.

I keep my passwords on a piece of paper stashed in my apartment.

It's been the foolproof solution since forever.

Jump in the discussion.

No email address required.

I just forget my passwords and reset them everytime I need to login.

Jump in the discussion.

No email address required.

:sigmatalking#:

Jump in the discussion.

No email address required.

Some websites actually force you to do that, 2FA via e-mail every single fricking time. I fricking hate it.

Jump in the discussion.

No email address required.

you could use other websites duh

Jump in the discussion.

No email address required.

reset the password for one account over 8x in the past 3 months cause i never use it. didn’t save the most recent one

Jump in the discussion.

No email address required.

Same I just have a physical list hidden in my home, I definitely trust it more than having it in a file on my windows, even encrypted

On the other hand, if a fire or something breaks out in my home I'm absolutely fricked

Jump in the discussion.

No email address required.

>he doesn't have remote disaster recovery facilities set up at across five continents and on the ISS

Jump in the discussion.

No email address required.

All my passwords, encrypted, on a flash drive, in my rectum, next to my precious poop


Don't forget to turn off signatures in settings!

Jump in the discussion.

No email address required.

I definitely trust it more than having it in a file on my windows, even encrypted

:#marseygigaretard:

Jump in the discussion.

No email address required.

This is exactly what my favorite schizo professor does. He worked for the NSA for over a decade. Physical, handled properly, is still safer than anything connected to the internet. No encryption schemes guarantees perpetual security, besides OTPs I suppose.

Jump in the discussion.

No email address required.

The only disadvantage a local password database has compared to a physical list is that it can be digitally copied. I have a 16 random character password for my local Keypass database that would take thousands of years to brute force.

Jump in the discussion.

No email address required.

That's the same thing I do, but it's still technically more vulnerable

Jump in the discussion.

No email address required.

A physical list is completely exposed IRL, assuming you're not using a cypher. If someone is really worried about glowies then they should consider how trivial it is for them to slip in and out of a house or office without notice. That's like one of the oldest tricks in the glowie book.

Jump in the discussion.

No email address required.

I think he keeps it on him at all times. I guess the logic there is that it's impossible to be stolen without you knowing. He's an interesting character.

Jump in the discussion.

No email address required.

More comments

16 characters? A bit short. How many of them are letters and at which positions? And which letters specifically? This is very important.

Jump in the discussion.

No email address required.

:#marseythonk:

Jump in the discussion.

No email address required.

And then because you never ever type that password in to your computer, your database is totally safe.

Right?

Jump in the discussion.

No email address required.

Don't give me that. It's easier to tell if someone broke into your home than it is if you've been hacked. And let's not pretend like microsoft themselves aren't able to copy your keys and store them for themselves

Jump in the discussion.

No email address required.

If you've been hacked then your passwords are already compromised when you enter them from your physical list. Brute forcing a Keypass database with a 16 random character password would take tens of thousands of years and Keypass has built-in measures against keylogging.

Jump in the discussion.

No email address required.

Put a copy in a safety deposit box or something and keep it at a bank?

Jump in the discussion.

No email address required.

zoz

Jump in the discussion.

No email address required.

zle

Jump in the discussion.

No email address required.

zozzle

Jump in the discussion.

No email address required.

Zozbot approved method

Jump in the discussion.

No email address required.

But it isn’t your password is it, it’s a hint to your password and you forgot it one time until one day drinking it popped into your head the hint you left on the paper and the extra mark has nothing to do with the password hint is huh

Jump in the discussion.

No email address required.

>not using facial recognition but training it to recognize your peepee

Hackercels btfo

Jump in the discussion.

No email address required.

Same my negro

Jump in the discussion.

No email address required.

i’d do that but i have a fear of my house burning down and burning all my passwords so then i can’t log into any of my accounts

Jump in the discussion.

No email address required.

I have an irl notepad with all my passwords on it. Some butt would have to break into my fricking house to steal them.

Jump in the discussion.

No email address required.

google knows everything about me, so i let them keep my passwords too. :marseychimera:

Jump in the discussion.

No email address required.

Google actually stores your passwords in an sqlite database in the Chrome folder alongside your session cookies. And actually this can be decrypted pretty fairly easily just based on what's on your computer

Jump in the discussion.

No email address required.

WELL IF THEY HAVE ACCESS TOO MY COMPUTER TOO DECRYPT THEY CAN PROBABLY ALSO GET A KEYLOGGER OR WHATEVER. AND AT THAT POINT PASSWORD MANAGERS ARE MOOT.

trans lives matter

Jump in the discussion.

No email address required.

I can add it to certain browser extensions without notification to the user. It dosent give me the whole box but it does allow session jacking and passwords

Jump in the discussion.

No email address required.

The thing everyone predicted would happen happened? :marseyshook:


https://i.rdrama.net/images/17092367509484937.webp https://i.rdrama.net/images/17093267613293715.webp https://i.rdrama.net/images/1711210096745272.webp

Jump in the discussion.

No email address required.

Encrypted passwords

:#marseysleep:

Jump in the discussion.

No email address required.

:#@bitwardenshillpat:

Jump in the discussion.

No email address required.

bitwarden sisters... we're winning

Jump in the discussion.

No email address required.

hmm

Jump in the discussion.

No email address required.

if you have a good master password it's fine

:marseysleep:

Jump in the discussion.

No email address required.

:#marseyjam:

Unironically useful for me as I had a lot of old accounts which LastPass which I couldn’t log in to due to a fricky situation, thanks!

Jump in the discussion.

No email address required.

@Aevann maybe this one gets a pin?

Jump in the discussion.

No email address required.

buy your own pin

Jump in the discussion.

No email address required.

sounds like capitalism

Jump in the discussion.

No email address required.

I just store my passwords on a notepad document. Never had a password breach yet, cry about it incels :)

Jump in the discussion.

No email address required.

does anyone have the torrent

Jump in the discussion.

No email address required.

Why? Did you forget your passwords?

Jump in the discussion.

No email address required.

yes :marseysadge: maybe you could give me your password to help me feel better about it?

Jump in the discussion.

No email address required.

Should be good for new wordlists :marseyill:

Jump in the discussion.

No email address required.

Apparently the URLs were unencrypted. This means that if you had accounts on some naughty websites (e.g. KiwiFarms) there is now a link between your LastPass email and those websites (even if the exact username is not known)

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

God darn the r-slurs that use their amateur radio callsign as their username are absolutely fricked. Since the fcc makes your name, address, phone number and email associated with your callsign public, the scammer’s job is practically done for them

Jump in the discussion.

No email address required.

wtf i love bitwarden now

Jump in the discussion.

No email address required.

Hahahahahahahahha

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

Nice post, bro! I posted it to twitter.

All lastpass credentials available as a torrent https://rdrama.net/h/slackernews/post/146151/all-lastpass-credentials-available-as-a #SpeakerOfTheUnitedStatesHouseOfRepresentatives #towards #idk

Jump in the discussion.

No email address required.

Reported by:
  • whyareyou : its not ur fault tthis time snaps

I'm not used to such hate being directed at me and that made me cry

Snapshots:

Jump in the discussion.

No email address required.

:#marseywholesome:

Jump in the discussion.

No email address required.

hmm

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.