Bottom text
The article doesn't say anything about a torrent, OP is a faggot All lastpass credentials available as a torrent
https://www.cnet.com/tech/services-and-software/lastpass-customers-need-to-change-all-of-their-passwords
- 85
- 131
Now playing: Gang-Plank Galleon remix (DKC).mp3
Jump in the discussion.
No email address required.
The article doesn't say anything about a torrent. AFAIK the database was stolen but it wasn't published by the hackers, which is why haveibeenpwned.com doesn't have it.
Jump in the discussion.
No email address required.
Here is the source for my torrent claim
https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/j7vvd0v/
Also, it associates website usernames with your email and if you have an email or username that associates to your real identity it can be used to purge you for wrongthink
Jump in the discussion.
No email address required.
Kiwifarms gets a new source to point and laugh
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
Subscribe to me for more bangers
Supreme Court Denies Kazhar Supremacy 9-0
Indiana to placate the yellow menace
Bardfinn presents the "Hogwarts express" trolley problem
r/frickbicycles gets some tread
they got us bros
Rethuglicans literally murder first transgender transracial congresswoman
School district under fire after photos surface of sixth-graders practicing pole dancing
Jump in the discussion.
No email address required.
hmm...
Jump in the discussion.
No email address required.
Its getting engagement tho. Also this one was a psa
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
"All lastpass credentials available as a torrent?"
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
Finally someome said it
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Jump in the discussion.
No email address required.
Self-promotion is acceptable on
HNSN. We're all tech-dude startup founders here.Jump in the discussion.
No email address required.
More options
Context
More options
Context
BARD BOT ALERT! Reset the counter! Current counter was: 0 days 00 hours 16 minutes and 59 seconds
Record is 1 days 03 hours 34 minutes and 29 seconds by Shreddedmanlet
longest streak broken in the last 7 days was aminobastard which was 0 days 15 hours 03 minutes and 21 seconds
Best friend is ACA with 83 mentions
rdrama is currently running at 177.855 µBardyhertz with 2343 total mentions since 2022-09-24
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Today I will give a startup company all of my passwords so they can store them on the cloud
Jump in the discussion.
No email address required.
The company my girlfriend works for uses LastPass. They're all women there.
I'm sure they won't even be bothered by this breach.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
lmao this is why i use a local keepass db for my passwords
imagine giving a website your credentials to everything
Jump in the discussion.
No email address required.
I keep my passwords on a piece of paper stashed in my apartment.
It's been the foolproof solution since forever.
Jump in the discussion.
No email address required.
I just forget my passwords and reset them everytime I need to login.
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
More options
Context
Some websites actually force you to do that, 2FA via e-mail every single fricking time. I fricking hate it.
Jump in the discussion.
No email address required.
you could use other websites duh
Jump in the discussion.
No email address required.
More options
Context
More options
Context
reset the password for one account over 8x in the past 3 months cause i never use it. didn’t save the most recent one
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Same I just have a physical list hidden in my home, I definitely trust it more than having it in a file on my windows, even encrypted
On the other hand, if a fire or something breaks out in my home I'm absolutely fricked
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
All my passwords, encrypted, on a flash drive, in my rectum, next to my precious poop
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Jump in the discussion.
No email address required.
This is exactly what my favorite schizo professor does. He worked for the NSA for over a decade. Physical, handled properly, is still safer than anything connected to the internet. No encryption schemes guarantees perpetual security, besides OTPs I suppose.
Jump in the discussion.
No email address required.
The only disadvantage a local password database has compared to a physical list is that it can be digitally copied. I have a 16 random character password for my local Keypass database that would take thousands of years to brute force.
Jump in the discussion.
No email address required.
That's the same thing I do, but it's still technically more vulnerable
Jump in the discussion.
No email address required.
A physical list is completely exposed IRL, assuming you're not using a cypher. If someone is really worried about glowies then they should consider how trivial it is for them to slip in and out of a house or office without notice. That's like one of the oldest tricks in the glowie book.
Jump in the discussion.
No email address required.
I think he keeps it on him at all times. I guess the logic there is that it's impossible to be stolen without you knowing. He's an interesting character.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
16 characters? A bit short. How many of them are letters and at which positions? And which letters specifically? This is very important.
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
And then because you never ever type that password in to your computer, your database is totally safe.
Right?
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
Don't give me that. It's easier to tell if someone broke into your home than it is if you've been hacked. And let's not pretend like microsoft themselves aren't able to copy your keys and store them for themselves
Jump in the discussion.
No email address required.
If you've been hacked then your passwords are already compromised when you enter them from your physical list. Brute forcing a Keypass database with a 16 random character password would take tens of thousands of years and Keypass has built-in measures against keylogging.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
Put a copy in a safety deposit box or something and keep it at a bank?
Jump in the discussion.
No email address required.
zoz
Jump in the discussion.
No email address required.
zle
Jump in the discussion.
No email address required.
zozzle
Jump in the discussion.
No email address required.
Zozbot approved method
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context
But it isn’t your password is it, it’s a hint to your password and you forgot it one time until one day drinking it popped into your head the hint you left on the paper and the extra mark has nothing to do with the password hint is huh
Jump in the discussion.
No email address required.
More options
Context
Hackercels btfo
Jump in the discussion.
No email address required.
More options
Context
Same my negro
Jump in the discussion.
No email address required.
More options
Context
i’d do that but i have a fear of my house burning down and burning all my passwords so then i can’t log into any of my accounts
Jump in the discussion.
No email address required.
More options
Context
More options
Context
I have an irl notepad with all my passwords on it. Some butt would have to break into my fricking house to steal them.
Jump in the discussion.
No email address required.
More options
Context
google knows everything about me, so i let them keep my passwords too.
Jump in the discussion.
No email address required.
Google actually stores your passwords in an sqlite database in the Chrome folder alongside your session cookies. And actually this can be decrypted pretty fairly easily just based on what's on your computer
Jump in the discussion.
No email address required.
WELL IF THEY HAVE ACCESS TOO MY COMPUTER TOO DECRYPT THEY CAN PROBABLY ALSO GET A KEYLOGGER OR WHATEVER. AND AT THAT POINT PASSWORD MANAGERS ARE MOOT.
trans lives matter
Jump in the discussion.
No email address required.
I can add it to certain browser extensions without notification to the user. It dosent give me the whole box but it does allow session jacking and passwords
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Hi @dart200,
Your comment has been automatically removed because you forgot to include
trans lives matter
.Don't worry, we're here to help! We won't let you post or comment anything that doesn't express your love and acceptance towards the trans community. Feel free to resubmit your comment with
trans lives matter
included.This is an automated message; if you need help, you can message us here.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
More options
Context
The thing everyone predicted would happen happened?
Jump in the discussion.
No email address required.
More options
Context
Encrypted passwords
Jump in the discussion.
No email address required.
So, pretty much the same deal if you don't use a password vault. The only thing they have is your username.
I guess it's kind of fricked because if they crack it they have access to the rest of your accounts in one place.
Jump in the discussion.
No email address required.
Hunter2cels on suicide watch
@Aevann Hunter2 should be added to the word filter, turn it to asterisks
Jump in the discussion.
No email address required.
Should be fixed now: *******
Jump in the discussion.
No email address required.
More options
Context
done king
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
One password vs all my passwords is quite a difference.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Lastpass: "Since 2018, we have required a twelve-character minimum for master passwords. This greatly minimizes the ability for successful brute force password guessing."
Nerd: "If you are a LastPass customer, chances are that you are completely unaware of this requirement. That’s because LastPass didn’t ask existing customers to change their master password. I had my test account since 2018, and even today I can log in with my eight-character password without any warnings or prompts to change it."
Lastpass: "To further increase the security of your master password, LastPass utilizes a stronger-than-typical implementation of 100,100 iterations of the Password-Based Key Derivation Function (PBKDF2),"
Nerd: ""OWASP currently recommends 310,000 iterations. LastPass hasn’t increased their default since 2018 [...] In 2018 LastPass increased the default from 5,000 iterations to 100,100. But what happened to the existing accounts? Some have been apparently upgraded, while other people report still having 5,000 iterations configured."
Nerd raging when the leak happened.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Jump in the discussion.
No email address required.
bitwarden sisters... we're winning
Jump in the discussion.
No email address required.
More options
Context
hmm
Jump in the discussion.
No email address required.
More options
Context
More options
Context
if you have a good master password it's fine
Jump in the discussion.
No email address required.
More options
Context
Unironically useful for me as I had a lot of old accounts which LastPass which I couldn’t log in to due to a fricky situation, thanks!
Jump in the discussion.
No email address required.
More options
Context
@Aevann maybe this one gets a pin?
Jump in the discussion.
No email address required.
buy your own pin
Jump in the discussion.
No email address required.
sounds like capitalism
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
I just store my passwords on a notepad document. Never had a password breach yet, cry about it incels :)
Jump in the discussion.
No email address required.
More options
Context
does anyone have the torrent
Jump in the discussion.
No email address required.
Why? Did you forget your passwords?
Jump in the discussion.
No email address required.
yes maybe you could give me your password to help me feel better about it?
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
Should be good for new wordlists
Jump in the discussion.
No email address required.
More options
Context
Apparently the URLs were unencrypted. This means that if you had accounts on some naughty websites (e.g. KiwiFarms) there is now a link between your LastPass email and those websites (even if the exact username is not known)
Jump in the discussion.
No email address required.
More options
Context
Meltdown on /r/lastpass: https://old.reddit.com/r/Lastpass/comments/10ve9qb/why_didnt_lastpass_alert_users_from_within_our/
Jump in the discussion.
No email address required.
More options
Context
God darn the r-slurs that use their amateur radio callsign as their username are absolutely fricked. Since the fcc makes your name, address, phone number and email associated with your callsign public, the scammer’s job is practically done for them
Jump in the discussion.
No email address required.
More options
Context
wtf i love bitwarden now
Jump in the discussion.
No email address required.
More options
Context
Hahahahahahahahha
Jump in the discussion.
No email address required.
More options
Context
@Aevann
Here is the source for my torrent claim
https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/j7vvd0v/
Jump in the discussion.
No email address required.
More options
Context
Nice post, bro! I posted it to twitter.
Jump in the discussion.
No email address required.
More options
Context
I'm not used to such hate being directed at me and that made me cry
Snapshots:
archive.org
ghostarchive.org
archive.ph (click to archive)
Jump in the discussion.
No email address required.
More options
Context
Jump in the discussion.
No email address required.
More options
Context
hmm
Jump in the discussion.
No email address required.
More options
Context