Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Securopean

@securopean@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes.

Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.

307 Followers
595 Following
9 Posts
Joined November 05, 2022
Open post
Securopean @securopean@infosec.exchange
· 46mo ago
  1. Any incident is stressful, and at this time of year is even worse. I feel really really bad for everyone involved.
  2. Relying on users to pick a strong master password is not realistic. The #1Password approach appears to make more sense - force a secure default in the face of determined attackers who may ultimately succeed.
  3. I suspect for many users the "notes" fields are more sensitive than their passwords. Passwords can be changed.
  4. #LastPass will hopefully reflect on what design decisions drove them not to encrypt URLs, and if they have made any similar risk trade-offs elsewhere.
  5. Attribution (if possible) matters here for all of our threat models.
  6. I've seen little discussion of how the breach occurred, although the movement from dev environment->cloud backup is telling. The entire IT industry has walked itself into a cloud security nightmare, with easy-to-make mistakes or compromises having potentially severe consequences for many companies.
  7. #Bitwarden appears marginally better than LP, but I'm not seeing anything fundamentally better? (see 2). More like out of the frying pan into a small pot.
  8. I spent some time mucking around with Bitwarden self-hosted. Some of the guides to self-hosting I read were downright dangerous, and certificates were a problem. I'm unconvinced it's a realistic answer for all but a small few.

#infosec

infosec.exchange

Infosec Exchange

78
20
38
0
Open post
Securopean @securopean@infosec.exchange
· 5mo ago
Replying to
@GossiTheDog PE execs are reading about this stuff, asking their Board Chairs to ask their CEOs about it, those CEOs are talking to other CEOs, it all kind of snowballs from there. It's annoying, but I also find it an opportunity to ask for the stuff I've been wanting to get addressed for years. "If we don't fix the legacy piece of shit that's hanging out on the Internet, Mythos might definitely get us (not mentioning the hundred other current threat actors).".
1
0
0
0
Open post
Securopean @securopean@infosec.exchange
· 35mo ago
Replying to
@parismarx The EU is putting together some good legislation on this in the AI Act - along the lines of GDPR, so you can't be subject to arbitrary automated decision making.
2
0
2
0
Open post
Securopean @securopean@infosec.exchange
· 46mo ago
Replying to
@ghost0x0@mastodon.online Absolutely, same here, and I'll be quizzed on this over Christmas. I'm currently (strongly) leaning towards the 1Password model when family ask me, but I don't know enough about the product yet to recommend it.
3
4
0
0
Open post
Securopean @securopean@infosec.exchange
· 46mo ago
Replying to
@paulg No matter what happens, I don't think I want to ever go back to a site where the whims of one person (of whatever political persuasion) can cause so much chaos and upset. As I heard someone on here say, we lost something from the original Internet when we moved away from protocols and centralised around platforms.
3
0
0
0
Open post
Securopean @securopean@infosec.exchange
· 45mo ago
Replying to
@joshbressers I asked #midjourney for some help to design a logo.
1
0
0
0
Open post
Securopean @securopean@infosec.exchange
· 46mo ago
Replying to
@suswatibasu@mstdn.social Such a beautiful place, we were lucky enough to go hiking there a few years ago. And the ice-cream at the lake was a nice finish to the day :)
1
1
0
0
Open post
Securopean @securopean@infosec.exchange
· 46mo ago
Replying to
@computercellar@bitbang.social Hey, I haven't really looked into BitWarden, but I'm wondering what I'm missing when people say they are moving from LP to BW as the core product looks very similar to LastPass to me - encrypted online vaults, protected by user-chosen master passwords. (Obviously the self-hosted BitWarden has a different risk model, and might be a good option for someone who really understands what they are doing.). 1Password has made an attempt at finding a solution to the weak master password problem, and some of the other options mentioned here take different approaches (e.g. storing data in a personal vault only).
0
1
0
0
Open post
Securopean @securopean@infosec.exchange
· 46mo ago
Replying to
@adamshostack@infosec.exchange My thought process on this is that if I think through potential worst-cases as to what people might have stored, knowing who the attacker was and what their motivations potentially are may give some insight into what data will most immediately be at risk (e.g. will this be dumped somewhere for sale). I don't use LastPass so this is second-hand knowledge to me, but as I understand it the "notes" fields were essentially free-text. I wonder too how many people even know of this breach outside of our own echo chambers, and I see a bit of false security as well ("I have 2FA enabled on my vault").
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:31:17 UTC