Last Pass Breach 2022: My Recommendations

preview_player
Показать описание
LastPass has lost my trust. Here's what I'm doing about it, and what I think you should do.

More Ask Leo!

00:17 Short version
01:30 Missinformation and panic
03:50 Weak Master Passwords
05:52 Move away from LastPass
06:57 What I've moved to, and what I recommend
11:00 Setting up a new account
13:00 Migrating, the easy(ish) way
14:30 What I'm doing: the hard(ish) way
16:20 Do I need to change ALL my passwords?
18:48 Won't the new solution get breached?
20:15 Keep using a password vault!
22:30 Summary, it's time to move on

#askleo #lastpass #passwordmanager
Рекомендации по теме
Комментарии
Автор

I have watched dozens of videos on the lastpass mess....I finally found the right expert. Nice work. Thank you!

DRaged
Автор

12:47, Make sure your safe is fireproof as well.

LunaticTheCat
Автор

Bit warden is fantastic. I pay for the annual subscription just to support such an open and transparent company

dylan.t
Автор

I have Bitwarden and for now I am entirely happy and satisfied that they are looking after my private vault information.

ralphyo
Автор

Outstanding summation, with calm, clear, concise reasoning on the scope of the LastPass breach and why to move on to another password manager solution. My wife and I are not knowledgeable power users, so we went with NordPass. It is very easy to setup and intuitive to use-figure out, like LastPass. NordPass seems to be the up-and-comer of password managers with superior newer encryption technology from a solid, innovative security company. (Maybe this would be a great time for Microsoft to launch a full-fledged password manager built right into the OS for Windows users-just wondering).

Arizona-Sonoran-Desert-Guy
Автор

Thanks Leo, I'm leaving my LassPass account active, but switched over to BitWarden with new complex passwords. I'm letting LassPass serve as a HoneyPot. Keep them busy 🤣😂

rfrancoi
Автор

Once LastPass was sold by the original creator, things kept slipping. Too much metadata was left in the clear, provides hackers with ammunition to target people with all sorts with threats like asking for money or they will expose such and such. They did not update key settings for all clients and that is a huge mistake. Steve Gibson also did a great story of LastPass. Scary, just how many people use the built-in password manger of their web browser. Would not trust MS to create a secure PW manager.

andymok
Автор

Thanks, Leo! I've moved on from LastPass. Had a good master password, but like you said, trust is everything. This event also made me go through and do some password hygiene that I've been meaning to do. KeePass is also a good option, with a strong master password and then a DropBox it. Have a good password on DropBox.

InquisiitorWHK
Автор

Thanks Leo. This was very helpful and I was looking forward to your recommendation. Any reason I couldn't manually edit the .csv file to remove the cruft? This seems to be a less time consuming option than starting from scratch, plus I can sort it into different files for import into different 1Password vaults (I think). As long as I save it as a .csv file, I would think it should work. Appreciate your thoughts.

thenash
Автор

Really great info. Thank You. How about Keeper?

BethSargent
Автор

Leo, how do we know that 1password or Bitwarden are not storing some of our personal information in the clear just like LastPass did?

ronyoung
Автор

Another thing I've been doing as I change my passwords is enabling 2FA on important accounts that I didn't have it enabled on before. Also, I'm keeping 2FA information, such as Authy password and recovery keys for various accounts, out of my new password manager. That way, if my new password manager vault is compromised in the future, they still won't be able to log into important accounts.

dansanger
Автор

Thank you Leo! I've been waiting for your recommendations. What are your thoughts on NordPass password manager? Also, what is the difference between a passkey vs. a password?

johneaglin
Автор

Thanks you know if both of those managers use Yubikey for 2fa?

larrytaylor
Автор

Does anyone recommends iCloud Keychain?

edgarb.
Автор

personally, I don't understand choosing convenience over security when the name of the game is "Security". that is why i use KeepassXC. I'd rather park my car myself than handing my key to a valet hoping he/she won't damage my car.

BenjaminWSong
Автор

Leo thanks for another excellent video. I use 1Password Version 7 on my Windows 10 desktop PC. Is the Version 7 database only stored on my PC?

Dubinvero
Автор

The first passwords that I changed, and that I suggest others address as a priority, are your email passwords. Because for many websites, if you forget your password, what do they do? They send a link to your registered email address to confirm it’s you. If someone has access to your email, they can use it to reset passwords to your important accounts, such as banking, etc.

libbyd
Автор

I had my 2FA(Yubikey) enable before I can access my vault. Am I save to move on?

kingsleyfhk
Автор

Leo....I forgot to tell you that Steve Gibson of Security Now also switched to Bitwarden password manager after he did his research, he was a long time LastPass user.

larrytaylor
welcome to shbcf.ru