981
submitted 1 year ago by L4s@lemmy.world to c/technology@lemmy.world

More than $35 million has been stolen from over 150 victims since December — ‘nearly every victim’ was a LastPass user::Security experts believe some of the LastPass password vaults stolen during a security breach last year have now been cracked open following a string of cryptocurrency heists

you are viewing a single comment's thread
view the rest of the comments
[-] Ado@lemmy.world 161 points 1 year ago
[-] iHUNTcriminals@lemm.ee 52 points 1 year ago
[-] OberonSwanson@sh.itjust.works 18 points 1 year ago

Any recommendations on how-to?

[-] treadful@lemmy.zip 33 points 1 year ago

KeepassXC (desktop)/KeePassDX(mobile) on top of something like Syncthing or Nextcloud.

[-] OberonSwanson@sh.itjust.works 3 points 1 year ago

Thanks for the suggestion, I’ll try checking out both options. Unfortunately, I have an iPhone, so sadly there’s no KeepassDX. 🤔

[-] treadful@lemmy.zip 3 points 1 year ago

I think there's probably a Keepass compatible iPhone app out there but I haven't vetted it. Worth looking for though.

[-] hobbit@lemm.ee 27 points 1 year ago* (last edited 1 year ago)

Vaultwarden is what I use: https://github.com/dani-garcia/vaultwarden/

Their wiki is pretty good assuming you're comfortable with Docker.

Back before I self-hosted, KeePassXC for desktop and Keepass2Android for mobile (along with Synching to sync the database) got the job done.

[-] OberonSwanson@sh.itjust.works 4 points 1 year ago

Interesting, I’ll check it out, as it looks like it’ll cover what I need. Hopefully it’s simple enough, as always having an iPhone makes things more complicated lol.

[-] hobbit@lemm.ee 3 points 1 year ago

I host for my family which has a mix of Android and iPhone. So far, no complaints about Bitwarden on iOS. Hopefully it works out for you. If self hosting becomes a problem, I think premium is only $10/year and family is up to 6 people at $40/year.

It doesn't have to be difficult.

  1. Download keepass to your computer.

  2. Keep the save file on a USB or private cloud backup.

  3. Done!

As you get more comfortable with it, you'll start using it in more complex ways. Like having a phone app, connected to a self hosted network. But keep it simple for now.

[-] OberonSwanson@sh.itjust.works 3 points 1 year ago

This might be a good idea for my family, they definitely prefer a K.I.S.S. approach lol.

[-] whileloop@lemmy.world 6 points 1 year ago* (last edited 1 year ago)

If you wanna use KeePass, you just have to store your database in some secure location. It can be on your local drive or in the cloud, any location you trust really.

[-] OberonSwanson@sh.itjust.works 4 points 1 year ago

Guessing it’s suggested to use a small flash drive and keep it hidden somewhere?

[-] Nighed@sffa.community 3 points 1 year ago

You can set the encryption strength though, so I guess you could set it high and could even have it untrusted.

Mine takes a while to open on my phone because of that

[-] linuxguy@lemmy.gregw.us 2 points 1 year ago
[-] Ado@lemmy.world 4 points 1 year ago

Self-hosted with yubikey 2fa. Even Santa Claus can't see my info 😎

[-] iHUNTcriminals@lemm.ee 1 points 1 year ago

I should get around to doing this... But it scares me haha.

[-] Ado@lemmy.world 3 points 1 year ago

I started out with the Yubikey, which was such a relief all by itself. Even if you have my password, you need my physical USB key to plug in or NFC confirm for the 2fa. I did later move to self-hosting, but I def have a backup of a backup for that since space is cheap-ish.

[-] olympicyes@lemmy.world 2 points 1 year ago

Not sure about that software specifically but most yubikey 2FA implementations allow you to set up more than one key. That way you don’t lose access if you lose your key. I personally have three keys.

load more comments (30 replies)
this post was submitted on 07 Sep 2023
981 points (99.0% liked)

Technology

59419 readers
2937 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS