Pour one out for all of the security practitioners who are going to have to spend the holidays patiently explaining that using a password manager is still good, actually, to people who have glanced at a headline about the latest LastPass breach.
@evacide ok but serious question: is LastPass less secure than other password managers? I hear about their breaches quite often.
@antimatter @evacide As a thirty-odd-year systems admin, I wouldn't touch LastPass with a ten-meter pole at this point. HOWEVER, I do use a password manager semi-religiously: KeePass/MacPass. It's a bit more complex than something like 1Password, but it means my passwords are in cloud storage of MY choosing - or not! and they're encrypted *before* being sent to the cloud. If I hadda pick one for the cloud, I'd say 1Password or Bitwarden. (1Password has the option to use 3rd party cloud 👍 )
@stonebear @antimatter @evacide people seem to underestimate the fact that not everyone is an InfoSec worker. It's fine to have those discussions among peers, but frankly it does a disservice to the larger audience. Having people using a password manager rather than not by itself is a huge win.
@tssalvador @antimatter @evacide True, _and_, when the fit hits the shan, _which one_ is important. I gave alternatives that would fit both the nerd and the ... less technically inclined, b/c I know different technical levels toot here. _However_, having one with major problems is worse than not having one at all; you're sitting there thinking you're being ubersafe and that sucking noise is your bank accounts being drained... people need to know which is what.
@stonebear @antimatter @evacide possibly yes. I think LastPass will be fine for most still, assuming that they don't fall for the phishing.. I have been a LastPass user since when Steve Gibson recommended it on Security Now over at @TWiT, although I have been tempted to switch to #bitwarden and might finally give it a go, but I tell you I'm already dreading it. The trouble it took me to convince my wife to use in lieu of her one "same password everywhere" approach has been horrendous
@stonebear @antimatter @evacide it's not like they can see the benefit for the "trouble" it causes