Pour one out for all of the security practitioners who are going to have to spend the holidays patiently explaining that using a password manager is still good, actually, to people who have glanced at a headline about the latest LastPass breach.
@evacide ok but serious question: is LastPass less secure than other password managers? I hear about their breaches quite often.

@antimatter Difficult question to answer.I hate it how LastPass consistently downplays issues when they make them public. Also, they definitely aren’t great security-wise, and I’ve written on their shortcomings repeatedly.

Trouble is: other password managers aren’t great either, particularly the commercial cloud-based providers. I’ve looked into many, and the only one I could somewhat recommend is 1Password. Yet 1Password also failed to migrate away from PBKDF2. So if they are hacked, password data for high-profile targets is certain to be decrypted.

@evacide

How PBKDF2 strengthens your 1Password account password

Learn how 1Password uses Password-Based Key Derivation Function 2 to make it harder for someone to repeatedly guess your account password.

1Password
@shokk As I learned, 1Password has a truly random secret key to complement user’s password. Not as user-friendly, but then even PBKDF2 is in fact safe. @antimatter @evacide