LassPass was Hacked !!!!

Good thing I still use my brain to store my passwords lol

I recommend BitWarden, whether it's selfhosted or using their cloud. I haven't looked back since I switched to BW.
Any reason you went with BW? Part of me still wants to test it out, even though I'm happy with KP - always looking for that greener grass ;)
 
Any reason you went with BW? Part of me still wants to test it out, even though I'm happy with KP - always looking for that greener grass ;)
Username Generator that is intergrated with SL. Which i have a full paid plan of.
It's open sourced, there are secured notes option, Send option that is selfdestructing & pw locked, sender hidden, maximum access count locked etc etc
& overall, it's just much easier to use then some of the other ones I have used in the past (then again, i haven't tried other options for sometme now so i'm sure their functionality has improved but why move when i am comfortable with my current one)
 
Huh... Yeah KP is JUST passwords, can't even load CC's into it. I will have to check out BitWarden can you self host it?
Edit: You covered this, you can self host. KP now sounds like garbage lol
 
Last edited:
My advice to everyone who are there. Always use OFFLINE Password Managers (Keepass, BitWarden)

Create a VM (Can be Windows or Linux) in your local computer (many tutorials in youtube how to do it), get a firewall and block ALL connections, use Veracrypt (this is optional) encrypt your VM that you created.

Steps to make it very secure with offline software password managers:

1. Create a VM with VirtualBox or VMWare (many tutorials in youtube) can be Windows or Linux or other OS
2. Make sure they aren't connected to internet, block all connections both inbound or outbound and make it private.
3. Use a Masterkey and strong passwords in your masterkey or software enabled all 2FA security.
4. Optional -> Encrypt your VM that you have created with Veracrypt or other encryption solution available <- (OPTIONAL)
5. The probability of your being hacked is very lower, but very lower! ;)

Use this offline password manager (very secure if used locally and with master key and no internet connection)
https://keepass.info/download.html
Yes it works for Windows, Linux, Android, iOS, MAC OS.

If you want to have synchronize with browsers and make backups or more features you can use the plugins available
https://keepass.info/plugins.html
Available in many languages and ALL PASSWORDS is encrypted.
You can of course doing that without VM.

I advice anyone to use this in a computer locally and always do backup of your DB and master key in USB or other PC or cloud (Google Drive etc)

Keepass is one of best passwords managers and is completely free.

Alternative to Keepass and more modern:
https://bitwarden.com/
Cheers
 
Stopeed using it for a while already.

My advice to everyone who are there. Always use OFFLINE Password Managers (Keepass, BitWarden)

Create a VM (Can be Windows or Linux) in your local computer (many tutorials in youtube how to do it), get a firewall and block ALL connections, use Veracrypt (this is optional) encrypt your VM that you created.

Steps to make it very secure with offline software password managers:

1. Create a VM with VirtualBox or VMWare (many tutorials in youtube) can be Windows or Linux or other OS
2. Make sure they aren't connected to internet, block all connections both inbound or outbound and make it private.
3. Use a Masterkey and strong passwords in your masterkey or software enabled all 2FA security.
4. Optional -> Encrypt your VM that you have created with Veracrypt or other encryption solution available <- (OPTIONAL)
5. The probability of your being hacked is very lower, but very lower! ;)

Use this offline password manager (very secure if used locally and with master key and no internet connection)
https://keepass.info/download.html
Yes it works for Windows, Linux, Android, iOS, MAC OS.

If you want to have synchronize with browsers and make backups or more features you can use the plugins available
https://keepass.info/plugins.html
Available in many languages and ALL PASSWORDS is encrypted.
You can of course doing that without VM.

I advice anyone to use this in a computer locally and always do backup of your DB and master key in USB or other PC or cloud (Google Drive etc)

Keepass is one of best passwords managers and is completely free.

Alternative to Keepass and more modern:
https://bitwarden.com/
Cheers
So you use a VM just for accessing your PW manager and its DB?
 
So you use a VM just for accessing your PW manager and its DB?
You can host locally in your computer without VM, is still safe and secure.

But if you are paranoic and you want full data security even if your computer is stoled or anything like that.
Then, yes use a VM just for PW Manager and important things, if you encrypt your VM that will be a huge bonus for privacy.

Block all connections in your VM, then no hackers can acess your VM.
The chances of your VM being hacked is MINIMAL, very low / small risk. Huge privacy ;)
 
But if you are paranoic
Yes.

I noticed you didn't mention using a Yubikey or similar physical device. Any reason why? My DB requires it for all actions and I use it for multiple forms of 2FA, I have a second one that is kept safe as a backup although one pain in the ass is that if I do need to add another 2FA account I have to retrieve that backup and manually add the key to it also as you can't "clone" a Yubikey. I shall be heeding your VM advice good sir, thank you for your replies. :)
 
Yes.

I noticed you didn't mention using a Yubikey or similar physical device. Any reason why? My DB requires it for all actions and I use it for multiple forms of 2FA, I have a second one that is kept safe as a backup although one pain in the ass is that if I do need to add another 2FA account I have to retrieve that backup and manually add the key to it also as you can't "clone" a Yubikey. I shall be heeding your VM advice good sir, thank you for your replies. :)
Yeah don't use Twilio for 2FA
https://www.blackhatworld.com/seo/lastpass-was-hacked-twilio-2fa-isnt-doing-any-better.1433143/ ;)
 
They emailed their users about this but I don't know if that's true. I am using LastPass for a long time now, but I think I should switch to BitWarden now. It will take a lot of time though to change passwords for all the sites. :(
 
Found out my handy dandy password I’ve been using for the last few years across like a 100 sites was out in a dataleak lmao.
 
1 password everywhere is a critical mistake
I learned it the hard way. I was using one password everywhere and one of the captcha solver sites where I had the same password got hacked. After that, a lot of people tried to log into my account. Some got access to my Evernote account too, along with others but I could only change the password for the main sites that I remembered. After that, I never used the same password at two sites.
 
They emailed their users about this but I don't know if that's true. I am using LastPass for a long time now, but I think I should switch to BitWarden now. It will take a lot of time though to change passwords for all the sites. :(
You can export from Lastpass as an .xml and go to a new manager easily, just know that .xml has all the goods and no PW.
 
  • Like
Reactions: V
I learned it the hard way. I was using one password everywhere and one of the captcha solver sites where I had the same password got hacked. After that, a lot of people tried to log into my account. Some got access to my Evernote account too, along with others but I could only change the password for the main sites that I remembered. After that, I never used the same password at two sites.
Yeah that's right.
At least you can use different combinations of 1 password to make it easy memorable.
Password123
Password!!!
etc.
And you must have 3-4 types of this combination.
Also, I am never entering my main passwords on strange sites.
I am making about 5 password resets during month because I cant remember where what entered :D
 
Back
Top