Solved The LastPass breach settlement is real. Here’s what you should know


Password Managers are overrated! Just go analog, write 'em down in a notebook, it's the safest solution.
And also a major PITA if you're truly using secure passwords! Manually typing in the 12 character password of random upper case, lower case, numbers, and special symbols is not something I want to do all the time.
 

My Computers

System One System Two

  • OS
    Win 11 Pro 25H2, Build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14500
    Motherboard
    Gigabyte B760M G P WIFI
    Memory
    64GB DDR4
    Graphics Card(s)
    GeForce RTX 4060
    Sound Card
    Chipset Realtek
    Monitor(s) Displays
    LG 45" Ultragear, Acer 24" 1080p
    Screen Resolution
    5120x1440, 1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 3D NAND NVMe M.2 SSD (O/S)
    Silicon Power 2TB US75 NVMe PCIe Gen4 M.2 2280 SSD (backup)
    Crucial BX500 2TB 3D NAND (2nd backup)
    Seagate 4TB Ironwolf, rotating HDD archive files
    External off-line backup Drives: 2 NVMe 4TB drives in external enclosures
    PSU
    Thermaltake Toughpower GF3 750W
    Case
    LIAN LI LANCOOL 216 E-ATX PC Case
    Cooling
    Lots of fans!
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • Operating System
    Win 11 Pro 25H2, Build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14400
    Motherboard
    Gigabyte B760M DS3H AX
    Memory
    32GB DDR5
    Graphics card(s)
    Intel 700 Embedded GPU
    Sound Card
    Realtek Embedded
    Monitor(s) Displays
    27" HP 1080p
    Screen Resolution
    1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 eD NAND PCIe SSD
    Samsung EVO 990 2TB NVMe Gen4 SSD
    Samsung 2TB SATA SSD
    PSU
    Thermaltake Smart BM3 650W
    Case
    Okinos Micro ATX Case
    Cooling
    Fans
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
Even better than writing them down is to use https://www.passwordcard.org and write down the code.

This generates a card you can physically print to make coded passwords:
So if I wanted an 8-character password for my Gmail login, I might use "Diamond-Green-Left" as my code, which means my Gmail password would be "Peh2WmGK" (per the screenshot above).

Nobody can get my passwords unless they have both my Password Card and my book of codes for it. Everything is offline/air-gapped.
 

My Computer

System One

  • OS
    Windows 11 Pro
Just go analog, write 'em down in a notebook, it's the safest solution.

I've done that at times. Especially if I have to (rarely) get into banking or local government websites...

Some websites are more valuable to protect than others.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2 build: (26200.7623)
    Computer type
    Laptop
    Manufacturer/Model
    Microsoft Surface Pro
    Memory
    32GB
  • Operating System
    Microsoft 25H2 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Dell Pro 14 - PC14250
    CPU
    Intel Core Ultra 7
    Memory
    64GB
    Graphics card(s)
    Intel Integrated Graphics
    Hard Drives
    Micron 1TB SSD
I remember when people were saying that LastPass security was unbreakable.
Secure, encrypted or not. It's just a dumb idea to be storing your passwords on someone else's computer.
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Stigg's Build
    CPU
    Intel Core i9-10900X
    Motherboard
    GIGABYTE X299X DESIGNARE 10G
    Memory
    Corsair 64 GB (4 x 16 GB) CMW64GX4M4C3000C15 Vengeance RGB Pro 3000Mhz DDR4
    Graphics Card(s)
    GIGABYTE GeForce GTX 1660 Super Mini ITX 6 GB OC
    Sound Card
    Realtek ALC1220
    Monitor(s) Displays
    Samsung 27" FHD LED FreeSync Gaming Monitor (LS27F350FHEXXY)
    Screen Resolution
    1920 x 1080
    Hard Drives
    Samsung 970 Pro Series 1TB M.2 2280 NVMe SSD
    Western Digital Red Pro WD8003FFBX-68B9AN0 8 TB, 7200 RPM, SATA-III
    Western Digital Red Pro WD8003FFBX-68B9AN0 8 TB, 7200 RPM, SATA-III
    PSU
    Corsair HX1200 1200W 80 Plus Platinum
    Case
    Fractal Design Define 7 Black Solid Case
    Cooling
    Noctua NH-D15 Chromax Black
    Keyboard
    Razer Ornata V2
    Mouse
    Razer DeathAdder Essential
    Internet Speed
    FTTN 100Mbps / 40Mbps
    Browser
    Mozilla Firefox
    Antivirus
    N/A
    Other Info
    Logitech BRIO 4k Ultra HD USB-C Webcam
  • Operating System
    Windows 10 Pro
    Computer type
    Laptop
    Manufacturer/Model
    ASUS ROG Zephyrus M GM501GS
    CPU
    Core i7-8750H
    Motherboard
    Zephyrus M GM501GS
    Memory
    SK Hynix 32 GB (2 x 16 GB) HMA82GS6CJR8N-VK 16 GB DDR4-2666 DDR4 SDRAM
    Graphics card(s)
    NVIDIA GeForce GTX 1070
    Sound Card
    Realtek ALC294
    Monitor(s) Displays
    AU Optronics B156HAN07.1 [15.6" LCD]
    Screen Resolution
    1920 x 1080
    Hard Drives
    Samsung MZVKW512HMJP-00000 512 GB, PCI-E 3.0 x4
    Samsung SSD 860 QVO 4TB 4 TB, SATA-III
    PSU
    N/A
    Case
    N/A
    Cooling
    N/A
    Keyboard
    PC/AT Enhanced PS2 Keyboard (101/102-Key)
    Mouse
    Razer DeathAdder Essential
    Internet Speed
    FTTN 100Mbps / 40Mbps
    Browser
    Mozilla Firefox
    Antivirus
    N/A
    Other Info
    USB2.0 HD UVC Webcam
I remember when people were saying that LastPass security was unbreakable.

No matter how strong a password is, they can sometimes be reset with the "forgotten password" feature of the website in question, mainly those send a reset link to your email account. So if someone has access to your email account, then they can reset the passwords of all your other accounts.
 

My Computer

System One

  • OS
    Windows 11 Pro
So if someone has access to your email account, then they can reset the passwords of all your other accounts.
This is a reason to:
  1. Protect your email account as well as you can — treat it like your password manager account if possible.
  2. Use 2FA everywhere, or at least everywhere important.
Even passkey recovery typically still requires your email; there’s currently no way around that.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
High security is just as much a PITA as typing 24 random characters into a dialog box!
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS ROG Strix
  • Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    ASUS VivoBook
The root problem here is using online password managers, that fundamentally publish your vault on "the cloud" (ie, someone's else computer) and you access it remotely. Then your safety depends on how well implemented is this protection. From the LastPass breach, it seemed that it didn't protect it very well. Other online managers were also breached in the past, but sometimes only encrypted data was leaked, at least, they took security much better.

If you remain with offline password managers you get all their benefits without the risk of being hacked if there is a problem on their site. Also if oyu use an open source one there is greater reasurance that proper security techniques have been used.
My passwords are encrypted in a local file that I only ever have access.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
it needs to be remembered password managers be it online or local
be they encrypted on written down on paper are only protecting the front door
most seasoned hackers/burglars/thieves will use the back door.

hence the best security you or anyone else has is common sense.
best of luck Steve ..
 

My Computers

System One System Two

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
I use keepass to store passwords, its not integrated into anything, just a straight forward manager.
 

My Computer

System One

  • OS
    Win11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Mine 1.5
    CPU
    7800X3D
    Motherboard
    ASUS B650 Tuf with wifi.
    Memory
    32gb G.Skill
    Graphics Card(s)
    4070 Ti Super
    Monitor(s) Displays
    1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
    Screen Resolution
    1440p
    Hard Drives
    C:\NVME (500GB), D:\Seagate (2TB), E:\ & F:\ SSD 990EVO (1TB)
    PSU
    Corsair HX1000i
    Case
    Phanteks Enthoo Primo w/10 140mm SP Fans
    Cooling
    Artic TF2 420
    Keyboard
    Corsair 1000
    Mouse
    Steel Series Prime Wireless
    Internet Speed
    20 MB/s
    Browser
    Firefox 64
    Antivirus
    not telling!
    Other Info
    https://i.imgur.com/aoz3vWY.jpg?2
I'm pretty sure that you'll find that the browser's password manager is less secure than the dedicated password vaults.
That's what I've heard too. I never use the browser's password manager.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell OptiPlex 7060
    CPU
    Hexa-Core i5-8600T processor 3.2GHz
    Motherboard
    Dell Inc. 0DWPVW A00
    Memory
    32GB of DDR4 RAM
    Graphics Card(s)
    integrated Intel HD 630 coprocessor
    Monitor(s) Displays
    Intel(R) UHD Graphics 630 [Display adapter] DELL S2230MX [Monitor] (21.7"vis, s/n XX-05GX1Y-XXXXX-23J-08WM, March 2012)
    Antivirus
    Windows Defender Version 4.18.24090.11 Malwarebytes Anti-Malware Version 5.2.4.157
This is a reason to:
  1. Protect your email account as well as you can — treat it like your password manager account if possible.
  2. Use 2FA everywhere, or at least everywhere important.
Even passkey recovery typically still requires your email; there’s currently no way around that.
Now they're saying that text message 2FA is not really secure.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell OptiPlex 7060
    CPU
    Hexa-Core i5-8600T processor 3.2GHz
    Motherboard
    Dell Inc. 0DWPVW A00
    Memory
    32GB of DDR4 RAM
    Graphics Card(s)
    integrated Intel HD 630 coprocessor
    Monitor(s) Displays
    Intel(R) UHD Graphics 630 [Display adapter] DELL S2230MX [Monitor] (21.7"vis, s/n XX-05GX1Y-XXXXX-23J-08WM, March 2012)
    Antivirus
    Windows Defender Version 4.18.24090.11 Malwarebytes Anti-Malware Version 5.2.4.157
Now they're saying that text message 2FA is not really secure.
Yes — recommended order is FIDO2 (hardware/webauthn) > TOTP/push authenticator apps > email > SMS. SMS 2FA is weaker because of: 1) SIM‑swap or phone theft, 2) third‑party data leaks, and 3) SMS interception.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
more and more mobile phones are now using RCS messaging which is encrypted.

best of luck Steve ..
 

My Computers

System One System Two

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
more and more mobile phones are now using RCS messaging which is encrypted.
That’s an internet‑messaging protocol, not how service providers typically send 2FA codes to phones.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
That’s an internet‑messaging protocol, not how service providers typically send 2FA codes to phones.
i will check how my OTP's are sent next time the bank sends me one
because as far as i am aware all the messages that i have received thus far are RCS.

but all of my passwords are saved within the browser and i use a 2FA authenticator extension within the browser
but as a secondary method i also have text OTP's enabled on my logins as well, if that is available.

best of luck Steve ..
 

My Computers

System One System Two

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
i will check how my OTP's are sent next time the bank sends me one
because as far as i am aware all the messages that i have received thus far are RCS.
I think you'll find they are just SMS text messages.
 

My Computer

System One

  • OS
    windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 9510
    CPU
    11th Gen Intel(R) Core(TM) i7-11800H @ 2.30GHz (16 CPUs
    Memory
    16 GB
    Graphics Card(s)
    NVIDIA GeForce RTX 3050 Ti
    Hard Drives
    512GB Solid State Drive
    Browser
    Firefox
I think you'll find they are just SMS text messages.
but in the UK all copper phones lines are being removed and the whole network is being replaced with fibre
that means no land lines its all nearly digital now across the whole country.

so any and all texts will go by wifi via your mobile phone provider or by a fibre connection via your ISP, which is now mostly RCS encrypted text in the UK
but my bank only sends an OTP once every several logons, unless i delete all the cookies and reset the account back up.

best of luck Steve ..
 

My Computers

System One System Two

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software

Latest Support Threads

Back
Top Bottom