Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • I switched to keepass a decade ago (maybe) and never looked back
  • I ditched LastPass long ago for BitWarden, though I mostly use the Passwords app from Apple now.
  • This isn't great but it's not that big of a deal either. A lot of companies got bit by the Klue breach but it's not like your vaults are being accessed.
  • The vaults were accessed years ago
  • any company that stuck around (or began using) lastpass after vaults were leaked probably does not care about this one at all, considering its just CRM data.

    i can sympathize a little bit with companies that stick with lastpass. when i had to switch an org from lastpass to 1password, it was a massive undertaking and incredibly annoying. however, i have no sympathy for anyone who has chosen lastpass after 2022.

  • Agreed.

    The non-story here is the data is of minor criticality.

    The real story is is that however minor, you expect LastPass to be better. They’re a password storage company, in order to be trusted they need to be better than this.

  • I think it's time for LastPass to rebrand themselves as First0wned.
  • I've been an Enpass user for years because I got a lifetime purchase for a good deal. They don't host the cloud services for syncing passwords. Instead you just auth your cloud storage (I use Google Drive) and it syncs to that.

    This approach seems better to me. For one thing, I'd already be screwed if someone malicious got into my Google account, probably worse than if they got into my password manager. And additionally, this means they're not creating an absolute jackpot of data to breach in a centralized place. No one's gonna hack Enpass of all their passwords because that would require hacking all of Google Drive, Dropbox, iCloud, etc. and looking for the files manually.

    by hbn
  • How is that different from KeyPass for example?
  • > No one's gonna hack Enpass of all their passwords because that would require hacking all of Google Drive, Dropbox, iCloud, etc. and looking for the files manually.

    Or they compromise their self-update system if that exists.

  • I'm sure this is worse than using lastpass in some way

    but for the past couple years I've just generated and forgotten 90% of my passwords. the final 10% I keep in a password manager. But if the service isn't really that important I just use the 'forgot my password' to change and generate a new password every time I need to login

  • This is why a lot of services have just moved to using email with magic links to log people in.

    In the end for a lot of services controlling your email is defacto controlling the login.

  • I got caught out as I had no longer access to the old phone number that was now used to send 2FA text.
  • This works if the account doesn't have 2FA. On my last side project app users can login only via email OTP. There are security downsides with that, someone can send phishing link and use OTP submitted to the fake site, but the app doesn't store anything sensitive (it's a game which tracks your progress) so I guess it's not a major security risk.
  • As much as the collective dumping on LastPass for yet another breach, and how they're totally irresponsible for handing customer data to some third party is amusing.

    I think if people took a moment to actually look at what happened, they might realise that the story everyone has in their heads is quite different from reality.

    Klue is one of those CRM services that so many sales teams are using. Yes, you have to hand them customer records (email of the customer contacts, finance teams, etc). That show Klue delivers it's "market intelligence" thing about that customer.

    If you go to your sales teams and see what random stuff they have hooked up to your systems, I bet you will find similar things.

    Whether or not this is a good idea (I firmly dislike it), this is how sales teams work these days. If you try to take it away you will be fighting the entire sales organisation.

    I am more surprised that these breaches don't happen more often.

    It doesn't impact LastPass's actual password databases.

    (No affiliation with any of the entities involved in this)

  • > I am more surprised that these breaches don't happen more often.

    They do.

  • WTF is LastPasd doing, handing customer details to a market research company? Any such data should have been fully anonymized: no names, no specific addresses, etc..

    For anyone looking for a recommendation: I use KeepassXC with Keepass2Android. Open source, with a local database that you can choose to sync (or not). I sync using Own cloud.

  • passwordstore.org also a nice alternative
  • I've been using pwsafe for years. Also free and open source. Local-only vault. No cloud service to depend on that's going to incompetently lose your data. You can optionally store your vault in dropbox or iCloud drive, but why would you?
  • > Any such data should have been fully anonymized: no names, no specific addresses, etc..

    Why even give them that?

  • I self host everything but email and credentials. Email because I already have a full time job, and credentials because if an emergency is sufficient enough to remove me from my hardware, that’s when I’ll need my passwords the most.

    To be fair, I could just sync the db somewhere safe.

  • https://blog.lastpass.com/posts/klue-supply-chain-incident-a...

    > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.

  • Lots more companies affected. Some more listed below:

    >"Klue has not said how many of its hundreds of customers are affected. Several companies have come forward to confirm they had data stolen during the attack, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium."

    >Cybercrime group Icarus took credit for the breach, saying on its leak site that it will publish the stolen data on Monday if the company does not pay the hackers’ ransom."

    https://techcrunch.com/2026/06/22/klue-hack-results-in-data-...

  • How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
  • As others have pointed out, LastPass is often chose for compliance. Not for security.
  • What's the risk, and does that change by moving to an alternative?

    Companies deal with leaked secrets a lot. A company already using a password manager is ahead of the game.

    Suppose they move to a competitor. That's a migration and training that someone has to drive. What do they gain? Another company that can also have exploits? Or they self-host, and now have to fund that, and still potentially get exploits?

    Ultimately, this likely isn't that big of a deal for a company.

    And they have to weigh it up against all the other things that they can be doing.

  • The one that amazes me is Okta.

    OK their Mac UX is great, but given their rate of incidents how can you trust it?

    Clearly this stuff is not actually bought based on track record.

  • People still use Windows
    by pluc
  • How does anyone trust ANY third party with all their passwords and encryption keys is beyond me.

    Setting up KeePassXC is trivial.

  • I’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were the ones that had been breached in the past. Until the execs and board see the dollar impact themself and not just read about it, the security program never gets the funds it needs.

    I’m not saying I recommend LastPass for that reason, but I wouldn’t write them off for that reason.