Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk  ·  activity timestamp 2 weeks ago

UK data protection fine for password manager LastPass:

> Password manager provider fined £1.2m by ICO for data breach affecting up to 1.6 million people in the UK

https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/12/password-manager-provider-fined/

#GDPR #DataProtection #LastPass

  • Copy link
  • Flag this post
  • Block
Gary Hawkins
Gary Hawkins
@ghawkins@mastodon.garyhawkins.uk replied  ·  activity timestamp 2 weeks ago

@neil In paragraph 216, did the ICO really redact the undiscounted fine amount before the 30% discount was applied but were quite happy to tell us in the same paragraph what the fine amount after discount was? If only there was a way to work out what the redacted figure was 😂

  • Copy link
  • Flag this comment
  • Block
Fazal Majid
Fazal Majid
@fazalmajid@social.vivaldi.net replied  ·  activity timestamp 2 weeks ago

@neil password managers are obviously high-value targets, but like security software in general, there is far more snake oil than genuine security. I've never trusted LastPass and 1Password. Closed source and loud marketing are a strong indicator of "avoid" as far as I am concerned.

I used to rely on the Apple Keychain, but now that I am moving away from Apple due to creeping enshittification I am relying on KeePassXC.

  • Copy link
  • Flag this comment
  • Block
Giles of the Jungle
Giles of the Jungle
@gilester45@twit.social replied  ·  activity timestamp 2 weeks ago

@neil I wasn't too worried about this at first, because my vault was secured way beyond the default level of pbkdf iterations and with a long unique password.

Then I discovered they didn't actually bother encrypting everything in the vault. Passwords, yes, but notes? Nope. WHAT?!

Absolutely unconscionable!

Dropped them in a second, moved to BitWarden and had a somewhat unenjoyable Christmas day cycling passwords just in case, because all trust in LastPass had evaporated.

  • Copy link
  • Flag this comment
  • Block
JSON Alexander
JSON Alexander
@crashtestdev@woof.tech replied  ·  activity timestamp 2 weeks ago

@neil I tried to LastPass up several times at work, but every time their client software was such a bug filled mess, I was never able to complete the sign up; and also the thought process "if they can't reliably make a simple sign up form work, what are they like with security", needless to say I was unsurprised when the data breach was reported

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 2 weeks ago

vaultwarden is here:

https://github.com/dani-garcia/vaultwarden/

Your data, encrypted, on your own server. This works really well for family sharing too, in my experience.

  • Copy link
  • Flag this comment
  • Block
Ruben
Ruben
@cyclops_@fosstodon.org replied  ·  activity timestamp 2 weeks ago

@neil how's the browser plugin for this, in your experience?

  • Copy link
  • Flag this comment
  • Block
David S
David S
@elphez@mas.to replied  ·  activity timestamp 2 weeks ago

@neil Out of curiosity, how would that work if you're away from home and the home connection dies? Do you have a failover connection (ISTR seeing something about you getting cheap data SIMs)?

  • Copy link
  • Flag this comment
  • Block
Wendy M. Grossman
Wendy M. Grossman
@wendyg@mastodon.xyz replied  ·  activity timestamp 2 weeks ago

@neil It may be there, but the problem with sending people to github is there's rarely any quick explanation of what the thing is...

  • Copy link
  • Flag this comment
  • Block
ahnlak
ahnlak
@ahnlak@kavlak.uk replied  ·  activity timestamp 2 weeks ago

@neil so... 75p per head?

That's what the ICO thinks personal data is worth, eh?

  • Copy link
  • Flag this comment
  • Block
Em :official_verified:
Em :official_verified:
@Em0nM4stodon@infosec.exchange replied  ·  activity timestamp 2 weeks ago

@neil Those fines are really too tiny.

  • Copy link
  • Flag this comment
  • Block
Tats 🇬🇧🫖
Tats 🇬🇧🫖
@Tattooed_Mummy@beige.party replied  ·  activity timestamp 2 weeks ago

@neil and it's because of that breach I'm now with @bitwarden

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.40 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct