frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

LastPass notifies users of yet another data breach

https://9to5mac.com/2026/06/23/lastpass-notifies-users-of-yet-another-data-breach/
44•mooreds•1h ago

Comments

lyu07282•20m ago
https://news.ycombinator.com/item?id=48657784

https://news.ycombinator.com/item?id=48647272

Third time's the charm

TZubiri•17m ago
>“On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,”

The specific dependency that gets companies infected, and the optics that result, are so important. There have been sillier examples, but you can see how in this case, the priority of sales and profits has resulted in the sacrifice of the main quality measure of their main and only product.

fn-mote•11m ago
> the priority of sales and profits has resulted in the sacrifice of the main quality measure of their […] product

To be fair, and I don’t want to, supposedly the only thing that was compromised was contact info. No vaults were exfiltrated or unlocked (as far as the article info goes).

So this is really just another very boring info breach, not a targeted password-stealing hack.

The other breaches they suffered were worse.

TZubiri•19m ago
Using a password manager has 2 main tradeoffs and mistakes:

1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff.

2- Cat and mouse security: There's a class of security decisions that work because they are new and different. First the weakness was that passwords were short, then you make passwords long but unmemorable, so people rely on some other mechanisms to authenticate, like a file on their computer, a drive, a fingerprint, facial recog, which may in turn be protected by a second factor password.

At first the new security model will not be stressed, but as more users migrate from one security model to the next one, that's when you are able to compare the security of both technologies, it starts being a juicy enough target that it becomes attacked.

So we are at the point where password managers are used enough that they start becoming worthwhile targets of attack (to overcome the difficulty of vulnerating them).

Also worth noting that these attacks are more winner-takes-all. In the sense that rather than seeing one account hacked every couple of hours, you will see them all hacked at once, because you introduced a vendor in the password supply chain AND because the vendor centralizes all of the passwords. So target that one vendor and from a single attack you get all the spoils. So when comparing the security of the olden method and the new, just 1 incident is enough to undo all of the reputational gains it has made over the years.

zarzavat•7m ago
"Password manager" used to mean a program that runs locally on your computer. At some point people started making it into a SaaS, because that's more profitable.

I do think there are some cases where an online password manager makes sense, e.g. for businesses, but for individuals it's better to just stick with an offline password manager, at least for the high value accounts.

amenghra•7m ago
Password managers (whether it's Lastpass or your browser's built-in password store) also protect against phishing since they tie passwords to domain names.

I don't think password managers which store encrypted vaults are less safe than trying to have and juggle strong unique-per-domain passwords, even if you think that the password manager is becoming a target.

throwawayffffas•13m ago
So... you business plan is to secure peoples personal data by handing some of that data to a third party. Got it.
cyanydeez•8m ago
the Achilles heel of a "secrets vault" is it becomes a defacto priority target. I still dont see how any reasonable person was convinced a cloud service was the best place to put all their secrets.
jagged-chisel•7m ago
How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
acheron•7m ago
The article is about a marketing data breach, not passwords.

Droughts are transforming the Turkish landscape with sinkholes

https://www.bbc.com/future/article/20260624-droughts-are-transforming-the-turkish-landscape-with-...
1•geox•1m ago•0 comments

Show HN: Mapping the Human Hippocampus, Sort Of

https://github.com/AImageLab-zip/CALHippo-Framework
1•ettore_c•2m ago•0 comments

Beyond Fable: Can a Local LLM Replace Cloud AI for Security Code Reviews

https://srlabs.de/blog/beyond-fable
1•dubbel•4m ago•0 comments

Mid-tier knives: worth the cost?

https://www.paragon-knives.com/
1•bgzlsxaz•7m ago•0 comments

OpenStreetMap running on an ESP32 with TypeScript and Canvas [video]

https://www.youtube.com/watch?v=-ktOCcfCIqA
1•arbayi•8m ago•0 comments

Cory's Cookies and The 92% Tax Rate (2018)

https://wrestlinggnon.com//essay/2018/09/02/corys-cookies-and-the-92p-tax-rate.html
1•surprisetalk•10m ago•0 comments

IBM hails new 'block of flats' design breakthrough for ultra tiny chips

https://www.bbc.co.uk/news/articles/cvg7vpyn5pxo
1•alastairr•10m ago•0 comments

How I use Anki to learn anything

https://jdlms.site/blog/how-i-use-anki-to-learn-anything
1•tietjens•11m ago•0 comments

Show HN: Simple Ledger

https://simple-ledger.app
1•heiswayi•16m ago•0 comments

Show HN: GTM Jobs – a weekly job board for GTM engineers (27 roles this week)

https://gtmjobs.beehiiv.com/p/gtm-engineer-jobs-this-week-27-roles-up-to-210k
3•meetvolley•16m ago•0 comments

Show HN: Create animated explainer video from a prompt

https://github.com/scosman/videowright
1•scosman•16m ago•0 comments

What are these artifacts on Google Maps?

https://www.google.com/maps/place/Bar+Miralago/@46.01658,11.2509747,992m/data=!3m1!1e3!4m7!3m6!1s...
1•abbassix•19m ago•1 comments

The Boom That Sprays One Weed at a Time – Mobility and Field Robotics

https://atomsfrontier.substack.com/p/the-boom-that-sprays-one-weed-at
1•jpatel3•20m ago•0 comments

Writing code versus shipping code: Productivity effects of AI coding tools

https://cepr.org/voxeu/columns/writing-code-versus-shipping-code-productivity-effects-across-gene...
2•rramadass•21m ago•0 comments

Software engineers are facing an 'identity crisis bordering on depression'

https://www.businessinsider.com/software-engineers-face-an-ai-identity-crisis-vc-partner-says-2026-6
3•robtherobber•22m ago•0 comments

A Teardown of Claude Tag's Agent Identity Concept

https://promptql.io/blog/a-teardown-of-claude-tags-agent-identity-concept
1•manushikhanna•22m ago•0 comments

Show HN: Kranth – test your idea on AI personas before real users see it

https://kranth.ai
1•iamdecatalyst•22m ago•0 comments

Instant Replay for Desktops

https://rewindly.app/
2•degecko•23m ago•1 comments

Benchmark unlimited Claude.md files against eachother

https://github.com/emiliolugo/clawmark
1•emiliolugo•23m ago•0 comments

Qualcomm to Acquire Modular

https://investor.qualcomm.com/news-events/press-releases/news-details/2026/Qualcomm-to-Acquire-Mo...
1•vovavili•23m ago•0 comments

One Sensible Choice at a Time

https://www.birdy.chat/blog/one-sensible-choice-at-a-time
1•rmesters•24m ago•0 comments

What Is Claude Code's Automatic Mode

https://www.polimetro.com/en/What-is-Claude-Code%27s-automatic-mode/
3•Gedxx•31m ago•0 comments

Show HN: Multi Agent Protocol for AI Scientist by Hexo Labs

https://github.com/hexo-ai/socrates
2•martianvoid•34m ago•0 comments

IBM claims first sub-1 nanometer chip technology

https://arstechnica.com/gadgets/2026/06/ibm-claims-worlds-first-sub-1-nanometer-chip-technology/
2•Gedxx•35m ago•0 comments

No one is self-made

https://aeon.co/essays/zhuangzi-and-the-case-against-meritocracy
5•robtherobber•35m ago•0 comments

What is IBM's nanostack chip architecture

https://research.ibm.com/blog/what-is-a-nanostack
1•rolivercoffee•37m ago•0 comments

Emperor penguin chicks jump off a 50-foot cliff in Antarctica

https://www.youtube.com/watch?v=4PwDFddpo4c
1•bookofjoe•37m ago•0 comments

Show HN: Claude Code Session Trace/Browse Tool (Python)

https://github.com/yonk-labs/claude-session-analyzer
1•TheMadHatter76•37m ago•0 comments

The protocol is not the thing to get good at, the AX discipline is

https://www.oreilly.com/radar/stop-getting-good-at-protocols-get-good-at-agent-experience/
1•developsean•38m ago•0 comments

'Digit' maker Agility Robotics to go public in $2.5B deal

https://www.geekwire.com/2026/digit-maker-agility-robotics-to-go-public-in-2-5b-deal-heres-what-t...
1•ripe•39m ago•0 comments