Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP.

The lesson here is to get off of LP ASAP, you can figure out where to go later.



You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.


I put my passwords in Google Sheets temporarily. Then I moved them to 1Password, except the throwaway stuff.

Google accounts aren’t immune to being compromised, so I agree that it’s not a good home for passwords (without even the need to invoke internal threats) — but it felt safer than LastPass. Which ought to be an embarrassment.


your passwords are used to train LLMs now :3


Why those countries? Does google have weaker internal security for employees in those countries?


I had exactly this happen to me, suffered great monetary losses and had my identity stolen. I've learnt my lesson and have moved on to 1password.

At the end of it I couldn't help but reflect on my foolishness. I realised just how much better I would've felt if only it had been an American, Canadian, or European Googler who stole my data. It really is the worst when malicious entities are Chinese, Indian, or Pakistani. Just the worst!!! (/s)


this is... such a bad idea lol


Not as bad as the idea of passwords.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: