New best story on Hacker News: Ask HN: How did my LastPass master password get leaked?

Ask HN: How did my LastPass master password get leaked?
607 by gregsadetsky | 325 comments on Hacker News.
Hi, I've just had a bizarre thing happen and wanted to see if the HN community could come up with some theories as to what happened. LastPass blocked a login attempt from Brazil (it wasn't me). According to an email I received from LastPass, this login was using the LastPass account's master password. The email doesn't look like it's a phishing attempt. What troubles me is that the master password was stored in a local encrypted KeePassX file. I can imagine that someone has my KeePassX file and the (completely different) password to this file. If that's the case, I'm in a world of hurt. But are there any other possibilities? Is the email from LastPass accurate i.e. was the login attempt actually using my master password? Is there some LastPass extension installed on some computer still having a valid auth token allowing them to login as me to LastPass..? I'm really confused, and scared. Thanks for your help. P.S. The LastPass account had 2FA set up, but I was able to simply remove it (since I didn't have access to the token anymore). That's scary too -- what's the point of a 2FA you can remove...?? --- Update: - the email was truly not phishing -- the same information regarding the login attempt appears in my LastPass dashboard. I also talked to LastPass support over the phone, and they confirmed seeing the same information. - There are 2 separate users in the thread below confirming that the same exact same thing happened to them, from the exact same IP range as me. Either the 3 of us had the same malware/Chrome extension or somehow had our master passwords compromised...? Or...? Is this a LastPass issue?

New best story on Hacker News: 25-Dec. Shout-out to everyone else at work

25-Dec. Shout-out to everyone else at work
542 by sandworm101 | 115 comments on Hacker News.
I made a similar post last year at this time and, again, I am in my office on Christmas morning. There are a few days every year that really show which jobs are vital and which can be left aside for a day. I started my car this morning (-32, -40 with wind chill). On my way to work I drove past a hospital and a care home, both were manned. The dairy farm had its lights on. A cop with his flashers drove past me on the way to some emergency. The macdonalds drive-through was open too. I had to be at work by 0600, but I was relieving someone who had been sitting in another office since 1800. On my computer were the same dozen emails I get every morning, each from someone else who drew the short straw. There aren't many of us on HN that work weekends let alone Christmas morning, but If you too are sitting in a dark office remember that all across the world are millions of other people working the truly important jobs.

New best story on Hacker News: Tell HN: You are not alone this Christmas

Tell HN: You are not alone this Christmas
740 by mattowen_uk | 202 comments on Hacker News.
Hi, my Christmas is solitary this year, no family or friends. I'm not even having a Christmas dinner. I'm not sad about this, though. It's just the way it is. What I wanted to say is, if you are in the same situation, you are not alone. So have a virtual hug from me.

New best story on Hacker News: Ask HN: Those making $500/month on side projects in 2021 – Show and tell

Ask HN: Those making $500/month on side projects in 2021 – Show and tell
580 by folli | 613 comments on Hacker News.
It seems this question hasn't been asked for some time, so I'd be interested hear what new (and old) ideas have come up.

New best story on Hacker News: AWS appears to be down again

AWS appears to be down again
539 by riknox | 389 comments on Hacker News.
Console is flickering between "website is unavailable" and being up for my team. This is happening very frequently just now, reliability seems to have taken a hit.

New best story on Hacker News: Ask HN: Are most of us developers lying about how much work we do?

Ask HN: Are most of us developers lying about how much work we do?
622 by ConfessionTime | 434 comments on Hacker News.
I have been working as a software developer for almost two decades. I have received multiple promotions. I make decent money, 3x - 4x my area's median salary, so I live a comfortable life. I have never been fired or unemployed for more than a few months total over my entire career. Through most of that time I have averaged roughly 5 - 10 hours of actual work a week. I'm not even discounting job related but non-coding time as not work. There are literally days in which the only time I spend on my job is the few minutes it takes to attend the morning stand-up. Then I successfully bullshit my way through our next stand-up to hide my lack of production. No one has ever called me out on this and my performance reviews range from mediocre to great. I'm generally a smart person. I went to a top 30 university, but it's not like I'm a genius or I'm coasting off connections made while getting a Harvard education. I wouldn't consider myself an abnormally talented developer. I often don't understand the technical details other engineers discuss in meetings. I have probably bombed more tech interviews than I have passed. All my jobs have been between 2-5 years so I'm neither finding a place to stagnate or leaving before anyone could judge my production. It feels like I am in the middle of the bell curve in terms of career success. So what gives? Are most of us secretly lying about how much we are working? Do people regularly run into coworkers like me during their career and simply ignore it because they find it too awkward to criticize them? Have I just been incredibly lucky and every boss I have had is too incompetent to notice? Do I have imposter syndrome and I am actually a 10x developer whose laziness makes them a 1x developer? These questions have kept popping up in my mind over the last year. Remote work during the pandemic has allowed me to finally be honest with myself and stop pretending I am working when I am not. I want to know if I was the only one pretending.

Fox News Breaking News Alert

Fox News Breaking News Alert

Number of dead rises after devastating tornadoes, Kentucky governor announces

12/13/21 7:52 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

Biden approves Kentucky disaster declaration after devastating tornado

12/12/21 8:43 PM

Fox News Breaking News Alert

Fox News Breaking News Alert

Blue Origin successfully sends 6-person crew, including Michael Strahan, to space and back

12/11/21 7:13 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

Kentucky tornado death toll likely to exceed 50, governor warns

12/11/21 2:58 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

UK court ruling opens door to Wikileaks' Assange being extradited to US

12/10/21 3:07 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

Al Unser, four-time Indy 500 winner, dead at 82

12/10/21 12:52 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

BREAKING NEWS: Demaryius Thomas, former NFL receiver, dead at 33

12/09/21 11:11 PM

New best story on Hacker News: YouTube suspended my account for posting DeFi hackathon video

YouTube suspended my account for posting DeFi hackathon video
579 by thijser | 345 comments on Hacker News.
I knew Google's automated processes were pretty bad from earlier stories here, but today I got hit by it myself. I participated in the totally legit EthGlobal "Hack Money" hackathon ( https://ift.tt/3c6VSHN ) earlier this year and one of required submissions of that event was a video describing your work. I made one and uploaded it to Youtube. The hackathon went great and we won some prizes but that's not relevant to this story. Yesterday evening I received an email from Youtube that they've removed my channel because "Spam, scams or commercially deceptive content are not allowed on YouTube.". I thought this certainly must be an error so I used the attached appeal link and got a response within less than 15 minutes that they appeal has been rejected and that no further replies will be processed. I am a paid Youtube Music subscriber and I can't login to even listen to my own music anymore. Amazing. I would like to think that Google's AI systems are smarter than just videoTitle.contains("hack") && videoTitle.contains("money"), but apparently not. If anybody has connections who can help get me unsuspended that would be highly appreciated. The google cache of my channel is still available here: https://ift.tt/3ouRFad...

Fox News Breaking News Alert

Fox News Breaking News Alert

Biden administration makes big move ahead of 2022 Winter Olympics in Beijing

12/06/21 11:24 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

Jussie Smollett takes the stand in Chicago

12/06/21 10:14 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

Big-city mayor announces vaccine mandate for private sector workers

12/06/21 6:26 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

Burma’s Aung San Suu Kyi gets 4 years in prison on first charges against her

12/05/21 11:07 PM

Fox News Breaking News Alert

Fox News Breaking News Alert

Jennifer, James Crumbley plead not guilty to involuntary manslaughter charges after school shooting

12/04/21 6:46 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

Parents of Michigan school shooting suspect make first court appearance after overnight apprehension

12/04/21 6:32 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

Parents of Michigan shooting suspect nabbed in Detroit after frantic search

12/03/21 11:11 PM

Fox News Breaking News Alert

Fox News Breaking News Alert

Charges filed against Michigan school shooting suspect's parents

12/03/21 9:09 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

WATCH LIVE: Biden reacts to November jobs report that missed expectations

12/03/21 7:46 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

November jobs report misses expectations big-time

12/03/21 5:40 AM

New best story on Hacker News: Ask HN: What are these low quality “code snippet” sites?

Ask HN: What are these low quality “code snippet” sites?
563 by endofreach | 309 comments on Hacker News.
Whenever i am trying to google a code issue i have, there is countless low quality sites just showing SO threads with no added value whatsoever. It is so annoying it actually drives me mad. Does anyone know what's up with that? I am really disappointed because the guys creating these sites (i guess for some kind of monetization) must have some relation to coding. But i feel this is an attack against all of us. Every programmer should be grateful for the opportunity to find good quality content quickly. Now my search results are flooded with copy & paste from SO. They are killing that. Am I the only one experiencing this or being that annoyed by it? P.S: I don't name URLs because if you don't know what I am talking about already, you probably don't have that issue.

Fox News Breaking News Alert

Fox News Breaking News Alert

Lawmakers react to Mississippi abortion case before Supreme Court

12/02/21 8:27 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

EXCLUSIVE: Waukesha parade suspect breaks silence in jailhouse interview

12/01/21 1:33 PM

Fox News Breaking News Alert

Fox News Breaking News Alert

First case of COVID-19 omicron variant found in US, official says

12/01/21 10:53 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

LISTEN LIVE: Supreme Court hears oral arguments in potentially landmark abortion case

12/01/21 7:02 AM

Fox News Breaking News Alert

Fox News Breaking News Alert

What to know about pivotal abortion case going before Supreme Court today

12/01/21 4:15 AM