Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> What’s the best way to delete an account? Overwrite all password values? Wait a month, overwrite again, wait a month, delete?

The only sensible approach is to change every password on every site that you’ve ever stored credentials in LastPass for. Any attempt to change the passwords is just hoping hay their backups are better secured than their prod database (they are almost certainly not), and also that the data wasn’t popped before you changed them (which they almost certainly were, probably multiple times).

Delete your account, but revoke/update all those passwords asap as well. Since the site/url and email addresses were not encrypted, I’d be changing the email address on at least critical accounts as well where I can.



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: