Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

201–210 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#201

I got the same thing in the last month. Then my bank account had 7 transactions from ali express about a week later. Nine were mine. I deleted everything in lastpass and deleted my account.

Nine out of seven? How does that work?

Re: Ask HN: How did my LastPass master password get leaked?

#202
post #163

May be a dumb question, but how much are we trusting Lastpass that whoever tried these logins actually used the correct master password? The posted statements sound a bit ambiguous, maybe they're mistaken? Does it show as a login attempt if somebody uses your correct account email address and the wrong password? Of course if Lastpass is sending ambiguous or mistaken communication about whether someone else has your m…

Unfortunately, the email sent from LastPass specifically says "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" LastPass support did confirm that the IP from Brazil did have the master password. I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the mas…

I thought that LastPass didn't send your master password over the wire, rather it uses client-side code to take your Master Password and turn it into a hash which is then sent to LastPass for comparison[1]. If that is the case, how can LastPass claim to know that your master password was used? At best, they can claim that the hash sent to the server matches your password's hash but that is not the same as your master password being used.

Given the widespread nature of this issue, I'd guess someone has discovered a flaw in the LastPass login process which is allowing a bad hash to pass the master password hash check: that contradicts what the support agent said, but I'd assume they're mistaken, rather than LastPass are lying in their documentation about how their system works.

[1] https://support.logmeininc.com/lastpass/help/about-password-...

Re: Ask HN: How did my LastPass master password get leaked?

#203
I see a lot of people suggesting other password managers, so I was wandering am I the only one who uses google's? I've used lastpass briefly but it was pretty buggy and didn't feel like it was worth the price. Google (Chrome) password manager is free, and recently got a native autofill for android, which works flawlessly, compared to others.

Re: Ask HN: How did my LastPass master password get leaked?

#204

Just happened to me one hour ago and got scared shitless. Time Monday, December 27, 2021 at 3:50 PM EST Location UNITED STATES IP address 107.173.195.83 Actions taken, in this order: - Head to *Advanced Options* -> *View account history* to see if anything suspicious is going on (nothing so far) - Disable Lastpass MFA and use Google Authenticator (Authy) - *Account Settings* -> click on *Show Advanced Settings* -> *D…

This is my worst nightmare and I wonder what the order of operations is in terms of downloading and unlocking a vault. This sounds like you need the master password to download and unlock the vault, so that’s a tiny bit of extra protection I guess (not much).

I wonder if password managers should be designed around, and encourage the use of, an undocumented PIN that’s appended to every stored password. You could use the same PIN for everything and if someone got your vault decrypted there would at least be a chance they didn’t get the secondary PIN too.

Re: Ask HN: How did my LastPass master password get leaked?

#205

Just happened to me one hour ago and got scared shitless. Time Monday, December 27, 2021 at 3:50 PM EST Location UNITED STATES IP address 107.173.195.83 Actions taken, in this order: - Head to *Advanced Options* -> *View account history* to see if anything suspicious is going on (nothing so far) - Disable Lastpass MFA and use Google Authenticator (Authy) - *Account Settings* -> click on *Show Advanced Settings* -> *D…

You received a "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email? And your master password was secure/not used anywhere else, etc.? Did we all (that's 8 of us now in the thread) get compromised a few years ago (using the LastPass extension?) and someone just mass attempted to try all of those passwords..? Edit: since you're tracking IPs found…

"Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look."

Could be... I haven't rotated my password in a while. Could you link me to more info about the LastPass compromise that you mentioned?

p.s. My master password is definitely not dictionary material, and it's not used anywhere else, so I am 100% sure it's not a bruteforce / phishing attempt.

Re: Ask HN: How did my LastPass master password get leaked?

#206
Same issue for me.

Time Monday, December 27, 2021 at 3:55 PM EST

Location UNITED STATES

IP address 154.202.117.78

Password is only used for lastpass. It was caught since I use 2FA. I did previously have "The Great Suspender" chrome extension, which changed hands and had an update including malware, I wonder if this was the culprit.

I last changed my master password on November 24, 2017, the previous exploit was apparently resolved in July 2016.

Re: Ask HN: How did my LastPass master password get leaked?

#207

Earlier quoted context omitted.

Unfortunately, the email sent from LastPass specifically says "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" LastPass support did confirm that the IP from Brazil did have the master password. I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the mas…

I thought that LastPass didn't send your master password over the wire, rather it uses client-side code to take your Master Password and turn it into a hash which is then sent to LastPass for comparison[1]. If that is the case, how can LastPass claim to know that your master password was used? At best, they can claim that the hash sent to the server matches your password's hash but that is not the same as your master…

Very interesting theory!

What's a bit surprising is how "low effort" the rest of the attack was: presumably if they found this flaw to bypass passwords, they then attempted to login (which caused an email to be sent out), but LastPass stopped them because they (i.e. the folks on the Brazil IP range) were logging in from a new IP.

So this would be a case of one protective layer (the new IP detection) compensating for a vulnerability in the other one (the password protection).

That would be "re-assuring" in a certain way (as the passwords themselves did not leak -- presumably!).

Thanks

Re: Ask HN: How did my LastPass master password get leaked?

#208

Just got the same notification 2 hours ago, from IP address 107.173.195.213

Did your email say "Someone just used your master password to try to log in to your account from a device or location we didn't recognize"?

Just trying to verify that we're all concerned with the same problem.

Thank you

Re: Ask HN: How did my LastPass master password get leaked?

#209
I might be overreacting but if it’s true then it’s bad. Ive Been getting reports from my devices that all my accounts had been leaked in a data breach and I was thinking whaaa? What all of them? Wait a minute! Some of which I had generated complex long passwords for in Lastpass and even I didn’t know what the password was. So this fits.

My Evernote account which I don’t use any more is showing logins from Brazil. I’ve disabled and asked for an count deletion. Ive got a bad feeling about this.

Re: Ask HN: How did my LastPass master password get leaked?

#210
post #83

Earlier quoted context omitted.

They appear to have sunset their phpBB instance. It was the main hub and support portal on their website with up to thousands of active visitors at any given time. You can see it archived here: https://web.archive.org/web/20150629081250/https://forums.la... Here's the archived phpBB login page. It asks for your LastPass login and password (not your forum account, your actual LastPass login and actual LastPass master…

Unless I’m misremembering, the login to their general system was done by never sending the password over the wire. Instead they used js to do some sort of hashing type system locally. But during the heartbleed attack when their systems were shown to be vulnerable, that was one of their arguments as to why it wasn’t so bad.

They pretty heavily fumbled exactly this heartbleed response too. They claimed they "weren't vulnerable" because of this setup but they clearly were. If you exfiltrated an SSL key, which heartbleed allowed, you can serve whatever JS (including JS that just explicitly exfiltrated your passphrase) you wanted to end users.

LastPass is full of clowns. There's already two examples of their cavalier approach to what should be simple security in this thread and I'm pretty sure there are more.

Post reply on HN