Got the same but from NJ.
Just making sure we're all concerned with the same issue
Thanks!
211–220 of 529 posts
Got the same but from NJ.
Just making sure we're all concerned with the same issue
Thanks!
Earlier quoted context omitted.
What do you do for sites with strange password requirements, like 12 character max or requiring you to use a very specific set of special characters? I used to do what you described but my base password was rejected by far too many sites because of absurd (and insecure) requirements.
> requiring you to use a very specific set of special characters? Stupid requirements don't matter. If you have a secure password, e.g. a passphrase consisting of 7 random words (diceware) and the service complains that you're missing digits, uppercase, and symbols, then adding A0! to the passphrase does not make it less secure. Appending anything never makes it less secure. You can also write down in plain text and…
And while the 12 char max is (mostly) a thing of the past, I run into max char issues (usually around 24) far more than I should in 2021.
I might be overreacting but if it’s true then it’s bad. Ive Been getting reports from my devices that all my accounts had been leaked in a data breach and I was thinking whaaa? What all of them? Wait a minute! Some of which I had generated complex long passwords for in Lastpass and even I didn’t know what the password was. So this fits. My Evernote account which I don’t use any more is showing logins from Brazil. I’v…
Earlier quoted context omitted.
Completely agree. I did check and my Account History is showing the same info. I also talked to their support and they confirmed this info.
Where is LastPass's account history?
- In the sidebar that shows up, "View account history" -- it's in the middle of the page vertically
Make sure to use both "Logins" and "Events" when doing searches.
The "Login Verification Email Sent" (i.e. someone attempted to login with the correct master password) show up under Events.
I see a lot of people suggesting other password managers, so I was wandering am I the only one who uses google's? I've used lastpass briefly but it was pretty buggy and didn't feel like it was worth the price. Google (Chrome) password manager is free, and recently got a native autofill for android, which works flawlessly, compared to others.
The Chrome option is great at what it does, slightly limited, and not that customizable. Personally I also dislike password manager where the company making the manager also provides the cloud storage used to sync (encrypted) passwords between devices.
was it a login attempt or an actual login?
A login attempt without the 2fa token, failed with valid master password, so far a handful of others have reported it in this thread.
I was able to remove the 2fa by clicking a link that LastPass sent to my email (confirming that I wanted to remove the 2fa).
So if anyone has your LastPass master password and has access to your email, it's game over and having the 2fa enabled on the LastPass account won't do anything.
Earlier quoted context omitted.
You received a "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email? And your master password was secure/not used anywhere else, etc.? Did we all (that's 8 of us now in the thread) get compromised a few years ago (using the LastPass extension?) and someone just mass attempted to try all of those passwords..? Edit: since you're tracking IPs found…
"Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look." Could be... I haven't rotated my password in a while. Could you link me to more info about the LastPass compromise that you mentioned? p.s. My master password is definitely not dictionary material, and it's not used anywhere else, so…
The compromise was mentioned here: https://news.ycombinator.com/item?id=29707325
Just happened to me one hour ago and got scared shitless. Time Monday, December 27, 2021 at 3:50 PM EST Location UNITED STATES IP address 107.173.195.83 Actions taken, in this order: - Head to *Advanced Options* -> *View account history* to see if anything suspicious is going on (nothing so far) - Disable Lastpass MFA and use Google Authenticator (Authy) - *Account Settings* -> click on *Show Advanced Settings* -> *D…
This is my worst nightmare and I wonder what the order of operations is in terms of downloading and unlocking a vault. This sounds like you need the master password to download and unlock the vault, so that’s a tiny bit of extra protection I guess (not much). I wonder if password managers should be designed around, and encourage the use of, an undocumented PIN that’s appended to every stored password. You could use t…