Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

271–280 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#271

Earlier quoted context omitted.

> There was no 1Password to LastPass importer at the time I wrote that The details were hazy, but in 2016, there was a way to export your passwords from LastPass and import them into 1Password, though I don't think there was a way to do so on windows (which I believe is what your importer addresses). After LastPass vulnerability in July 2016, I switched to 1Password.

There is, I just did it recently. It's an unncrypted copy paste dump from lastpass into 1password

This was in reference to the OP not having an option in 2017 to import to 1pass.

If I recall, I had to sign up for LastPass premium to pull my passwords to my phone, and then use keychain to import them to 1pass.

I don't think that solution would work for Windows users back in 2016.

Re: Ask HN: How did my LastPass master password get leaked?

#272
post #269

Earlier quoted context omitted.

My master password, and whole account, was definitely from 2017. Which 2017 breach are you referring to? This? https://www.theguardian.com/technology/2017/mar/30/lastpass-...

Yes, my bad,it's technically not a breach, since in theory it was never exploited.

No, it's super interesting.

So presumably back in 2017, the vulnerability was found but considered to be un-exploited, but it's maybe turning out that our master passwords did get breached back then and laid dormant for a few years, to be finally used just now?

Re: Ask HN: How did my LastPass master password get leaked?

#273

Just happened to me one hour ago and got scared shitless. Time Monday, December 27, 2021 at 3:50 PM EST Location UNITED STATES IP address 107.173.195.83 Actions taken, in this order: - Head to *Advanced Options* -> *View account history* to see if anything suspicious is going on (nothing so far) - Disable Lastpass MFA and use Google Authenticator (Authy) - *Account Settings* -> click on *Show Advanced Settings* -> *D…

- Disable Lastpass MFA and use Google Authenticator (Authy) could you please explain this point? Isn't LastPass Authenticator equivalent to Google Authenticator, Authy or any other TOTP app? Or is there something that makes it less secure than other apps? Perhaps because it has cloud backups?

When you do authy (or google auth) it will generate a new set of keys for you and shutdown any old ones associated with the lastpass stuff thus making the old keys useless. Also obviously he should change his master password to a new one.

Re: Ask HN: How did my LastPass master password get leaked?

#274

Earlier quoted context omitted.

There was no 1Password to LastPass importer at the time I wrote that (believe me, I looked because I have better things to do than write apps to benefit a commercial entity like agilebits otherwise), and of course the code is published on GitHub and released under the MIT license. It's very short and simple and rather easy to review. It's also a .NET executable, which is ridiculously easy to reverse-compile back to C…

Clearly we both agree it's an insecure practice, since you felt it needed a warning. Now that you know there's an official LastPass importer for 1Password, I'm curious why you're defending your version rather than updating your blog post, unlinking your original HN comment and deprecating the GitHub repo. I believe you're genuine and just trying to help. If there's an attack, it wouldn't be you doing it – it'd be som…

I agree that's the right response, maybe just give them some time to consider it. It can be tough to give up something you worked on.

Re: Ask HN: How did my LastPass master password get leaked?

#276

Earlier quoted context omitted.

Is this all today? Also did you check account history on your LastPass before asking for account deletion?

Yes just checked earlier when I saw activity here. Ive actually been getting reports for a few days about accounts being in a breach from iOS and Google and I have diligently changed my passwords. Then looked at the old Evernote account and saw logins from Brazil and India. I use 2FA everywhere important but if this master is compromised then it’s all over. I cant delete my Lastpass account it is controlled by the or…

Did you have country restrictions enabled? That seems to have (temporarily) saved a few people here

Re: Ask HN: How did my LastPass master password get leaked?

#278

Earlier quoted context omitted.

1Password allows you to use a local vault, encrypted with a master password, that can be synced across devices in multiple ways, for instance using Dropbox. There's no web logins going, no 'someone elses database' accessed over the web. I have used this solution for a number of years, and would _never_ go for a cloud option like lastpass, for important personal data.

I see no big diff actually. It offers you no more security if you're directly compromised. It also doesn't help much in reducing the risk of the 3rd party services being hacked, as your data still travels through someone else's cloud. The one attack you avoid by it is LastPass being hacked and your encrypted vault stolen - but then you also open up yourself for Dropbox being hacked and your data stolen attack (which…

There is a fairly big difference, you are decrypting a local file using a master password NOT stored on the internet. No data is going over the wire, no 'other peoples computers'.

Even if someone got your vault file, with a _very strong_ master password it's just not going to get brute forced any time soon. [1]

With an online-only solution you have no idea how they are storing your data. I think 1p local vault (only) with db sync with an extremely strong master pw is adequate, but indeed for most use cases, it could be better to simply one-way sync from your main computer to your mobile device with something like Resilio Sync and avoid Dropbox entirely.

I cannot bring myself to trust any online service with this kind of data. Nobody is getting my master password without hacking my machine, brain, or government backdoor. There is a lot of peace of mind to be had with a local system IMO.

[1] https://support.1password.com/pbkdf2/

Re: Ask HN: How did my LastPass master password get leaked?

#279

Earlier quoted context omitted.

There was no 1Password to LastPass importer at the time I wrote that (believe me, I looked because I have better things to do than write apps to benefit a commercial entity like agilebits otherwise), and of course the code is published on GitHub and released under the MIT license. It's very short and simple and rather easy to review. It's also a .NET executable, which is ridiculously easy to reverse-compile back to C…

> There was no 1Password to LastPass importer at the time I wrote that The details were hazy, but in 2016, there was a way to export your passwords from LastPass and import them into 1Password, though I don't think there was a way to do so on windows (which I believe is what your importer addresses). After LastPass vulnerability in July 2016, I switched to 1Password.

Password managers generally use CSV, avoiding vendor lock-in. However, back when Lastpass doubled their subscription cost (yes, doubled, literally) I switched to Bitwarden. At that point, there was some issue with exporting passwords with a certain character (IIRC it was ; or #). I ended up changing the few passwords which quit working.

As for OP, my take is you clicked a bad link triggering a zero day vulnerability in your browser, or perhaps you logged in on Lastpass via a VPN or Tor? Its pure speculation though.

Re: Ask HN: How did my LastPass master password get leaked?

#280

Earlier quoted context omitted.

This is my worst nightmare and I wonder what the order of operations is in terms of downloading and unlocking a vault. This sounds like you need the master password to download and unlock the vault, so that’s a tiny bit of extra protection I guess (not much). I wonder if password managers should be designed around, and encourage the use of, an undocumented PIN that’s appended to every stored password. You could use t…

Can't use the same PIN as a hacker would just add myhackurl.com/login to your vault and see what the PIN came across as. I think you'd also run into issues with password length as a lot of sites still have a restriction. I like the idea though and maybe a different implementation could work.

I mean a PIN that's not stored in the vault or auto-filled. It would be something extra that you add manually after the password manager fills in the password

So the password manager would put in 'password' and I'd manually type '1234' to make it 'password1234'.

Post reply on HN