Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

1–10 of 529 posts

Ask HN: How did my LastPass master password get leaked?

#1
Hi,

I've just had a bizarre thing happen and wanted to see if the HN community could come up with some theories as to what happened.

LastPass blocked a login attempt from Brazil (it wasn't me). According to an email I received from LastPass, this login was using the LastPass account's master password. The email doesn't look like it's a phishing attempt.

What troubles me is that the master password was stored in a local encrypted KeePassX file.

I can imagine that someone has my KeePassX file and the (completely different) password to this file. If that's the case, I'm in a world of hurt.

But are there any other possibilities? Is the email from LastPass accurate i.e. was the login attempt actually using my master password? Is there some LastPass extension installed on some computer still having a valid auth token allowing them to login as me to LastPass..?

I'm really confused, and scared.

Thanks for your help.

P.S. The LastPass account had 2FA set up, but I was able to simply remove it (since I didn't have access to the token anymore). That's scary too -- what's the point of a 2FA you can remove...??

---

Update:

- the email was truly not phishing -- the same information regarding the login attempt appears in my LastPass dashboard. I also talked to LastPass support over the phone, and they confirmed seeing the same information.

- There are 2 separate users in the thread below confirming that the same exact same thing happened to them, from the exact same IP range as me.

Either the 3 of us had the same malware/Chrome extension or somehow had our master passwords compromised...? Or...? Is this a LastPass issue?

Re: Ask HN: How did my LastPass master password get leaked?

#2
I'd get in touch with LastPass support asap to see if they have a digital trail to help you figure out what happened.

I'd also guess the most plausible situation would be malware on your computer that managed to sniff your credentials in-transit/clipboard/memory/browser/keyboard and exfiltrate it to some shady folks.

Re: Ask HN: How did my LastPass master password get leaked?

#4
Since your master password is stored in another password manager, would it be accurate to say you copy/paste it into LastPass? If so, something running on your machine could be scraping your clipboard.

This of course assumes that it wasn’t really you from an IP that was just misidentified as being from Brazil.

For what it’s worth, I stopped using LastPass after they sold out to LogMeIn and would recommend others stop using it as well.

Re: Ask HN: How did my LastPass master password get leaked?

#5
post #2

I'd get in touch with LastPass support asap to see if they have a digital trail to help you figure out what happened. I'd also guess the most plausible situation would be malware on your computer that managed to sniff your credentials in-transit/clipboard/memory/browser/keyboard and exfiltrate it to some shady folks.

Thanks

Sending emails to support@lastpass.com doesn't work ("This inbox is not monitored") and I have to upgrade my account to contact their support, which I'll do right away.

EDIT: after checking, the login attempt does appear in my Account History (my original email said it didn't -- I wasn't looking in the right place)

Re: Ask HN: How did my LastPass master password get leaked?

#6
post #3

My bet would be on malware or compromised browser extension. You probably typed (or copy/pasted) the password ans something kept a copy along the way.

Compromised browser extension could make sense, aye.

Do Chrome extensions have access to the file system too? Is there a chance my local KeePassX file has been siphoned off?

Thanks

Re: Ask HN: How did my LastPass master password get leaked?

#7
Because LastPass is beyond stupid and uses your master password to log in to their bbulletin or whatever php forum.

That’s what got me to write and publish this: https://neosmart.net/blog/2017/a-free-lastpass-to-1password-...

EDIT: "or whatever" means I couldn't remember the name of the php forum notorious for its insecurity, I thought it was something like 'bbulletin'. It was phpBB.

Re: Ask HN: How did my LastPass master password get leaked?

#8
post #4

Since your master password is stored in another password manager, would it be accurate to say you copy/paste it into LastPass? If so, something running on your machine could be scraping your clipboard. This of course assumes that it wasn’t really you from an IP that was just misidentified as being from Brazil. For what it’s worth, I stopped using LastPass after they sold out to LogMeIn and would recommend others stop…

Yes, I do copy/paste from my local password manager. A clipboard scraper is a possibility, yes.

I hadn't logged into that LastPass account for years, so it's definitely not me who attempted to login earlier.

Re: LastPass, is there another cloud-based tool that's generally considered as more trustworthy? Bitwarden? Thanks

Re: Ask HN: How did my LastPass master password get leaked?

#9

Because LastPass is beyond stupid and uses your master password to log in to their bbulletin or whatever php forum. That’s what got me to write and publish this: https://neosmart.net/blog/2017/a-free-lastpass-to-1password-... EDIT: "or whatever" means I couldn't remember the name of the php forum notorious for its insecurity, I thought it was something like 'bbulletin'. It was phpBB.

Sorry, what do you mean by "to log in to their bbuletin or whatever php forum"?

According to LastPass, they don't have access to the master password // presumably it's not stored on their side. Is that accurate..?

Thanks

Re: Ask HN: How did my LastPass master password get leaked?

#10
post #4

Since your master password is stored in another password manager, would it be accurate to say you copy/paste it into LastPass? If so, something running on your machine could be scraping your clipboard. This of course assumes that it wasn’t really you from an IP that was just misidentified as being from Brazil. For what it’s worth, I stopped using LastPass after they sold out to LogMeIn and would recommend others stop…

Why do you recommend others to stop using LastPass?
Post reply on HN