Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

11–20 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#11
post #3

My bet would be on malware or compromised browser extension. You probably typed (or copy/pasted) the password ans something kept a copy along the way.

Compromised browser extension could make sense, aye. Do Chrome extensions have access to the file system too? Is there a chance my local KeePassX file has been siphoned off? Thanks

I don't think that's possible, more likely an extension that has access to the login form of lastpass

Re: Ask HN: How did my LastPass master password get leaked?

#12
post #4

Since your master password is stored in another password manager, would it be accurate to say you copy/paste it into LastPass? If so, something running on your machine could be scraping your clipboard. This of course assumes that it wasn’t really you from an IP that was just misidentified as being from Brazil. For what it’s worth, I stopped using LastPass after they sold out to LogMeIn and would recommend others stop…

Yes, I do copy/paste from my local password manager. A clipboard scraper is a possibility, yes. I hadn't logged into that LastPass account for years, so it's definitely not me who attempted to login earlier. Re: LastPass, is there another cloud-based tool that's generally considered as more trustworthy? Bitwarden? Thanks

Bitwarden is great, highly recommend, it's open-source which adds to its trustworthiness and has a good track record of respecting users.

Re: Ask HN: How did my LastPass master password get leaked?

#13
Without knowing anything about LastPass, a few ideas come to mind. First, is your master password only something that exists in your head? Or is it written down anywhere else either digitally or physically. If so, someone may have gained access to that. Did you use the same password anywhere else, ever? If so, it could have been in a database of possible passwords that someone used to try to brute force a copy of your KeePassX file, and succeeded. Also possible liabilities for brute force attacks are using a password that contains some kind of facts or information related to you, such as a birthday, loved one's name, address, etc, etc.

The other possibility that comes to mind is a man in the middle attack of your password was ever sent over the wire with zero or weak encryption, when someone was snooping, like on coffee shop wifi or even a nosy neighbor on your home wifi.

Re: Ask HN: How did my LastPass master password get leaked?

#14
post #13

Without knowing anything about LastPass, a few ideas come to mind. First, is your master password only something that exists in your head? Or is it written down anywhere else either digitally or physically. If so, someone may have gained access to that. Did you use the same password anywhere else, ever? If so, it could have been in a database of possible passwords that someone used to try to brute force a copy of you…

Thanks -- this specific master password was only stored in another, offline, password manager.

The specific password was computer generated, and I have not used it anywhere else i.e. it was only created for this LastPass account.

That's why this (probably) either means that my local password manager has been compromised (catastropic if true) or that the info I received from LastPass is not completely accurate..?

Re: Ask HN: How did my LastPass master password get leaked?

#15
post #11

Earlier quoted context omitted.

Compromised browser extension could make sense, aye. Do Chrome extensions have access to the file system too? Is there a chance my local KeePassX file has been siphoned off? Thanks

I don't think that's possible, more likely an extension that has access to the login form of lastpass

Got it, thanks. And yes, you're right, after checking, Chrome extensions don't have access to local files by default. I checked all of the extensions I have (after disabling them all) and none had "file access" enabled.

Re: Ask HN: How did my LastPass master password get leaked?

#16

Because LastPass is beyond stupid and uses your master password to log in to their bbulletin or whatever php forum. That’s what got me to write and publish this: https://neosmart.net/blog/2017/a-free-lastpass-to-1password-... EDIT: "or whatever" means I couldn't remember the name of the php forum notorious for its insecurity, I thought it was something like 'bbulletin'. It was phpBB.

Sorry, what do you mean by "to log in to their bbuletin or whatever php forum"? According to LastPass, they don't have access to the master password // presumably it's not stored on their side. Is that accurate..? Thanks

I don’t use Lastpass, but if what you are saying is correct, they could not have sent the OP an e-mail (assuming it’s legit) informing them of the attempt to sign in using the master pass from Brazil, right?

Re: Ask HN: How did my LastPass master password get leaked?

#18

Because LastPass is beyond stupid and uses your master password to log in to their bbulletin or whatever php forum. That’s what got me to write and publish this: https://neosmart.net/blog/2017/a-free-lastpass-to-1password-... EDIT: "or whatever" means I couldn't remember the name of the php forum notorious for its insecurity, I thought it was something like 'bbulletin'. It was phpBB.

Sorry, what do you mean by "to log in to their bbuletin or whatever php forum"? According to LastPass, they don't have access to the master password // presumably it's not stored on their side. Is that accurate..? Thanks

After a bit of searching, I wasn't able to find any PHP forum software that LastPass lets you log in to. I could only find one official-seeming forum, and it uses a different login. So, I think this is FUD... I don't use LastPass, but accusing them of something like this (and using the phrase "or whatever") is pretty serious without proof.

Re: Ask HN: How did my LastPass master password get leaked?

#19
post #4

Since your master password is stored in another password manager, would it be accurate to say you copy/paste it into LastPass? If so, something running on your machine could be scraping your clipboard. This of course assumes that it wasn’t really you from an IP that was just misidentified as being from Brazil. For what it’s worth, I stopped using LastPass after they sold out to LogMeIn and would recommend others stop…

Why do you recommend others to stop using LastPass?

https://en.wikipedia.org/wiki/LastPass#Security_issues

Re: Ask HN: How did my LastPass master password get leaked?

#20
post #4

Since your master password is stored in another password manager, would it be accurate to say you copy/paste it into LastPass? If so, something running on your machine could be scraping your clipboard. This of course assumes that it wasn’t really you from an IP that was just misidentified as being from Brazil. For what it’s worth, I stopped using LastPass after they sold out to LogMeIn and would recommend others stop…

Yes, I do copy/paste from my local password manager. A clipboard scraper is a possibility, yes. I hadn't logged into that LastPass account for years, so it's definitely not me who attempted to login earlier. Re: LastPass, is there another cloud-based tool that's generally considered as more trustworthy? Bitwarden? Thanks

I use 1Password, seems alright security wise, won’t definitely say one way or the other, but you could DYOR on it.
Post reply on HN