Does lastpass have a login history? first thing would be to check if the mail is genuine
Ask HN: How did my LastPass master password get leaked?
51–60 of 529 posts
Re: Ask HN: How did my LastPass master password get leaked?
#52Re: Ask HN: How did my LastPass master password get leaked?
#53Earlier quoted context omitted.
Thanks Sending emails to support@lastpass.com doesn't work ("This inbox is not monitored") and I have to upgrade my account to contact their support, which I'll do right away. EDIT: after checking, the login attempt does appear in my Account History (my original email said it didn't -- I wasn't looking in the right place)
I suspect that it was a random phishing attempt. > Login attempt blocked > Hello, Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look. Looks fairly classic. Might want to look at the email headers, to see if it really came from LastPass. I get about ten of these a day. Some are scarily w…
Re: Ask HN: How did my LastPass master password get leaked?
#54Re: Ask HN: How did my LastPass master password get leaked?
#55Hey, this _just_ happened to me too....my password would be near impossible to guess and is not used elsewhere... Just deleted my last pass account! here's the info that came with the email Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235
WHAT!! Same IP range for me. How is this possible????
Re: Ask HN: How did my LastPass master password get leaked?
#56Earlier quoted context omitted.
Bitwarden is great, highly recommend, it's open-source which adds to its trustworthiness and has a good track record of respecting users.
+1, you can host your own server as well https://github.com/dani-garcia/vaultwarden
Re: Ask HN: How did my LastPass master password get leaked?
#57Earlier quoted context omitted.
WHAT!! Same IP range for me. How is this possible????
not sure, but this seems pretty bad! fwiw, i haven't used lastpass in at least a year. i've been using 1password.
Re: Ask HN: How did my LastPass master password get leaked?
#58Earlier quoted context omitted.
Yes, I do copy/paste from my local password manager. A clipboard scraper is a possibility, yes. I hadn't logged into that LastPass account for years, so it's definitely not me who attempted to login earlier. Re: LastPass, is there another cloud-based tool that's generally considered as more trustworthy? Bitwarden? Thanks
Personally I just stick to local Keepass database files. I’ve never ventured into the cloud based services. If you are really worried about it, do you really need to use a cloud based password service? Sure, managing the KeePass files by hand is certainly more cumbersome, but to me it’s worth it for the security/ peace of mind gains. I have never put my DB or key files in the cloud. And when I need to sync them up ov…
It sounds a bit complicated reading this back, but in reality it's pretty straightforward.
Re: Ask HN: How did my LastPass master password get leaked?
#59Earlier quoted context omitted.
After a bit of searching, I wasn't able to find any PHP forum software that LastPass lets you log in to. I could only find one official-seeming forum, and it uses a different login. So, I think this is FUD... I don't use LastPass, but accusing them of something like this (and using the phrase "or whatever") is pretty serious without proof.
They appear to have sunset their phpBB instance. It was the main hub and support portal on their website with up to thousands of active visitors at any given time. You can see it archived here: https://web.archive.org/web/20150629081250/https://forums.la... Here's the archived phpBB login page. It asks for your LastPass login and password (not your forum account, your actual LastPass login and actual LastPass master…
Re: Ask HN: How did my LastPass master password get leaked?
#60Look at the email headers and post them here. Was the email actually from lastpass????!!!
So in this case, it's not a phishing attempt unfortunately.