Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

61–70 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#62
post #27

Earlier quoted context omitted.

Yes, I do copy/paste from my local password manager. A clipboard scraper is a possibility, yes. I hadn't logged into that LastPass account for years, so it's definitely not me who attempted to login earlier. Re: LastPass, is there another cloud-based tool that's generally considered as more trustworthy? Bitwarden? Thanks

Personally I just stick to local Keepass database files. I’ve never ventured into the cloud based services. If you are really worried about it, do you really need to use a cloud based password service? Sure, managing the KeePass files by hand is certainly more cumbersome, but to me it’s worth it for the security/ peace of mind gains. I have never put my DB or key files in the cloud. And when I need to sync them up ov…

I absolutely agree. I love KeePass and use it for everything... this LastPass account was setup to share passwords with others at an org that I worked at.

The problem is... that LastPass password, the one stored in KeePass, is presumably the one that was leaked.

Which is what is spooking me -- if someone has access to my entire KeePass file, it's game over.

Re: Ask HN: How did my LastPass master password get leaked?

#64

Hey, this _just_ happened to me too....my password would be near impossible to guess and is not used elsewhere... Just deleted my last pass account! here's the info that came with the email Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235

WHAT!! Same IP range for me. How is this possible????

[deleted]

Re: Ask HN: How did my LastPass master password get leaked?

#65

This just happened to me today, but login location was Bangkok. I also haven’t used my lastpass account in almost 2 years since I switched to Bitwarden, so no way this could have stolen from my computer recently

Can you please post more information?

Was this an old LastPass account? You didn't use this master password elsewhere, etc.?

Thanks!

Re: Ask HN: How did my LastPass master password get leaked?

#66

Earlier quoted context omitted.

not sure, but this seems pretty bad! fwiw, i haven't used lastpass in at least a year. i've been using 1password.

How old approximately was your account? I used my master password the last time in 2017... were our master passwords compromised back then... and someone held on to them for that long? That seems improbable?

just checked my email. last pass account was created in 2015, not sure if the current leaked password has been in use that whole time, but it has definitely been quite a few years. moved over to 1passward in march of this year and likely have not used last pass at all since.

Re: Ask HN: How did my LastPass master password get leaked?

#67

Earlier quoted context omitted.

Thanks Sending emails to support@lastpass.com doesn't work ("This inbox is not monitored") and I have to upgrade my account to contact their support, which I'll do right away. EDIT: after checking, the login attempt does appear in my Account History (my original email said it didn't -- I wasn't looking in the right place)

I'm pretty sure you can get a full login attempt history from them in the ui - can't verify though, don't use LP anymore. Try a bogus attempt yourself with wrong PW, or from a cloud host/vpn/etc to verify the audit log you can access. Assuming it does list your attempts, then yeah, it would have to be phishing/lp bug.

Yeah, thanks, I was finally able to find my Account History, and the foiled login from Brazil does appear there. So it seems like the email wasn't phishing.

Re: Ask HN: How did my LastPass master password get leaked?

#68
post #4

Since your master password is stored in another password manager, would it be accurate to say you copy/paste it into LastPass? If so, something running on your machine could be scraping your clipboard. This of course assumes that it wasn’t really you from an IP that was just misidentified as being from Brazil. For what it’s worth, I stopped using LastPass after they sold out to LogMeIn and would recommend others stop…

Yes, I do copy/paste from my local password manager. A clipboard scraper is a possibility, yes. I hadn't logged into that LastPass account for years, so it's definitely not me who attempted to login earlier. Re: LastPass, is there another cloud-based tool that's generally considered as more trustworthy? Bitwarden? Thanks

1Password has a cloud-based option these days, for better or worse.

Re: Ask HN: How did my LastPass master password get leaked?

#69

Earlier quoted context omitted.

How old approximately was your account? I used my master password the last time in 2017... were our master passwords compromised back then... and someone held on to them for that long? That seems improbable?

just checked my email. last pass account was created in 2015, not sure if the current leaked password has been in use that whole time, but it has definitely been quite a few years. moved over to 1passward in march of this year and likely have not used last pass at all since.

That's really so strange.

What is the probability that you, techknight (the other user in this thread) and me used the exact same compromised software back in ~2017 and had our master passwords stolen then? And for that person/bot (in Brazil) to try all of those master passwords now?

It's beginning to look like this is a LastPass issue, no..?

Re: Ask HN: How did my LastPass master password get leaked?

#70

Because LastPass is beyond stupid and uses your master password to log in to their bbulletin or whatever php forum. That’s what got me to write and publish this: https://neosmart.net/blog/2017/a-free-lastpass-to-1password-... EDIT: "or whatever" means I couldn't remember the name of the php forum notorious for its insecurity, I thought it was something like 'bbulletin'. It was phpBB.

Is there an official counter for phpBB RCEs/vulnerabilities that revealed user passwords? This has been going on for decades now. It's getting ridiculous.
Post reply on HN