Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

91–100 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#91

Earlier quoted context omitted.

From my interaction with LastPass support (I'm a premium user), they've outsourced to some cheap company where agents have no clue how anything works. It took weeks to get through to somebody who even understands the problem and their reply was essentially "yeah we know it's broken, it's broken because of security". Left a really bad taste in my mouth. I wouldn't be using them at all if I didn't have to for a client.

I remember reading a blog entry, a few years ago. Someone received a phishing email from "their bank." They responded to the email, and got someone on the horn, immediately. But their bank (the real one), sent them to a horrifying voice jail. The point was that the crooks gave better customer service than the real bank.

Barclays recently tried sending me a new credit card because they were changing to Mastercard or something.

I got an email one day that my new Barclaycard was activated. Called support, and they swore to me it was a phishing email (it was definitely from Barclay's official domain). Would not listen to me at all and kept trying to get me to hang up. I asked if I could tell them the email MessageID and they could verify the authenticity. They said no.

About 10 minutes into trying to convince them it was not a phishing email, I refresh my dashboard and there was a $600 purchase at a Long Island Walmart. That shut them up really quickly and they transferred me to their fraud department who asked me for the MessageID at the bottom of the activation email and confirmed it was real...

I asked if I could set up any additional security, and how could they activate a new credit card? Did they have my online password? Apparently no, you can just call on the phone and activate it, no authentication required. They told me I could set up a "voice password" for my account for all phone support and I did just that.

I called them back 30 minutes later, got through to support to where I could change anything about my account. Asked them if my "Voice Password" was enabled. "Yes it is." "....Okay, no one has asked me for my voice password yet, and here you are about to change my address". They still didn't really understand the seriousness, so I told them "I'm not I'm a hacker trying to steal his money." and they understood.

The worst part? I couldn't cancel that credit card until they physically sent me one to activate. No way to visit a branch and get one. It ended up getting stolen out of the mail THREE TIMES before they finally sent it with a signature required.

Re: Ask HN: How did my LastPass master password get leaked?

#92
Reading the comments here there's one possibility that I haven't seen mentioned in that there may be an issue with lastpass allowing some level of access into people's accounts without actually having the password (which wouldn't enable the attacker to access the encrypted data).

Re: Ask HN: How did my LastPass master password get leaked?

#93
post #71

Earlier quoted context omitted.

Not sure it's really in Brazil. LACNIC says the IP range was transferred to AFRINIC. They then say that it is owned by: Affiliated Computing Services (Pty) Ltd descr: P. O. Box 261333 descr: Excom 2023 country: ZA But then further note that ownership is in dispute! We need someone to look it up in the current routing tables to see where it's presently being routed to.

I also saw that very weird thing -- Brazil vs AFRINIC. Help/insight from ASN? BGP? networking experts would be appreciated..! Thanks a lot

Perhaps this will help? https://bgpview.io/ip/160.116.88.235

Re: Ask HN: How did my LastPass master password get leaked?

#94

Earlier quoted context omitted.

There's a level of irony in complaining about LastPass's security, followed by suggestion people run their passwords through random third-party software that you wrote. Even if your code isn't malicious (which I believe), it opens up so many potential attack vectors. For anyone reading this, please use the official 1Password import functionality, not this: https://support.1password.com/import-lastpass/

There was no 1Password to LastPass importer at the time I wrote that (believe me, I looked because I have better things to do than write apps to benefit a commercial entity like agilebits otherwise), and of course the code is published on GitHub and released under the MIT license. It's very short and simple and rather easy to review. It's also a .NET executable, which is ridiculously easy to reverse-compile back to C…

Just because you put a warning label on a bad practice doesn't mean it's a good practice.

Pumping your passwords through some random code on Github that has a "be smart" label doesn't make it a good idea.

Would be so easy to imitate you, reupload the code with an exploit. For giggles, if I was making this into a hijack I'd leave all your warnings in and even make them bigger and more obvious, confident in the knowledge that 99%+ of my stolen users wouldn't read the code or would just download the binaries sight unseen.

Re: Ask HN: How did my LastPass master password get leaked?

#95
post #4

Since your master password is stored in another password manager, would it be accurate to say you copy/paste it into LastPass? If so, something running on your machine could be scraping your clipboard. This of course assumes that it wasn’t really you from an IP that was just misidentified as being from Brazil. For what it’s worth, I stopped using LastPass after they sold out to LogMeIn and would recommend others stop…

Of note, LastPass just announced that they are splitting out of LogMeIn and becoming independent again: https://blog.lastpass.com/2021/12/lastpass-investing-even-mo...

Of course, you must reduce the risk to the parent company before the huge disclosure comes out

Re: Ask HN: How did my LastPass master password get leaked?

#96
Given we’re likely stuck with passwords for the foreseeable future, I’d like to see two things in a password manager (maybe these exist?)

1. “hardware wallet” level security, with good UX. Maybe a USB/Lightning dongle, but I really wish computers/phones had built-in capability to do hardware wallets. Apple TouchBar got close (I realize it wouldn’t considered be a dedicated hardware wallet).

2. a way to automatically roll passwords periodically (with a small amount of user intervention, per requirement #1). This would require either some excellent AI or crowdsourced automations for every website.

Re: Ask HN: How did my LastPass master password get leaked?

#97

Earlier quoted context omitted.

That's really so strange. What is the probability that you, techknight (the other user in this thread) and me used the exact same compromised software back in ~2017 and had our master passwords stolen then? And for that person/bot (in Brazil) to try all of those master passwords now? It's beginning to look like this is a LastPass issue, no..?

LastPass was my first thought, but I couldn't find anyone else having the same issue and decided it couldn't possibly be them. Now I'm not sure! I've emailed you a list of the extensions I use in Chrome - if you want to share publicly any that we have in common I'm okay with that

Hey, thanks -- just replied to your email.

Since I haven't used this LastPass master password since 2017, I'd have to remember which extensions I had back then, which is hard to do...

I may have had 1Password and Adblock Plus which you had/have too.

But it's hard to say. It's a possible vector (that you, dogman123 and I had the same compromised extensions) but also... why would the hackers have sat on our master passwords for nearly 4 years (in my case)?

Re: Ask HN: How did my LastPass master password get leaked?

#99

This just happened to me today, but login location was Bangkok. I also haven’t used my lastpass account in almost 2 years since I switched to Bitwarden, so no way this could have stolen from my computer recently

I too moved to bitwarden a year or so ago. Kept my lastpass account around just in case. This post inspired me to finally delete it for good.

Re: Ask HN: How did my LastPass master password get leaked?

#100

Yeah me too. Same IP range too, but location listed as Toronto. Not that this means anything.

Wait sorry, this might be actually critically important.

When you say same IP range, what do you mean? The IP that the login attempt happened from starts with 160.?

If 4 of us (in this thread) all had quasi-successful login attempts to our accounts, it could mean that some LastPass master passwords have been leaked...?? Or LastPass has been compromised?

Post reply on HN