Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

101–110 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#101
post #71

Earlier quoted context omitted.

Not sure it's really in Brazil. LACNIC says the IP range was transferred to AFRINIC. They then say that it is owned by: Affiliated Computing Services (Pty) Ltd descr: P. O. Box 261333 descr: Excom 2023 country: ZA But then further note that ownership is in dispute! We need someone to look it up in the current routing tables to see where it's presently being routed to.

I also saw that very weird thing -- Brazil vs AFRINIC. Help/insight from ASN? BGP? networking experts would be appreciated..! Thanks a lot

Far from an expert,but https://www.dan.me.uk/bgplookup lists it as owned by AS202769, which is apparently "Cooperative Investments LLC" Scamalytics[1] states that much of their address space is VPNs, so the trail may go cold here.

[1] https://scamalytics.com/ip/isp/cooperative-investments-llc

Re: Ask HN: How did my LastPass master password get leaked?

#102

Earlier quoted context omitted.

What, really?? This is too crazy of a coincidence to be a coincidence. This is exactly what's happening to me, and same IP prefix. What does it mean? --- How old of account was this? Can you contact me by email (email in my profile)? --- Two theories: - there is a problem with LastPass - you and I both had the same Chrome extension installed that was actually compromised, and that extension was listening to/sending p…

posting another comment here too for visibility, but this _just_ happened to me as well.... Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235

Hmm. So I don't know if this means anything, but I was googling for the IP address and wound up at https://ipinfo.io/160.116.88.235 which says hostname: visit.keznews.com. When you go to that hostname, it's one of the best phishing sites I've ever seen. They dynamically inserted my ISP's logo (Spectrum) and tried to do a phishing attempt:

https://i.imgur.com/C9HQw1c.png

The full non-clickable URL:

  https://us.poonstate.click/us/i/spectrum/?track=u.pslnk.link&key=eyJ0aW1lc3RhbXAiOiIxNjQwNjM4NTIyIiwiaGFzaCI6IjNiZjRkYTg5MTA5MzMzNmU5NjRmMjZiNDY1NWUyN2UwMjk3NzI0OTYifQ%3D%3D&tsid=7ae4766b-0de5-4865-9f1b-025a45c71c3f&bemobdata=c%3D314f53db-f844-46ea-99f8-f277456639d3..l%3Df57d9a37-1c67-4958-ac52-6f4854ce6840..a%3D2..b%3D1..z%3D0.0016..e%3Dzr4b7f4393675711ecb78f122b3efc6f65f31163358f914cea90c49d2c8cc35b7b0612682b8c773fbcf1..c1%3Dwhiskey-oar-eAcMKVvZ..c2%3Dgriseous-trout..c4%3DDOMAIN..c6%3DNON-ADULT..c8%3D1655308..c9%3Dfbb8c5b0-5140-11ec-a217-0aea8b85a94f..c10%3D0#
I went through and answered the "questions", and it tried to take me to the actual phishing site:

https://i.imgur.com/wYt5WB3.png

https://i.imgur.com/Picaw4a.png

Screenshots of the actual phishing site

https://i.imgur.com/Bh5c2lZ.png

https://i.imgur.com/q7xnSki.png

https://i.imgur.com/GX4hWnQ.png

And its url (non-clickable):

  https://welcome.myonlineeconomy.com/us/238700/25/?pubid=aff-us&pob=3&click_id=61ca28bcf92ca000011aa4c0&subid=RT-60338e1b79fcbe00012195a3-168&utm_medium=mail&utm_term=ipadpro&terms=y&email=&fname=&lname=&fp=&address=&city=&zip=&state=&lpkeyua=a17666fa4eadface9331c0311b1e8875.1640638952

Now, the interesting part is that this phishing attempt only happened once. When I tried to visit again just now, it just says "something went wrong" (on the first site) and "Access denied" (on the second site).

I saved the sites to disk as I went, but I doubt these dumps will tell you much. Just in case though:

1. https://gist.github.com/shawwn/4deace812e7c752949a0df096ef66...

2. https://gist.github.com/shawwn/721f235e760dd2257cd760edb1188...

Long story short: It sounds like all of you got phished. I suspect you installed a malicious app that somehow targeted your web browser's LastPass extension, modifying it to send your master password to these fine people. ¯\_(ツ)_/¯

Re: Ask HN: How did my LastPass master password get leaked?

#103
post #92

Reading the comments here there's one possibility that I haven't seen mentioned in that there may be an issue with lastpass allowing some level of access into people's accounts without actually having the password (which wouldn't enable the attacker to access the encrypted data).

let's not make any ridiculous assumptions

Re: Ask HN: How did my LastPass master password get leaked?

#104
post #56
post #33

Earlier quoted context omitted.

+1, you can host your own server as well https://github.com/dani-garcia/vaultwarden

There's an official self-host open source version as well ( the one you linked is unofficial), but it's rather heavy ( multiple .NET services, MS SQL) and not adapted for small scales.

yes, we don't talk about that one

Re: Ask HN: How did my LastPass master password get leaked?

#105
post #61

Do you ever store your LastPass in your clipboard? Malicious apps on some platforms can access your clipboard without your knowledge. Do you use a clipboard manager? Is it trustworthy? Does it store data safely on disk? Good questions to ask yourself

Good questions for sure!

In my case, the LastPass master password hadn't been used since 2017. It was stored (safely, I presume or at least hope!) in a local encrypted KeePass password manager file.

I definitely could have malware on my computer that sniffed/read the KeePass file while it's temporarily unencrypted (when I open it to get a password).

Re: Ask HN: How did my LastPass master password get leaked?

#108

Hey, this _just_ happened to me too....my password would be near impossible to guess and is not used elsewhere... Just deleted my last pass account! here's the info that came with the email Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235

WHAT!! Same IP range for me. How is this possible????

Is the date / time exactly the same? It seems like they might have emailed _everyone_ at this point. Maybe it's just a bug.

Re: Ask HN: How did my LastPass master password get leaked?

#109

Given we’re likely stuck with passwords for the foreseeable future, I’d like to see two things in a password manager (maybe these exist?) 1. “hardware wallet” level security, with good UX. Maybe a USB/Lightning dongle, but I really wish computers/phones had built-in capability to do hardware wallets. Apple TouchBar got close (I realize it wouldn’t considered be a dedicated hardware wallet). 2. a way to automatically…

1. Check out https://www.themooltipass.com

Re: Ask HN: How did my LastPass master password get leaked?

#110
post #3

My bet would be on malware or compromised browser extension. You probably typed (or copy/pasted) the password ans something kept a copy along the way.

Compromised browser extension could make sense, aye. Do Chrome extensions have access to the file system too? Is there a chance my local KeePassX file has been siphoned off? Thanks

Chrome extensions can run native binaries, so yes.
Post reply on HN