Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

141–150 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#144
post #128

My girlfriend once asked me why I don't use a password manager like LastPass. A week later she got locked out of her LastPass account because she was inadvertently using an enterprise account that one of her clients forced her to use while on a project. And even though she was paying for her own premium LastPass subscription, the support experience had was terrible. Issue was resolved when the client was able to unlo…

I completely agree; sticky notes have a much superior support experience

Re: Ask HN: How did my LastPass master password get leaked?

#145
post #135

Earlier quoted context omitted.

Hmm. So I don't know if this means anything, but I was googling for the IP address and wound up at https://ipinfo.io/160.116.88.235 which says hostname: visit.keznews.com. When you go to that hostname, it's one of the best phishing sites I've ever seen. They dynamically inserted my ISP's logo (Spectrum) and tried to do a phishing attempt: https://i.imgur.com/C9HQw1c.png The full non-clickable URL: https://us.poonstat…

That’s not a phishing site. That’s standard zero-click /smartlink monetization. It’s a lot to explain and I’m on mobile but it isn’t anything to do with phishing.

But, it certainly wasn't from Spectrum (my ISP), but they designed the page to make it look like it was.

I agree that it could be totally unrelated to the root mystery though. But "everyone here fell for malware or got phished" seems like the most likely explanation, even if my answer happens to be otherwise incorrect.

Re: Ask HN: How did my LastPass master password get leaked?

#146

Earlier quoted context omitted.

Hey, That's quite possible, for sure. I am not beyond/above/below being phished like anyone else, ha! The issue -- what makes it perplexing -- is that I haven't used this LastPass password since 2017. I know because this LastPass account was only used to share passwords within an org that I left back then. Is it possible that I was phished 4 years ago, and they sat on the password? Sure. But 2 other people in this th…

Couldn't it just be that someone got a copy of the password some years ago and now sold the list of credentials to someone else, who then tried to use it? Maybe the original owner of the list didn't realize some of the credentials was for LastPass, for example. I'm still seeing hackers trying to log on using passwords I haven't used in ~10 years, because it's on a list somewhere.

This seems likely.

Re: Ask HN: How did my LastPass master password get leaked?

#147
post #81

Earlier quoted context omitted.

just checked my email. last pass account was created in 2015, not sure if the current leaked password has been in use that whole time, but it has definitely been quite a few years. moved over to 1passward in march of this year and likely have not used last pass at all since.

What prompted the move to 1password? Curious as I am deciding myself which service to use.

Not OP commenter but I personally would recommend using pass (https://passwordstore.org), I’m a little paranoid about all this fuzz, plus did you see the news in HN a few months ago about a password manager web browser extension having an exploitable vulnerability? Not sure if it was lastpass but I’ll try to search for it…

Edit: I found an old post from about 5 years ago on a vulnerability in LastPass’s extension [0]

[0] https://news.ycombinator.com/item?id=12171547

Re: Ask HN: How did my LastPass master password get leaked?

#148

This just happened to me today, but login location was Bangkok. I also haven’t used my lastpass account in almost 2 years since I switched to Bitwarden, so no way this could have stolen from my computer recently

Same thing for me, havent used my account for years, has strong password and I just got an email that someone from Paris tried to login but was blocked.

Re: Ask HN: How did my LastPass master password get leaked?

#149
post #87

People are always saying (smugly) how crucial LastPass is...

Do you mean LastPass specifically or password managers in general?

If the former: I haven't noticed that -- usually folks on HN seem to recommend 1Password or BitWarden.

If the latter: Password managers are important to resist credential stuffing attacks through password reuse.

While I don't like that many of them force you to upload your secrets to the cloud (LastPass, 1Password 8, etc), it's still a better security posture than having your weakest link be every site on which you've used the same password.

Re: Ask HN: How did my LastPass master password get leaked?

#150
>Is there some LastPass extension installed on some computer still having a valid auth token allowing them to login as me to LastPass..?

You can kill existing sessions - see account settings destroy sessions.

Edit: All looks normal my side. No emails, no login attempts, but will change pass just in case

Post reply on HN