Earlier quoted context omitted.
Hey, That's quite possible, for sure. I am not beyond/above/below being phished like anyone else, ha! The issue -- what makes it perplexing -- is that I haven't used this LastPass password since 2017. I know because this LastPass account was only used to share passwords within an org that I left back then. Is it possible that I was phished 4 years ago, and they sat on the password? Sure. But 2 other people in this th…
Hey guys I think that maybe this has to do with an exploit in the web browser LastPass extension about 5 years ago: HN POST: [0]. [0] https://news.ycombinator.com/item?id=12171547
Ask HN: How did my LastPass master password get leaked?
161–170 of 529 posts
Re: Ask HN: How did my LastPass master password get leaked?
#162Earlier quoted context omitted.
Hey, That's quite possible, for sure. I am not beyond/above/below being phished like anyone else, ha! The issue -- what makes it perplexing -- is that I haven't used this LastPass password since 2017. I know because this LastPass account was only used to share passwords within an org that I left back then. Is it possible that I was phished 4 years ago, and they sat on the password? Sure. But 2 other people in this th…
Couldn't it just be that someone got a copy of the password some years ago and now sold the list of credentials to someone else, who then tried to use it? Maybe the original owner of the list didn't realize some of the credentials was for LastPass, for example. I'm still seeing hackers trying to log on using passwords I haven't used in ~10 years, because it's on a list somewhere.
So LastPass (their extension) may have been hacked ~5 years ago ish, a few people here on the thread were all hacked in the same way, our passwords were sold off, and now the same Brazil IP range just tried all of those passwords.
Re: Ask HN: How did my LastPass master password get leaked?
#163Of course if Lastpass is sending ambiguous or mistaken communication about whether someone else has your master password, that's a really bad sign for them as a company too.
On the "bright" side, if somebody had your KeePassX file and master password to that, I would think they'd be doing things a lot worse than trying to log into your LastPass account from Brazil. If they had that data and were serious about LastPass for some reason, they'd probably at least break into your email too and try and intercept those warning emails. Keep an eye on email, banking, credit card, hosting systems, any other higher-value accounts that might have credentials in that file for any signs of suspicious activity. If there's none, then a successful exfiltration of that data seems unlikely.
Re: Ask HN: How did my LastPass master password get leaked?
#164My girlfriend once asked me why I don't use a password manager like LastPass. A week later she got locked out of her LastPass account because she was inadvertently using an enterprise account that one of her clients forced her to use while on a project. And even though she was paying for her own premium LastPass subscription, the support experience had was terrible. Issue was resolved when the client was able to unlo…
And regardless, people should finally take this to heart:
If something is important to you, back it up in a format that you can read with offline software. I don't care if you store it on punch cards under your pillow or in The Cloud, so long as it's independent of the primary copy (such that you can access it regardless of access to the primary copy, and such that you don't need the original service to load the data in order to read it). It doesn't sound like that was the case for your friend.
Re: Ask HN: How did my LastPass master password get leaked?
#165Hey, this _just_ happened to me too....my password would be near impossible to guess and is not used elsewhere... Just deleted my last pass account! here's the info that came with the email Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235
got one at 1528EST from 23[.]236[.]213[.]5 - OSINT shows it part of BLAZING_SEO_PROXY pw was only ever used here and stored offline
Or I am drawing a random line through a cloud of dots..? :-)
What other IPs are part of BLAZING_SEO_PROXY?
Re: Ask HN: How did my LastPass master password get leaked?
#166Earlier quoted context omitted.
WHAT!! Same IP range for me. How is this possible????
Is the date / time exactly the same? It seems like they might have emailed _everyone_ at this point. Maybe it's just a bug.
Re: Ask HN: How did my LastPass master password get leaked?
#167You trusted an online service to look after your passwords. Use something local, like 1password. I have no idea why anyone would use a hosted solution like LastPass. Of course something will happen?
> I have no idea why anyone would use a hosted solution like LastPass. Convenience. I use Bitwarden. I get a lot of value from having my passwords synced across multiple PCs and my phone.
Re: Ask HN: How did my LastPass master password get leaked?
#168May be a dumb question, but how much are we trusting Lastpass that whoever tried these logins actually used the correct master password? The posted statements sound a bit ambiguous, maybe they're mistaken? Does it show as a login attempt if somebody uses your correct account email address and the wrong password? Of course if Lastpass is sending ambiguous or mistaken communication about whether someone else has your m…
LastPass support did confirm that the IP from Brazil did have the master password.
I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the master password.
Re: KeePassX, I agree. It's a catastrophic scenario if true, but it does seem improbable.
Re: Ask HN: How did my LastPass master password get leaked?
#169Re: Ask HN: How did my LastPass master password get leaked?
#170It happened to me to but I'm no longer using LastPass for years now. I got an email saying that somebody tried to access my account from the US (the attacker is using a VPN) and changed password and recovery email on my Outlook account
Did the email say that "Someone just used your master password to try to log in to your account from a device or location we didn't recognize"
And was that master password generally secure / wasn't used anywhere else?
Thanks!