Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

181–190 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#181

FWIW, I migrated off paid LastPass onto the free BitWarden plan recently and my experience has been much improved. I was a huge LastPass proponent in the beginning and at the time they seemed like the obvious best choice in a field with few options. But they have definitely not been able to keep up with the times and their paid service just isn't even comparable to what is now available for free.

Similar story as you, promoted LastPass when it first started because it worked and was the obvious choice. About 3 years ago I finally switched to BitWarden after realizing Lastpass was never going to fix their terrible UI. A few months ago I switched to 1Password though and am very happy. It has a few nice QOL improvements over BitWarden IMO, though BitWarden was leagues better than LastPass at least.

This post prompted me to go in and clean out/delete my old LastPass account though!

Re: Ask HN: How did my LastPass master password get leaked?

#182
post #158

Earlier quoted context omitted.

I have an iPhone and I do have my keepass file there too. So yes, presumably, the iOS app that I use could have accessed my keepass file and sent it unencrypted over the network to someone (which would be terrible). Thanks for the comment/reminder! I'll definitely have to re-consider what I do with regards to the keepass file on my phone.

also, just for grins. have you checked to see if the same email is generated in error when a failed login attempt happens from an unknown location?

Yes, good call. And I did just check.

A wrong password = no email.

Correct password from different IP = exact same email saying "Someone just used your master password to try to log in to your account from a device or location we didn't recognize"

That's the exact same email I received earlier with the Brazil IP.

Re: Ask HN: How did my LastPass master password get leaked?

#183

Hopefully LastPass is already researching. Nothing on any other boa d, Twitter or on LastPass webpage. The Chrome vulnerability was 2019. Long time to stand in the shadow.

LastPass support brushed it off, unfortunately. A second agent I talked to (after the story started picking up here) reached out to Level 2, but they also brushed it off.

Re: Ask HN: How did my LastPass master password get leaked?

#184

This also happened to me back on Nov 10, 2021. I had an old LastPass account, wasn't using it, when all of a sudden i get an email: -- Login attempt blocked Hello, Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look. --- Like you, it told me that the attempt came from Brazil, using an IP…

What, really?? This is too crazy of a coincidence to be a coincidence. This is exactly what's happening to me, and same IP prefix. What does it mean? --- How old of account was this? Can you contact me by email (email in my profile)? --- Two theories: - there is a problem with LastPass - you and I both had the same Chrome extension installed that was actually compromised, and that extension was listening to/sending p…

I am having the same issue!!! One of my important passwords was leaked and in free use by a bunch of people who were all accessing my evernote account (thankfully it had nothing important in it). I've been on a spree to change my passwords since then.

I have been wondering - is this because of the following lastpass bug?

https://www.zdnet.com/article/lastpass-bug-leaks-credentials...

Re: Ask HN: How did my LastPass master password get leaked?

#185
post #118

Could be that someone at Lastpass simply does not know how to write properly. Maybe the attacker attempted to use the master password login festure without having the actual correct master password itself, and the email is poorly written.

Unfortunately, I just tried and that email is sent when the correct master password is sent.

When someone uses the wrong password, it doesn't send any email. (That event is logged though, and I see those failed attempts in the dashboard -- those, I'm less worried about, obviously)

Re: Ask HN: How did my LastPass master password get leaked?

#186
post #119

Please stop using this service. Use reliable, open source and auditable services. https://www.privacyguides.org/software/passwords/

Here is a wider list: https://github.com/pluja/awesome-privacy

There are 57 different categories on that page, direct link to the relevant content: https://github.com/pluja/awesome-privacy#password-managers

This list is also more narrow, not wider: awesome-privacy recommends Bitwarden, Keepass, and Padloc, while privacyguides recommends Bitwarden, Keepass, Psono, Password Safe, and Pass.

Re: Ask HN: How did my LastPass master password get leaked?

#187
post #94

Earlier quoted context omitted.

There was no 1Password to LastPass importer at the time I wrote that (believe me, I looked because I have better things to do than write apps to benefit a commercial entity like agilebits otherwise), and of course the code is published on GitHub and released under the MIT license. It's very short and simple and rather easy to review. It's also a .NET executable, which is ridiculously easy to reverse-compile back to C…

Just because you put a warning label on a bad practice doesn't mean it's a good practice. Pumping your passwords through some random code on Github that has a "be smart" label doesn't make it a good idea. Would be so easy to imitate you, reupload the code with an exploit. For giggles, if I was making this into a hijack I'd leave all your warnings in and even make them bigger and more obvious, confident in the knowled…

> Just because you put a warning label on a bad practice doesn't mean it's a good practice.

That is such a salient point, generally.

Re: Ask HN: How did my LastPass master password get leaked?

#188

Earlier quoted context omitted.

1. Check out https://www.themooltipass.com

Cool, great start, but something Yubikey sized would be more practical.

It can be done with yubikey. Passwords stored encrypted on disk and get decrypted on the yubikey with gpg.

https://github.com/drduh/YubiKey-Guide

https://attackpointsecurity.com/go-pass-yubikey-and-gpg

Re: Ask HN: How did my LastPass master password get leaked?

#189

Do you have your master password stored in a file or email someplace?

I only stored that LastPass master password in a KeePass file that I keep local and (obviously) encrypted.

I hadn't logged into to that LastPass account since 2017.

Hence, I presumed that my KeePass file might have been compromised, but it seems unlikely now, considering many other people (6? 7?) are coming to this thread with a similar story of their master passwords being known to the "Brazil" attackers as well.

i.e. our master passwords have been leaked. By when? And by whom?

Post reply on HN