Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

251–260 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#251
+1 -- happened to my account today as well. Haven't logged into or used this account in years. Password is unique and has never been used elsewhere.

Deleted my account.

Email Text:

Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look.

Was this you?

Account ...@gmail.com Time Monday, December 27, 2021 at 11:53 AM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.95.249

Re: Ask HN: How did my LastPass master password get leaked?

#252
The proper response to this;

0. Consider using a new device for the following or wipe and reinstall an old device in case it's a malware/spyware attack.

1. Change your email provider(s) passphrase first, assuming it may be compromised. This is your key to recovering most other accounts if necessary. Make sure 2FA is turned on.

2. Work down the priority list (financial, work, GitHub, etc.) and reset passwords. Turn on 2FA where applicable.

3. Consider using integrated browser password managers (slightly less in-band signalling for such a security-sensitive tool) or your own locally encrypted list which can be synced with version control to other devices.

Re: Ask HN: How did my LastPass master password get leaked?

#253

Earlier quoted context omitted.

There was no 1Password to LastPass importer at the time I wrote that (believe me, I looked because I have better things to do than write apps to benefit a commercial entity like agilebits otherwise), and of course the code is published on GitHub and released under the MIT license. It's very short and simple and rather easy to review. It's also a .NET executable, which is ridiculously easy to reverse-compile back to C…

Clearly we both agree it's an insecure practice, since you felt it needed a warning. Now that you know there's an official LastPass importer for 1Password, I'm curious why you're defending your version rather than updating your blog post, unlinking your original HN comment and deprecating the GitHub repo. I believe you're genuine and just trying to help. If there's an attack, it wouldn't be you doing it – it'd be som…

No post body was provided.

Re: Ask HN: How did my LastPass master password get leaked?

#254

Just happened to me one hour ago and got scared shitless. Time Monday, December 27, 2021 at 3:50 PM EST Location UNITED STATES IP address 107.173.195.83 Actions taken, in this order: - Head to *Advanced Options* -> *View account history* to see if anything suspicious is going on (nothing so far) - Disable Lastpass MFA and use Google Authenticator (Authy) - *Account Settings* -> click on *Show Advanced Settings* -> *D…

One other thing to note is that by default lastpass allows reverting to your previous password for 30(?) days. The option is in account settings -> advanced -> "Allow master password changes to be reverted".

To be safe you would probably want to disable that then change your password again. Just don't lose your new password as you then can't revert.

See https://support.logmeininc.com/lastpass/help/recover-your-lo...

Re: Ask HN: How did my LastPass master password get leaked?

#255

Earlier quoted context omitted.

That IP is present in a cn record for visit[.]keznews[.]com, whose whois record lists an admin contact in CZ. Be very wary of geo-ip results, on the modern internet they are effectively useless.

Ignoring VPNs, why are they useless?

I wouldn't go so far as useless, but they frequently exhibit significant inaccuracy, no matter which vendor/service you use. It's not unusual for me to query 7 APIs and be told the user is in 7 different cities spanning 5 states. At least there's usually a quorum at the country level. Given the market ($$$) for IPv4, this feels like it's only getting worse as more blocks of IPs are being sold, leased, transferred, even between continents/RIRs and the geo providers are always a few steps behind.

For the IP posted above, I have 3 providers claiming it's in Sao Paulo, 3 who says it's in Joburg (this is as accurate as anyone's going to get right now) and one says it's in Chicago! If I'm trying to do something with these results programmatically, I don't have a majority or a plurality to pick as a "winner" and I have to try weighting specific providers, which is a whole new mess.

Anyway, there's a good idea brewing in RFC8805 but it'd require pretty much every AS to play along.

Re: Ask HN: How did my LastPass master password get leaked?

#257

Earlier quoted context omitted.

Yes, I do copy/paste from my local password manager. A clipboard scraper is a possibility, yes. I hadn't logged into that LastPass account for years, so it's definitely not me who attempted to login earlier. Re: LastPass, is there another cloud-based tool that's generally considered as more trustworthy? Bitwarden? Thanks

Bitwarden is great, highly recommend, it's open-source which adds to its trustworthiness and has a good track record of respecting users.

I'm in this party too. bitwarden for yourself, friends and family...

Re: Ask HN: How did my LastPass master password get leaked?

#258
post #16

Earlier quoted context omitted.

I don’t use Lastpass, but if what you are saying is correct, they could not have sent the OP an e-mail (assuming it’s legit) informing them of the attempt to sign in using the master pass from Brazil, right?

Cryptography means lastpass doesn't need the master password to verify the password.

[deleted]

Re: Ask HN: How did my LastPass master password get leaked?

#259
post #247

Earlier quoted context omitted.

What, really?? This is too crazy of a coincidence to be a coincidence. This is exactly what's happening to me, and same IP prefix. What does it mean? --- How old of account was this? Can you contact me by email (email in my profile)? --- Two theories: - there is a problem with LastPass - you and I both had the same Chrome extension installed that was actually compromised, and that extension was listening to/sending p…

I just tried logging into my LassPass (not used for a while) and I entered the password wrongly (I capitalised one letter) and got an email "Someone just used your master password to try to log in to your account from a device or location we didn't recognize." Maybe it says someone used your master password even if they didn't? It gave the IP as Islington which is kind of correct.

I think that password case is a separate issue. If I remember correctly, many online services do "secretly" accept mixed cases for the same password (because users make more mistakes than they realize and it would be "annoying" to be too strict)

If you didn't receive a "Someone just used" email (with an IP that's completely geographically off from where you are) that's a good sign, of course.

Re: Ask HN: How did my LastPass master password get leaked?

#260
post #163

May be a dumb question, but how much are we trusting Lastpass that whoever tried these logins actually used the correct master password? The posted statements sound a bit ambiguous, maybe they're mistaken? Does it show as a login attempt if somebody uses your correct account email address and the wrong password? Of course if Lastpass is sending ambiguous or mistaken communication about whether someone else has your m…

Unfortunately, the email sent from LastPass specifically says "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" LastPass support did confirm that the IP from Brazil did have the master password. I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the mas…

Your test of a login attempt with a wrong password was a good idea, but did you do it from a location they would not recognize? That's what you need to do to rule out that the Brazil message was not merely a wrong password login attempt.

I'm a bit skeptical that if someone tried a login with the correct password but from an unrecognized location that they would block it by default. People do travel and do change devices. It would really suck if you were far from home and needed to use one of your passwords and couldn't login because your are not at your normal location.

What I've seen from other services when logging in from a new location is either

1. They send an email or text to the email or phone number associated with the account, which must be acknowledged before the login is allowed, or

2. The login is allowed but they send an email or text telling me that there was such a login and that if it wasn't me how I can kick the person out and re-secure the account.

This item from their support site suggests that they do #1 [1].

[1] https://support.logmeininc.com/lastpass/help/best-practices-...

Post reply on HN