Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

261–270 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#262
post #256

My bet is on the 2017 breach. Those affected/unaffected can share how old their master password is? With enough data points it can be easy to pinpoint.

My master password, and whole account, was definitely from 2017.

Which 2017 breach are you referring to? This?

https://www.theguardian.com/technology/2017/mar/30/lastpass-...

Re: Ask HN: How did my LastPass master password get leaked?

#263
post #247

Earlier quoted context omitted.

What, really?? This is too crazy of a coincidence to be a coincidence. This is exactly what's happening to me, and same IP prefix. What does it mean? --- How old of account was this? Can you contact me by email (email in my profile)? --- Two theories: - there is a problem with LastPass - you and I both had the same Chrome extension installed that was actually compromised, and that extension was listening to/sending p…

I just tried logging into my LassPass (not used for a while) and I entered the password wrongly (I capitalised one letter) and got an email "Someone just used your master password to try to log in to your account from a device or location we didn't recognize." Maybe it says someone used your master password even if they didn't? It gave the IP as Islington which is kind of correct.

Oh! If the messaging is the same regardless of whether the right password is used then that changes everything!

Re: Ask HN: How did my LastPass master password get leaked?

#264

+1 -- happened to my account today as well. Haven't logged into or used this account in years. Password is unique and has never been used elsewhere. Deleted my account. Email Text: Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look. Was this you? Account ...@gmail.com Time Monday, Decem…

Yikes, seriously... We're at 13? independent reports.

Would you mind sharing how old was this account? Was it from 2017, or before?

Trying to find some common thread between all of us i.e. which exploit it might have been.

Re: Ask HN: How did my LastPass master password get leaked?

#265

Hey, this _just_ happened to me too....my password would be near impossible to guess and is not used elsewhere... Just deleted my last pass account! here's the info that came with the email Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235

Are we sure that same email isn't sent out if someone tries to log into your account with the wrong password?

Re: Ask HN: How did my LastPass master password get leaked?

#266
post #260

Earlier quoted context omitted.

Unfortunately, the email sent from LastPass specifically says "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" LastPass support did confirm that the IP from Brazil did have the master password. I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the mas…

Your test of a login attempt with a wrong password was a good idea, but did you do it from a location they would not recognize? That's what you need to do to rule out that the Brazil message was not merely a wrong password login attempt. I'm a bit skeptical that if someone tried a login with the correct password but from an unrecognized location that they would block it by default. People do travel and do change devi…

LastPass does send out an email every time that there is a new login attempt with the correct password from a new ip address. An included link from that email must be followed for the ip to be approved. Then, you can actually login from that ip. (and yes, that's annoying re: travel/ip changes...)

When a wrong password is entered, no email is sent.

I tested the above (using a new ip with correct password -> email; wrong password -> no email) and it also aligns with what my "Account History" shows. There's a list of bad password attempts, and there's a separate list of "Login Verification Email Sent" i.e. the password was correct (presumably -- or maybe its hash -- that's one theory going around) but it was from a new, un-verified-so-far ip.

Re: Ask HN: How did my LastPass master password get leaked?

#267

Earlier quoted context omitted.

Unfortunately, the email sent from LastPass specifically says "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" LastPass support did confirm that the IP from Brazil did have the master password. I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the mas…

I thought that LastPass didn't send your master password over the wire, rather it uses client-side code to take your Master Password and turn it into a hash which is then sent to LastPass for comparison[1]. If that is the case, how can LastPass claim to know that your master password was used? At best, they can claim that the hash sent to the server matches your password's hash but that is not the same as your master…

If Lastpass was zero knowledge then this wouldn't make sense. The master password or some derivative of it should decrypt your passwords on the local device.

I use Keeper and despite it being cloud based, that's exactly how it works.

Re: Ask HN: How did my LastPass master password get leaked?

#268
post #263
post #247

Earlier quoted context omitted.

I just tried logging into my LassPass (not used for a while) and I entered the password wrongly (I capitalised one letter) and got an email "Someone just used your master password to try to log in to your account from a device or location we didn't recognize." Maybe it says someone used your master password even if they didn't? It gave the IP as Islington which is kind of correct.

Oh! If the messaging is the same regardless of whether the right password is used then that changes everything!

When a wrong password is used, no email is sent out from my multiple experiments today.

I'm happy to be proven wrong, but I think that what's happening with @tim333 is that master passwords may be all lower cased (for example) before being hashed. Or maybe the password is hashed twice with the first letter upper and lower cased.

Here's what I found from a quick google re: password case:

https://www.zdnet.com/article/facebook-passwords-are-not-cas...

https://security.stackexchange.com/questions/68013/facebook-...

"This is simply Facebook trying to provide a better user experience for those users who may have Caps Lock enabled, or whose devices automatically capitalize the first letter of the password."

Re: Ask HN: How did my LastPass master password get leaked?

#269
post #256

My bet is on the 2017 breach. Those affected/unaffected can share how old their master password is? With enough data points it can be easy to pinpoint.

My master password, and whole account, was definitely from 2017. Which 2017 breach are you referring to? This? https://www.theguardian.com/technology/2017/mar/30/lastpass-...

Yes, my bad,it's technically not a breach, since in theory it was never exploited.

Re: Ask HN: How did my LastPass master password get leaked?

#270
post #265

Hey, this _just_ happened to me too....my password would be near impossible to guess and is not used elsewhere... Just deleted my last pass account! here's the info that came with the email Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235

Are we sure that same email isn't sent out if someone tries to log into your account with the wrong password?

No email is sent when an attempt was made to login with the wrong password.

Logging in with the wrong password is logged in the Account History as "Failed Login Attempt"

Logging in with the correct password (or hash? TBD) from a new IP triggers the email and that's logged in the Account History as "Login Verification Email Sent"

Post reply on HN