Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

331–340 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#331
This just happened to me Nov 10. I created a brand new LastPass account (created for the sole purpose of retrieving a password a client shared with me), generated a password from 1Password and copy/pasted it into the sign-up form in Chrome. It was barely an hour later before I got the ‘Login attempt blocked’ from São Paulo.

Re: Ask HN: How did my LastPass master password get leaked?

#332

Earlier quoted context omitted.

Did your email say "Someone just used your master password to try to log in to your account from a device or location we didn't recognize"? Just making sure we're all concerned with the same issue Thanks!

Yup. Exactly that text.

Thanks for confirming!

Re: Ask HN: How did my LastPass master password get leaked?

#333

Earlier quoted context omitted.

Holy moly!!! Were you using LastPass around 2017? One theory that's floating is that we were all owned by a compromised LastPass extension 4-5 years ago. Just trying to find some common thread among all of us (a thread that's different than "lastpass was owned" which presumably should be more improbable...)

I got the "Someone just used your master password" email too Time Monday, December 27, 2021 at 3:05 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.190.69 I haven't used LastPass since 2016 or 2017.

Thanks for this additional confirmation/data point!

Something clearly happened around 2017 to all of us... And to see the same ip range today come up again and again is really troubling.

Re: Ask HN: How did my LastPass master password get leaked?

#334

This just happened to me Nov 10. I created a brand new LastPass account (created for the sole purpose of retrieving a password a client shared with me), generated a password from 1Password and copy/pasted it into the sign-up form in Chrome. It was barely an hour later before I got the ‘Login attempt blocked’ from São Paulo.

That's really bad, and possibly invalidates the theory that this is a breach dating back from 2017...

Would you mind sharing the ip address that attempted to login?

Also, you created the account this year, in 2021?

Thanks

Re: Ask HN: How did my LastPass master password get leaked?

#335
post #186
post #119

Earlier quoted context omitted.

Here is a wider list: https://github.com/pluja/awesome-privacy

There are 57 different categories on that page, direct link to the relevant content: https://github.com/pluja/awesome-privacy#password-managers This list is also more narrow, not wider: awesome-privacy recommends Bitwarden, Keepass, and Padloc, while privacyguides recommends Bitwarden, Keepass, Psono, Password Safe, and Pass.

By "wider", I meant more categories, and not more items for this particular category.

Re: Ask HN: How did my LastPass master password get leaked?

#336

Oh no it happened to me too Time Monday, December 27, 2021 at 2:07 PM EST Location Fair Lawn, NJ 07410, UNITED STATES IP address 172.245.155.253

Fascinating, we must be at about 20 independent reports here.

When was your account created?

Re: Ask HN: How did my LastPass master password get leaked?

#337

Earlier quoted context omitted.

- Disable Lastpass MFA and use Google Authenticator (Authy) could you please explain this point? Isn't LastPass Authenticator equivalent to Google Authenticator, Authy or any other TOTP app? Or is there something that makes it less secure than other apps? Perhaps because it has cloud backups?

When you do authy (or google auth) it will generate a new set of keys for you and shutdown any old ones associated with the lastpass stuff thus making the old keys useless. Also obviously he should change his master password to a new one.

> When you do authy (or google auth) it will generate a new set of keys for you and shutdown any old ones

wouldn't it be the same if you were going the other way around? E.g. switching from Authy to Lastpass Authenticator

Re: Ask HN: How did my LastPass master password get leaked?

#338
My login attempt info: Time Monday, December 27, 2021 at 5:51 PM EST Location GERMANY IP address 168.81.122.153

It was definitely a unique password. Last set in 2017, but changed now. I had just purged virtually all the data in the account recently, but it's still frightening.

Re: Ask HN: How did my LastPass master password get leaked?

#339

This just happened to me Nov 10. I created a brand new LastPass account (created for the sole purpose of retrieving a password a client shared with me), generated a password from 1Password and copy/pasted it into the sign-up form in Chrome. It was barely an hour later before I got the ‘Login attempt blocked’ from São Paulo.

That's really bad, and possibly invalidates the theory that this is a breach dating back from 2017... Would you mind sharing the ip address that attempted to login? Also, you created the account this year, in 2021? Thanks

Yep I created the account just last month, here are the 'Was this you?' details from the email:

Time Wednesday, November 10, 2021 at 2:57 PM EST

Location São Paulo, SP 01323, BRAZIL

IP address 160.116.92.198

Re: Ask HN: How did my LastPass master password get leaked?

#340
post #203

I see a lot of people suggesting other password managers, so I was wandering am I the only one who uses google's? I've used lastpass briefly but it was pretty buggy and didn't feel like it was worth the price. Google (Chrome) password manager is free, and recently got a native autofill for android, which works flawlessly, compared to others.

Chrome and Firefox both have decent password managers, so I use them.

People are only satisfied with the overall situation because there hasn't been a generic zero-day affecting major email providers or senders allowing mass exploitation of password reset flows.

Federated logins are probably the way to go, though. Folks who "don't trust cloud providers" to store their passwords are already trusting the same companies for their entire OS, possibly the hardware, and significant application stacks, or else they already have plenty of Free Software tools available to manage passwords.

Post reply on HN