Earlier quoted context omitted.
I agree. I contacted the support agent I talked to again with a link to this thread and all of the similar IP addresses that tried to login, presumably with the knowledge of our master passwords. I also sent off a random email to the Verge, and tried tagging LastPass on Twitter. Does anyone have tech media connections who could try to squeeze a word out of LastPass?
krebsonsecurity might want to take a look? Sounds like right up their ally.
Ask HN: How did my LastPass master password get leaked?
401–410 of 529 posts
Re: Ask HN: How did my LastPass master password get leaked?
#402Earlier quoted context omitted.
If you have the hash and algorithm used to generate it of a human generated password you can in the vast majority of cases get the password. It’s a combination of people being very bad at generating, remembering, and entering passwords plus generally being unwilling to wait minutes or even seconds to generate the hash on their local computer.
MD5 is long considered a broken, weak hash algorithm. Here is the MD5 hash of a password: d9afca35a87a2af4168500640fcf2370 Password is 16 characters long, all lower case, no numbers, no special symbols. Please tell me the password.
Re: Ask HN: How did my LastPass master password get leaked?
#403Earlier quoted context omitted.
I just tried logging into my LassPass (not used for a while) and I entered the password wrongly (I capitalised one letter) and got an email "Someone just used your master password to try to log in to your account from a device or location we didn't recognize." Maybe it says someone used your master password even if they didn't? It gave the IP as Islington which is kind of correct.
Oh! If the messaging is the same regardless of whether the right password is used then that changes everything!
Re: Ask HN: How did my LastPass master password get leaked?
#404Earlier quoted context omitted.
Let me preface by saying I'm speculating of course. > Did the malware wait for me to open my keepass vault and snoop the password then? It's not impossible at least. There's been vulnerabilities in Keepass RPC which allowed any javascripts on Internet reading your passwords [1]. If a simple javascript can read secrets from keepass, I would not be at all surprised if that has happened. > the less probable it is that w…
I copy/pasted the password from 1Password, it may lend credence to the malware Chrome extension theory, at least in my case. Anybody else using these? uBlock Origin, Google Images Restored, Allow Right-Click, Clear Cache, StartMeeting.com Launcher, ShowPassword, Tampermonkey, Usability Hike: Find usability problems, Window Resizer, Tag Assistant Companion, Google Analytics Debugger, Google Docs Offline, Google Optimi…
The login attempt was out of the blue, using a password I hadn't used since 2017.
My LastPass password may have been compromised back in 2017, but there are at least two reports here of recent accounts being compromised as well (with the attacker connecting from the same 160... IP range)
Re: Ask HN: How did my LastPass master password get leaked?
#405I also just had this happen as well and have the same setup. Unique password stored in keepass-x and I use the chrome extension. I have very few installed though, so hopefully not a malicious one there. installed extensions: ublock origin, OneTab, Lastpass, metamask, cisco webex, edit this cookie
Could you please confirm which ip address the attacker tried to login from?
Also, how old was your account?
Re: Ask HN: How did my LastPass master password get leaked?
#406I don’t use LastPass often and wasn’t 100% on my master so I tried logging in and also received the block login alter from my attempt. I verified the new location/device and then tried again and it told me the password was invalid. Tried again and got in fine.
Could it be that master passwords are not actually compromised but they are sending the unrecognized device/location on any login attempt regardless of correct master?
Can someone else verify blocked login from unknown device/location using a wrong master password?
Re: Ask HN: How did my LastPass master password get leaked?
#407Re: Ask HN: How did my LastPass master password get leaked?
#408I also just had this happen as well and have the same setup. Unique password stored in keepass-x and I use the chrome extension. I have very few installed though, so hopefully not a malicious one there. installed extensions: ublock origin, OneTab, Lastpass, metamask, cisco webex, edit this cookie
Thanks for the report. We're probably at 25 reports in this thread by now. Could you please confirm which ip address the attacker tried to login from? Also, how old was your account?
Time Tuesday, December 28, 2021 at 6:20 AM EST Location GERMANY IP address 160.116.206.37
Re: Ask HN: How did my LastPass master password get leaked?
#409I also just had this happen as well and have the same setup. Unique password stored in keepass-x and I use the chrome extension. I have very few installed though, so hopefully not a malicious one there. installed extensions: ublock origin, OneTab, Lastpass, metamask, cisco webex, edit this cookie
Thanks for the report. We're probably at 25 reports in this thread by now. Could you please confirm which ip address the attacker tried to login from? Also, how old was your account?
Re: Ask HN: How did my LastPass master password get leaked?
#410Earlier quoted context omitted.
Thanks for the report. We're probably at 25 reports in this thread by now. Could you please confirm which ip address the attacker tried to login from? Also, how old was your account?
Sure, this is the email Time Tuesday, December 28, 2021 at 6:20 AM EST Location GERMANY IP address 160.116.206.37