Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

401–410 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#401

Earlier quoted context omitted.

I agree. I contacted the support agent I talked to again with a link to this thread and all of the similar IP addresses that tried to login, presumably with the knowledge of our master passwords. I also sent off a random email to the Verge, and tried tagging LastPass on Twitter. Does anyone have tech media connections who could try to squeeze a word out of LastPass?

krebsonsecurity might want to take a look? Sounds like right up their ally.

Good idea, I'll contact them.

Re: Ask HN: How did my LastPass master password get leaked?

#402
post #239

Earlier quoted context omitted.

If you have the hash and algorithm used to generate it of a human generated password you can in the vast majority of cases get the password. It’s a combination of people being very bad at generating, remembering, and entering passwords plus generally being unwilling to wait minutes or even seconds to generate the hash on their local computer.

MD5 is long considered a broken, weak hash algorithm. Here is the MD5 hash of a password: d9afca35a87a2af4168500640fcf2370 Password is 16 characters long, all lower case, no numbers, no special symbols. Please tell me the password.

What percentage of people do you think actually use 16 character passwords?

Re: Ask HN: How did my LastPass master password get leaked?

#403
post #263
post #247

Earlier quoted context omitted.

I just tried logging into my LassPass (not used for a while) and I entered the password wrongly (I capitalised one letter) and got an email "Someone just used your master password to try to log in to your account from a device or location we didn't recognize." Maybe it says someone used your master password even if they didn't? It gave the IP as Islington which is kind of correct.

Oh! If the messaging is the same regardless of whether the right password is used then that changes everything!

I don't think that's the case. I went back and looked at the auth logs and there are many "failed logins" and one "Login verification email sent", which is the only one I got an email for.

Re: Ask HN: How did my LastPass master password get leaked?

#404

Earlier quoted context omitted.

Let me preface by saying I'm speculating of course. > Did the malware wait for me to open my keepass vault and snoop the password then? It's not impossible at least. There's been vulnerabilities in Keepass RPC which allowed any javascripts on Internet reading your passwords [1]. If a simple javascript can read secrets from keepass, I would not be at all surprised if that has happened. > the less probable it is that w…

I copy/pasted the password from 1Password, it may lend credence to the malware Chrome extension theory, at least in my case. Anybody else using these? uBlock Origin, Google Images Restored, Allow Right-Click, Clear Cache, StartMeeting.com Launcher, ShowPassword, Tampermonkey, Usability Hike: Find usability problems, Window Resizer, Tag Assistant Companion, Google Analytics Debugger, Google Docs Offline, Google Optimi…

I use uBlock Origin too (only one in common with you), but in my case, I hadn't copied/used the master password before the login attempt

The login attempt was out of the blue, using a password I hadn't used since 2017.

My LastPass password may have been compromised back in 2017, but there are at least two reports here of recent accounts being compromised as well (with the attacker connecting from the same 160... IP range)

Re: Ask HN: How did my LastPass master password get leaked?

#405

I also just had this happen as well and have the same setup. Unique password stored in keepass-x and I use the chrome extension. I have very few installed though, so hopefully not a malicious one there. installed extensions: ublock origin, OneTab, Lastpass, metamask, cisco webex, edit this cookie

Thanks for the report. We're probably at 25 reports in this thread by now.

Could you please confirm which ip address the attacker tried to login from?

Also, how old was your account?

Re: Ask HN: How did my LastPass master password get leaked?

#406
I received the alert of a blocked login attempt yesterday from 168.81.33.157 (Mumbai, India).

I don’t use LastPass often and wasn’t 100% on my master so I tried logging in and also received the block login alter from my attempt. I verified the new location/device and then tried again and it told me the password was invalid. Tried again and got in fine.

Could it be that master passwords are not actually compromised but they are sending the unrecognized device/location on any login attempt regardless of correct master?

Can someone else verify blocked login from unknown device/location using a wrong master password?

Re: Ask HN: How did my LastPass master password get leaked?

#408

I also just had this happen as well and have the same setup. Unique password stored in keepass-x and I use the chrome extension. I have very few installed though, so hopefully not a malicious one there. installed extensions: ublock origin, OneTab, Lastpass, metamask, cisco webex, edit this cookie

Thanks for the report. We're probably at 25 reports in this thread by now. Could you please confirm which ip address the attacker tried to login from? Also, how old was your account?

Sure, this is the email

Time Tuesday, December 28, 2021 at 6:20 AM EST Location GERMANY IP address 160.116.206.37

Re: Ask HN: How did my LastPass master password get leaked?

#409

I also just had this happen as well and have the same setup. Unique password stored in keepass-x and I use the chrome extension. I have very few installed though, so hopefully not a malicious one there. installed extensions: ublock origin, OneTab, Lastpass, metamask, cisco webex, edit this cookie

Thanks for the report. We're probably at 25 reports in this thread by now. Could you please confirm which ip address the attacker tried to login from? Also, how old was your account?

My account was created in 2013 and changed the password last in 2016. I went back and looked in the audit log for the last year and there was nothing else suspect. Just some failed logins, but that's pretty common, I didn't see any logged in usage from any IPs but mine

Re: Ask HN: How did my LastPass master password get leaked?

#410

Earlier quoted context omitted.

Thanks for the report. We're probably at 25 reports in this thread by now. Could you please confirm which ip address the attacker tried to login from? Also, how old was your account?

Sure, this is the email Time Tuesday, December 28, 2021 at 6:20 AM EST Location GERMANY IP address 160.116.206.37

Thanks! Same 160.116 ip range as me and many others here.
Post reply on HN