Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

411–420 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#411

I received the alert of a blocked login attempt yesterday from 168.81.33.157 (Mumbai, India). I don’t use LastPass often and wasn’t 100% on my master so I tried logging in and also received the block login alter from my attempt. I verified the new location/device and then tried again and it told me the password was invalid. Tried again and got in fine. Could it be that master passwords are not actually compromised bu…

Hey,

I tested it here a few times, logging in with a wrong password does not generate an email, while logging in with the correct password from a new IP does generate that "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email.

Could you try again logging in with a completely wrong password (to see if you get a email) and then logging in with the correct password from a new IP?

Also, you can verify that those kinds of events (wrong password and correct password from new IP) are logged in the LastPass Account History. Instructions to get the Account History are here https://news.ycombinator.com/item?id=29708122

Re: Ask HN: How did my LastPass master password get leaked?

#412
post #87

People are always saying (smugly) how crucial LastPass is...

Do you mean LastPass specifically or password managers in general? If the former: I haven't noticed that -- usually folks on HN seem to recommend 1Password or BitWarden. If the latter: Password managers are important to resist credential stuffing attacks through password reuse. While I don't like that many of them force you to upload your secrets to the cloud (LastPass, 1Password 8, etc), it's still a better security…

The former, and in my day-to-day career.

Re: Ask HN: How did my LastPass master password get leaked?

#413

I received the alert of a blocked login attempt yesterday from 168.81.33.157 (Mumbai, India). I don’t use LastPass often and wasn’t 100% on my master so I tried logging in and also received the block login alter from my attempt. I verified the new location/device and then tried again and it told me the password was invalid. Tried again and got in fine. Could it be that master passwords are not actually compromised bu…

Hey, I tested it here a few times, logging in with a wrong password does not generate an email, while logging in with the correct password from a new IP does generate that "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email. Could you try again logging in with a completely wrong password (to see if you get a email) and then logging in with the…

Interesting. I tested twice before with the wrong password and vpn and it generated the email but was not able to get in. I assume it would still show in account history because that event is the login verification email event.

It isn’t sending that email for me at this point so maybe something has been corrected and LastPass will acknowledge something soon.

Re: Ask HN: How did my LastPass master password get leaked?

#414

Earlier quoted context omitted.

Hey, I tested it here a few times, logging in with a wrong password does not generate an email, while logging in with the correct password from a new IP does generate that "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email. Could you try again logging in with a completely wrong password (to see if you get a email) and then logging in with the…

Interesting. I tested twice before with the wrong password and vpn and it generated the email but was not able to get in. I assume it would still show in account history because that event is the login verification email event. It isn’t sending that email for me at this point so maybe something has been corrected and LastPass will acknowledge something soon.

For me, the behavior is:

* Connecting from my own IP with wrong password: It tells me to "Check my master password and try again."

* Connecting from another IP with wrong password: It tells me to "Check your inbox for an email from LastPass: " and also to check my login info.

It's a bit odd that it tells me to check my email even though the master password I provided was incorrect.

Re: Ask HN: How did my LastPass master password get leaked?

#415

Earlier quoted context omitted.

I see no big diff actually. It offers you no more security if you're directly compromised. It also doesn't help much in reducing the risk of the 3rd party services being hacked, as your data still travels through someone else's cloud. The one attack you avoid by it is LastPass being hacked and your encrypted vault stolen - but then you also open up yourself for Dropbox being hacked and your data stolen attack (which…

There is a fairly big difference, you are decrypting a local file using a master password NOT stored on the internet. No data is going over the wire, no 'other peoples computers'. Even if someone got your vault file, with a _very strong_ master password it's just not going to get brute forced any time soon. [1] With an online-only solution you have no idea how they are storing your data. I think 1p local vault (only)…

I would disagree with your premise. LastPass get hacked you hear all about it (this thread being a perfect example). You also then get group minds chasing solutions and spotting issues.

If you get hacked, you wont even know, and when you try to figure out how your genius security solution was foiled, you are on your own there too.

The only way your data is safer is in your mind, which is the first mistake of security; you dont get hacked because you knew about the weakness, you get hacked because you didn't.

PM's are, in most cases, a lot more advantageous for many reasons. But you can't really compare the solo solution at all, imo.

Re: Ask HN: How did my LastPass master password get leaked?

#416
post #363

Earlier quoted context omitted.

There's a level of irony in complaining about malicious code, and still recommending a closed source password manager.

I can't parse this. Is your point that "closed source" is a synonym for "insecure"?

Closed source is a synonym for insecure if you accept secure means no blackbox processes.

Re: Ask HN: How did my LastPass master password get leaked?

#418
This article claims LastPass has responded to their request for comment: https://www.howtogeek.com/776450/lastpass-says-it-didnt-leak...

"LastPass investigated recent reports of blocked login attempts and determined the activity is related to fairly common bot-related activity, in which a malicious or bad actor attempts to access user accounts (in this case, LastPass) using email addresses and passwords obtained from third-party breaches related to other unaffiliated services. It’s important to note that we do not have any indication that accounts were successfully accessed or that the LastPass service was otherwise compromised by an unauthorized party. We regularly monitor for this type of activity and will continue to take steps designed to ensure that LastPass, its users, and their data remain protected and secure."

Re: Ask HN: How did my LastPass master password get leaked?

#419

Earlier quoted context omitted.

My account was created 13 years ago.

What year was your master password last changed? It shows it in Vault > Account Settings. Or is your MP also 13 years old?

just an fyi: this can be deceptive, as you can change the security iterations while keeping the master password the same, which will reset this figure.

Re: Ask HN: How did my LastPass master password get leaked?

#420

This article claims LastPass has responded to their request for comment: https://www.howtogeek.com/776450/lastpass-says-it-didnt-leak ... "LastPass investigated recent reports of blocked login attempts and determined the activity is related to fairly common bot-related activity, in which a malicious or bad actor attempts to access user accounts (in this case, LastPass) using email addresses and passwords obtained fro…

Finally, if it is indeed not Lastpass's fault and as they say they dont store master password on their server, then there must be a software all these victims have in common. And it has to be fairly common so we could get at least 20 report on a HN thread.

Side Note: Interesting all it takes was AppleInsider publishing, getting some sort of traction. And Lastpass had a response within two hours.

Edit: This still doesn't make sense though. Unless @gregsadetsky had his computer access full hacked. Otherwise I dont see how his master password could have been stolen. Many of similar reports were from dead account they had a long time ago and wasn't actively being used.

Post reply on HN