Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

421–430 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#421

Earlier quoted context omitted.

Hey, I tested it here a few times, logging in with a wrong password does not generate an email, while logging in with the correct password from a new IP does generate that "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email. Could you try again logging in with a completely wrong password (to see if you get a email) and then logging in with the…

Interesting. I tested twice before with the wrong password and vpn and it generated the email but was not able to get in. I assume it would still show in account history because that event is the login verification email event. It isn’t sending that email for me at this point so maybe something has been corrected and LastPass will acknowledge something soon.

Just making sure, when you say wrong password, was the password completely wrong, or you changed the lower/upper case? There's a separate conversation on this topic here https://news.ycombinator.com/item?id=29708869

And again, to confirm, you used the wrong password and received an email saying "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" ?

Thanks!

Re: Ask HN: How did my LastPass master password get leaked?

#422

Earlier quoted context omitted.

Interesting. I tested twice before with the wrong password and vpn and it generated the email but was not able to get in. I assume it would still show in account history because that event is the login verification email event. It isn’t sending that email for me at this point so maybe something has been corrected and LastPass will acknowledge something soon.

For me, the behavior is: * Connecting from my own IP with wrong password: It tells me to "Check my master password and try again." * Connecting from another IP with wrong password: It tells me to "Check your inbox for an email from LastPass: " and also to check my login info. It's a bit odd that it tells me to check my email even though the master password I provided was incorrect.

Yeah, it's as if the error message (when using a wrong password on a new IP) was trying to not say that the password is wrong. It's just saying "check your email", just as if you had typed in the correct password (from a new IP).

But when you did attempt to login with a wrong password, you never received a "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email, correct?

Re: Ask HN: How did my LastPass master password get leaked?

#423

Trying to delete my old inactive account and it keeps throwing a meaningless error: "Something went wrong. : A". Wish I'd been more sensible and done it earlier.

I saw the same error earlier today, but trying to log into LastPass.com now shows this error: "You may have mistyped your email address. Try again."

At this stage, it's unclear if my account is already deleted, or if my account is flagged for something else. If it's deleted, it would have been ideal to send an email confirmation about it, but that hasn't happened so far.

Re: Ask HN: How did my LastPass master password get leaked?

#424
post #157

Earlier quoted context omitted.

So what do you do to remember passwords? Do you write them down on paper, or maybe save in browser? I'm curious, I've pondered writing down my pivotal passwords on paper and hiding in a book or something.

Personally I combine a hash of something site-specific, eg. name, purpose etc and a base alphanumeric string. Allows each account have their own specific credentials while not being overly burdensome to remember.

great, unless you get hit on the head.

Re: Ask HN: How did my LastPass master password get leaked?

#426

Earlier quoted context omitted.

For me, the behavior is: * Connecting from my own IP with wrong password: It tells me to "Check my master password and try again." * Connecting from another IP with wrong password: It tells me to "Check your inbox for an email from LastPass: " and also to check my login info. It's a bit odd that it tells me to check my email even though the master password I provided was incorrect.

Yeah, it's as if the error message (when using a wrong password on a new IP) was trying to not say that the password is wrong. It's just saying "check your email", just as if you had typed in the correct password (from a new IP). But when you did attempt to login with a wrong password, you never received a "Someone just used your master password to try to log in to your account from a device or location we didn't rec…

Correct, at 10:20 eastern I did receive the verify device/location email using an invalid password but it is no longer sending the email.

Re: Ask HN: How did my LastPass master password get leaked?

#427

Earlier quoted context omitted.

Yeah, it's as if the error message (when using a wrong password on a new IP) was trying to not say that the password is wrong. It's just saying "check your email", just as if you had typed in the correct password (from a new IP). But when you did attempt to login with a wrong password, you never received a "Someone just used your master password to try to log in to your account from a device or location we didn't rec…

Correct, at 10:20 eastern I did receive the verify device/location email using an invalid password but it is no longer sending the email.

That would truly be the best outcome possible -- that LastPass sent out "Someone just used your master password" emails incorrectly i.e. those were false positives.

Re: Ask HN: How did my LastPass master password get leaked?

#428
post #420

This article claims LastPass has responded to their request for comment: https://www.howtogeek.com/776450/lastpass-says-it-didnt-leak ... "LastPass investigated recent reports of blocked login attempts and determined the activity is related to fairly common bot-related activity, in which a malicious or bad actor attempts to access user accounts (in this case, LastPass) using email addresses and passwords obtained fro…

Finally, if it is indeed not Lastpass's fault and as they say they dont store master password on their server, then there must be a software all these victims have in common. And it has to be fairly common so we could get at least 20 report on a HN thread. Side Note: Interesting all it takes was AppleInsider publishing, getting some sort of traction. And Lastpass had a response within two hours. Edit: This still does…

I wonder how high the chance is of the master password itself having been reused, and of one of _those_ password sets getting compromised. Although I'd expect most people using a password manager would not be likely to reuse a master password.

On the other hand, my paranoia is now kicking in and I am on my way to change my (non-LastPass) master password, just in case past-me was very stupid a few years ago and then forgot about it...

Re: Ask HN: How did my LastPass master password get leaked?

#429
post #420

This article claims LastPass has responded to their request for comment: https://www.howtogeek.com/776450/lastpass-says-it-didnt-leak ... "LastPass investigated recent reports of blocked login attempts and determined the activity is related to fairly common bot-related activity, in which a malicious or bad actor attempts to access user accounts (in this case, LastPass) using email addresses and passwords obtained fro…

Finally, if it is indeed not Lastpass's fault and as they say they dont store master password on their server, then there must be a software all these victims have in common. And it has to be fairly common so we could get at least 20 report on a HN thread. Side Note: Interesting all it takes was AppleInsider publishing, getting some sort of traction. And Lastpass had a response within two hours. Edit: This still does…

Yeah, what doesn't make sense is that the emails we all received says:

"Someone just used your master password to try to log in to your account from a device or location we didn't recognize"

so either:

- the email was sent incorrectly i.e. our master passwords were /not/ used to login. In that case, why was the email sent?

- the email is correct i.e. someone does indeed have access to our master password (it was confirmed to me by one of the support agents -- that email is supposed to be sent out when the password is correct but used from a new IP) -- in that case, how is it possible that >20 people here were compromised?

In addition:

- many people here report never using their master password anywhere else

- and... not all accounts were old i.e. from 2017. A few accounts were from October/November 2021:

https://news.ycombinator.com/item?id=29711950

https://news.ycombinator.com/item?id=29710262

Re: Ask HN: How did my LastPass master password get leaked?

#430
post #420

This article claims LastPass has responded to their request for comment: https://www.howtogeek.com/776450/lastpass-says-it-didnt-leak ... "LastPass investigated recent reports of blocked login attempts and determined the activity is related to fairly common bot-related activity, in which a malicious or bad actor attempts to access user accounts (in this case, LastPass) using email addresses and passwords obtained fro…

Finally, if it is indeed not Lastpass's fault and as they say they dont store master password on their server, then there must be a software all these victims have in common. And it has to be fairly common so we could get at least 20 report on a HN thread. Side Note: Interesting all it takes was AppleInsider publishing, getting some sort of traction. And Lastpass had a response within two hours. Edit: This still does…

> Unless @gregsadetsky had his computer access full hacked.

He stored the LastPass password in KeePass, right? KeePass has had vulnerabilities allowing JavaScript on any web page read secrets from the KeePass storage.

I'm not saying that's what happened, but I don't think it's safe to say that "had his computer access full hacked.".

There's also plenty of NPM packages and similar which has had vulnerabilities which could have extracted passwords from whatever storage is used. Then it doesn't matter if the account was dead or not.

Also, it's not safe to say that "there must be a software all these victims have in common". An attacker can specialize in LastPass and may have purchased several credential lists right? Maybe some credentials were extracted via some vulnerable NPM library, maybe some via KeePass vuln, maybe some from password stuffing.

We're just speculating here, but I think what you're saying is a bit too definitive based on what we know so far. To me, LastPass seems a bit like a mess so I would not be surprised if they are to blame though.

Post reply on HN