Earlier quoted context omitted.
They are saying it’s just a credential stuffing attack and being that my master passphrase is only used for LastPass I’m hoping that is all that is going on. Their statement does say “It’s important to note that, at this time, we do not have any indication that accounts were successfully accessed” but I would still like confirmation the emails were sent even on invalid attempts.
But if your master passphrase is only used for LastPass (as is exactly my case -- I've never used it elsewhere), how can it can be credential stuffing? Or was the password breached from LastPass itself in the past? That's possible, but then it doesn't jell with people having this same issue with accounts created in November 2021. As far as I can tell, the "Someone just used your master password to try to log in to yo…
Ask HN: How did my LastPass master password get leaked?
451–460 of 529 posts
Re: Ask HN: How did my LastPass master password get leaked?
#452Earlier quoted context omitted.
It does make sense if you consider that there can be more than 1 vulnerability and that some attacker targeting LastPass may use recent password from a fresh vulnerability mixed with older passwords from some previous breach. I'm not actually following what does not make sense.
What's confusing to me is that my password was never used elsewhere (it was generated only to be used with LastPass and stored in KeePass). Other reports here say that their passwords were unique as well. I just have a doubt right now about the possibiliy that this attack was using passwords from past breaches (which is what LastPass is saying)
It's also entirely possible this is all is due to an entirely new vulnerability which hackers have uncovevered which the security community has not recognized yet. This is less likely, but whether it is the case or not doesn't change the fact this likes like a higher than average incident rate for indivual compromises, rather than a larger single event.
Re: Ask HN: How did my LastPass master password get leaked?
#453OP, the direction of this is totally based on these questions: - have you reused your LP master password as a password anywhere besides LP. - have you entered your LP master password into anything besides a LP login window. (edit: nvm, ya it went into the other PW manager. Without investigating that, not worth pointing the finger at LP and causing enterprise LP account usage chaos). - Do you enter the LP password int…
> - have you reused your LP master password as a password anywhere besides LP. No. I computer generated this password to use it for this LastPass account only. The password was secure (mixed alpha case + numbers, longer than 12 characters), and stored in an encrypted KeePass file. > - have you entered your LP master password into anything besides a LP login window. (edit: nvm, ya it went into the other PW manager. Wi…
Re: Ask HN: How did my LastPass master password get leaked?
#454Just happened to me one hour ago and got scared shitless. Time Monday, December 27, 2021 at 3:50 PM EST Location UNITED STATES IP address 107.173.195.83 Actions taken, in this order: - Head to *Advanced Options* -> *View account history* to see if anything suspicious is going on (nothing so far) - Disable Lastpass MFA and use Google Authenticator (Authy) - *Account Settings* -> click on *Show Advanced Settings* -> *D…
Re: Ask HN: How did my LastPass master password get leaked?
#455Earlier quoted context omitted.
Yeah, what doesn't make sense is that the emails we all received says: "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" so either: - the email was sent incorrectly i.e. our master passwords were /not/ used to login. In that case, why was the email sent? - the email is correct i.e. someone does indeed have access to our master password (it was conf…
An extra consideration is that LastPass claim to be monitoring their systems constantly, specifically call out automated attempts ("fairly common bot-related activity"), so we can assume that monitoring includes "attempts to login with wrong passwords" or "attempts to login to accounts that do not exist". That information would be a good way to identify a credential-stuffing attack with confidence, i.e: they might be…
The events are "failed login" and "Login verification email sent". The second one is what triggered the email and this event seems like it should only happen if you correctly login but their additional checks stop it from authenticating completely. The email has a button for "verify new device or location", which sure makes it seem like the login was successful.
I hope they just mangled up their event logger and it really should have been a failed login attempt but was logged as a valid login and triggered the email.
Re: Ask HN: How did my LastPass master password get leaked?
#456Earlier quoted context omitted.
One other thing to note is that by default lastpass allows reverting to your previous password for 30(?) days. The option is in account settings -> advanced -> "Allow master password changes to be reverted". To be safe you would probably want to disable that then change your password again. Just don't lose your new password as you then can't revert. See https://support.logmeininc.com/lastpass/help/recover-your-lo...
I last changed my master password in 2019, and it gave me the option to revert to previous password. So it's not just a 30 day thing.
"You can revert to your previous master password only if the change had taken place within the last 30 days."
I guess it is possible it is another UX issue and would fail if you tried, but that still isn't very reassuring.
Re: Ask HN: How did my LastPass master password get leaked?
#457Earlier quoted context omitted.
Begins with 160.116…
Exactly the same here!!!! Wow, this is fantastically bad.
196.19.204.79 Stated location: India WHOIS: Poland Warszawa Unit 117, Seychelles (Legacy) AFRINIC AS202769 COOP, US
160.116.206.37 Stated location: Germany WHOIS: Affiliated Computing Services, South Africa AFRINIC AS262287 Maxihost LTD, BR
168.81.122.153 Stated location: Germany WHOIS: Seychelles AFRINIC 202769 COOP, US
Someone is probably putting bogus information into the routes for these IP ranges. But what do all of these IPs have in common? According to my records, they are all related to a dodgy hosting provider in the Netherlands called Ecatel, now called Qasi Networks or IP Volume. And this is all disputed AFRINIC IP space, as per:
https://krebsonsecurity.com/2019/12/the-great-50m-african-ip...
Re: Ask HN: How did my LastPass master password get leaked?
#458Earlier quoted context omitted.
> - have you reused your LP master password as a password anywhere besides LP. No. I computer generated this password to use it for this LastPass account only. The password was secure (mixed alpha case + numbers, longer than 12 characters), and stored in an encrypted KeePass file. > - have you entered your LP master password into anything besides a LP login window. (edit: nvm, ya it went into the other PW manager. Wi…
Because it was stored in KeePass it sounds very likely that you’re copy pasting it into LastPass, which could have been intercepted by any malware that accessed the clipboard. Especially if you allow clipboard access to your phone from your computer.
What's harder to understand:
- with so many independent reports, including reports from accounts created as recently as Nov 2021, does it mean that we were all compromised by the same malware (across different devices, operating systems, etc.)
- even stranger things like:
https://twitter.com/Valcristerra/status/1475734357805572098
"Someone tried my @LastPass master password earlier yesterday and then someone just tried it again a few hours ago after I changed it. What the hell is going on?"
Re: Ask HN: How did my LastPass master password get leaked?
#459Earlier quoted context omitted.
That’s not a phishing site. That’s standard zero-click /smartlink monetization. It’s a lot to explain and I’m on mobile but it isn’t anything to do with phishing.
But, it certainly wasn't from Spectrum (my ISP), but they designed the page to make it look like it was. I agree that it could be totally unrelated to the root mystery though. But "everyone here fell for malware or got phished" seems like the most likely explanation, even if my answer happens to be otherwise incorrect.
Re: Ask HN: How did my LastPass master password get leaked?
#460Earlier quoted context omitted.
- Disable Lastpass MFA and use Google Authenticator (Authy) could you please explain this point? Isn't LastPass Authenticator equivalent to Google Authenticator, Authy or any other TOTP app? Or is there something that makes it less secure than other apps? Perhaps because it has cloud backups?
Lastpass MFA is not at all like Google Authenticator. The codes in Lastpass Authenticator are optional and can be bypassed. It's not secure at all.
How so? Are you saying that if I sign up for example to Dropbox and use Lastpass Authenticator for the 2FA, there is a way for me to log into Dropbox without retrieving the code from LastPass Authenticator? How would that work?