Earlier quoted context omitted.
Syncthing works great even behind a NAT, not sure how it works but it just works for me (might depend on your NAT though)
I've had zero success with nat hole punching in the past, on multiple networks. Maybe I'm just unlucky. :)
Ask HN: How did my LastPass master password get leaked?
501–510 of 529 posts
Re: Ask HN: How did my LastPass master password get leaked?
#502Earlier quoted context omitted.
Unfortunately, the email sent from LastPass specifically says "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" LastPass support did confirm that the IP from Brazil did have the master password. I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the mas…
Your test of a login attempt with a wrong password was a good idea, but did you do it from a location they would not recognize? That's what you need to do to rule out that the Brazil message was not merely a wrong password login attempt. I'm a bit skeptical that if someone tried a login with the correct password but from an unrecognized location that they would block it by default. People do travel and do change devi…
Re: Ask HN: How did my LastPass master password get leaked?
#503Earlier quoted context omitted.
There was no 1Password to LastPass importer at the time I wrote that (believe me, I looked because I have better things to do than write apps to benefit a commercial entity like agilebits otherwise), and of course the code is published on GitHub and released under the MIT license. It's very short and simple and rather easy to review. It's also a .NET executable, which is ridiculously easy to reverse-compile back to C…
Just because you put a warning label on a bad practice doesn't mean it's a good practice. Pumping your passwords through some random code on Github that has a "be smart" label doesn't make it a good idea. Would be so easy to imitate you, reupload the code with an exploit. For giggles, if I was making this into a hijack I'd leave all your warnings in and even make them bigger and more obvious, confident in the knowled…
Re: Ask HN: How did my LastPass master password get leaked?
#504Earlier quoted context omitted.
Hey, could you please confirm whether you have uBlock origin installed in the following thread? https://news.ycombinator.com/item?id=29719033 It's not the most scientifically accurate method, but a few people and I are trying to rule out / determine which software in common all of us might have. Thanks!
I feel this is like a Reddit detective moment. Almost everyone here is going to have uBlock Origin installed.
Re: Ask HN: How did my LastPass master password get leaked?
#505Earlier quoted context omitted.
Yes, I do copy/paste from my local password manager. A clipboard scraper is a possibility, yes. I hadn't logged into that LastPass account for years, so it's definitely not me who attempted to login earlier. Re: LastPass, is there another cloud-based tool that's generally considered as more trustworthy? Bitwarden? Thanks
Personally I just stick to local Keepass database files. I’ve never ventured into the cloud based services. If you are really worried about it, do you really need to use a cloud based password service? Sure, managing the KeePass files by hand is certainly more cumbersome, but to me it’s worth it for the security/ peace of mind gains. I have never put my DB or key files in the cloud. And when I need to sync them up ov…
Re: Ask HN: How did my LastPass master password get leaked?
#506Earlier quoted context omitted.
They are saying it’s just a credential stuffing attack and being that my master passphrase is only used for LastPass I’m hoping that is all that is going on. Their statement does say “It’s important to note that, at this time, we do not have any indication that accounts were successfully accessed” but I would still like confirmation the emails were sent even on invalid attempts.
But if your master passphrase is only used for LastPass (as is exactly my case -- I've never used it elsewhere), how can it can be credential stuffing? Or was the password breached from LastPass itself in the past? That's possible, but then it doesn't jell with people having this same issue with accounts created in November 2021. As far as I can tell, the "Someone just used your master password to try to log in to yo…
https://www.techradar.com/au/news/lastpass-accidentally-scar...
Re: Ask HN: How did my LastPass master password get leaked?
#507Earlier quoted context omitted.
But if your master passphrase is only used for LastPass (as is exactly my case -- I've never used it elsewhere), how can it can be credential stuffing? Or was the password breached from LastPass itself in the past? That's possible, but then it doesn't jell with people having this same issue with accounts created in November 2021. As far as I can tell, the "Someone just used your master password to try to log in to yo…
I was never able to successfully trigger the false positive last night but I believe the most recent explanation from LastPass is in line with what I have been seeing. Intermittent false positive emails. https://www.techradar.com/au/news/lastpass-accidentally-scar...
I don't know how much to read into their use of "some" and "likely" i.e. "some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error"
I would want to know whether they can demonstrate that wrong passwords were used in this attack. And have an explanation for those users who received the email a 2nd time after changing their passwords.
Re: Ask HN: How did my LastPass master password get leaked?
#508Earlier quoted context omitted.
Unless I’m misremembering, the login to their general system was done by never sending the password over the wire. Instead they used js to do some sort of hashing type system locally. But during the heartbleed attack when their systems were shown to be vulnerable, that was one of their arguments as to why it wasn’t so bad.
> Instead they used js to do some sort of hashing type system locally. Just the other day a co-worker brought up this idea as an offhand remark. After bouncing it off those present, it took him all of twenty seconds to see why it might do harm and will do little good. You'd think a password manager would employ some security minded people who could shoot down ideas that bad immediately.
Re: Ask HN: How did my LastPass master password get leaked?
#509Earlier quoted context omitted.
just checked my email. last pass account was created in 2015, not sure if the current leaked password has been in use that whole time, but it has definitely been quite a few years. moved over to 1passward in march of this year and likely have not used last pass at all since.
What prompted the move to 1password? Curious as I am deciding myself which service to use.
Re: Ask HN: How did my LastPass master password get leaked?
#510Same thing for me. I last changed my master password on Oct 4 2021. password never used elsewhere and stored only in my head, which makes me suspect a bad chrome extension. ``` Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look. Was this you? Account xxx@xxx.com Time Monday, December 27…
It’s unlikely to be due to a browser extension. A browser extension that can steal your master password can steal all the other passwords as well, it doesn’t need LastPass for that. More importantly, an extension can only steal your master password when it is used – yet several people reported not having used LastPass for a year or more. It’s still not impossible that an extension has been stealing master passwords f…
No - there are now reports of same thing happening with recent changes to password