Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

501–510 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#501

Earlier quoted context omitted.

Syncthing works great even behind a NAT, not sure how it works but it just works for me (might depend on your NAT though)

I've had zero success with nat hole punching in the past, on multiple networks. Maybe I'm just unlucky. :)

Some routers have UPnP disabled by default, maybe enabling that would help?

Re: Ask HN: How did my LastPass master password get leaked?

#502
post #260

Earlier quoted context omitted.

Unfortunately, the email sent from LastPass specifically says "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" LastPass support did confirm that the IP from Brazil did have the master password. I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the mas…

Your test of a login attempt with a wrong password was a good idea, but did you do it from a location they would not recognize? That's what you need to do to rule out that the Brazil message was not merely a wrong password login attempt. I'm a bit skeptical that if someone tried a login with the correct password but from an unrecognized location that they would block it by default. People do travel and do change devi…

I've had that exact thing happen before when logging on using my phone's hotspot. It did really suck, and what I ended up doing is remoting into my PC at home. I feel like they care a lot more about false negatives versus false positives.

Re: Ask HN: How did my LastPass master password get leaked?

#503
post #94

Earlier quoted context omitted.

There was no 1Password to LastPass importer at the time I wrote that (believe me, I looked because I have better things to do than write apps to benefit a commercial entity like agilebits otherwise), and of course the code is published on GitHub and released under the MIT license. It's very short and simple and rather easy to review. It's also a .NET executable, which is ridiculously easy to reverse-compile back to C…

Just because you put a warning label on a bad practice doesn't mean it's a good practice. Pumping your passwords through some random code on Github that has a "be smart" label doesn't make it a good idea. Would be so easy to imitate you, reupload the code with an exploit. For giggles, if I was making this into a hijack I'd leave all your warnings in and even make them bigger and more obvious, confident in the knowled…

Well, why shouldn't people who already use insecure software with vulnerabilities (LastPass) without the possibility to even audit the code also run some code written by other people they don't know?

Re: Ask HN: How did my LastPass master password get leaked?

#504

Earlier quoted context omitted.

Hey, could you please confirm whether you have uBlock origin installed in the following thread? https://news.ycombinator.com/item?id=29719033 It's not the most scientifically accurate method, but a few people and I are trying to rule out / determine which software in common all of us might have. Thanks!

I feel this is like a Reddit detective moment. Almost everyone here is going to have uBlock Origin installed.

Yeah I agree. And a few users who were compromised confirmed not having uBlock. So yeah. False trail.

Re: Ask HN: How did my LastPass master password get leaked?

#505
post #27

Earlier quoted context omitted.

Yes, I do copy/paste from my local password manager. A clipboard scraper is a possibility, yes. I hadn't logged into that LastPass account for years, so it's definitely not me who attempted to login earlier. Re: LastPass, is there another cloud-based tool that's generally considered as more trustworthy? Bitwarden? Thanks

Personally I just stick to local Keepass database files. I’ve never ventured into the cloud based services. If you are really worried about it, do you really need to use a cloud based password service? Sure, managing the KeePass files by hand is certainly more cumbersome, but to me it’s worth it for the security/ peace of mind gains. I have never put my DB or key files in the cloud. And when I need to sync them up ov…

Just configure keepass to sync with a file stored online when opening or saving the database and you have the same convenience. Syncing the main database file itself fails if different systems change the file without reloading in-between, but with sync configured it works perfectly.

Re: Ask HN: How did my LastPass master password get leaked?

#506

Earlier quoted context omitted.

They are saying it’s just a credential stuffing attack and being that my master passphrase is only used for LastPass I’m hoping that is all that is going on. Their statement does say “It’s important to note that, at this time, we do not have any indication that accounts were successfully accessed” but I would still like confirmation the emails were sent even on invalid attempts.

But if your master passphrase is only used for LastPass (as is exactly my case -- I've never used it elsewhere), how can it can be credential stuffing? Or was the password breached from LastPass itself in the past? That's possible, but then it doesn't jell with people having this same issue with accounts created in November 2021. As far as I can tell, the "Someone just used your master password to try to log in to yo…

I was never able to successfully trigger the false positive last night but I believe the most recent explanation from LastPass is in line with what I have been seeing. Intermittent false positive emails.

https://www.techradar.com/au/news/lastpass-accidentally-scar...

Re: Ask HN: How did my LastPass master password get leaked?

#507

Earlier quoted context omitted.

But if your master passphrase is only used for LastPass (as is exactly my case -- I've never used it elsewhere), how can it can be credential stuffing? Or was the password breached from LastPass itself in the past? That's possible, but then it doesn't jell with people having this same issue with accounts created in November 2021. As far as I can tell, the "Someone just used your master password to try to log in to yo…

I was never able to successfully trigger the false positive last night but I believe the most recent explanation from LastPass is in line with what I have been seeing. Intermittent false positive emails. https://www.techradar.com/au/news/lastpass-accidentally-scar...

Yeah, just saw their new announcement (thanks for doing those tests yesterday by the way!)

I don't know how much to read into their use of "some" and "likely" i.e. "some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error"

I would want to know whether they can demonstrate that wrong passwords were used in this attack. And have an explanation for those users who received the email a 2nd time after changing their passwords.

Re: Ask HN: How did my LastPass master password get leaked?

#508
post #83

Earlier quoted context omitted.

Unless I’m misremembering, the login to their general system was done by never sending the password over the wire. Instead they used js to do some sort of hashing type system locally. But during the heartbleed attack when their systems were shown to be vulnerable, that was one of their arguments as to why it wasn’t so bad.

> Instead they used js to do some sort of hashing type system locally. Just the other day a co-worker brought up this idea as an offhand remark. After bouncing it off those present, it took him all of twenty seconds to see why it might do harm and will do little good. You'd think a password manager would employ some security minded people who could shoot down ideas that bad immediately.

What were the counterpoints?

Re: Ask HN: How did my LastPass master password get leaked?

#509
post #81

Earlier quoted context omitted.

just checked my email. last pass account was created in 2015, not sure if the current leaked password has been in use that whole time, but it has definitely been quite a few years. moved over to 1passward in march of this year and likely have not used last pass at all since.

What prompted the move to 1password? Curious as I am deciding myself which service to use.

I was so pissed at LastPass when the Firefox extension stopped working when Firefox Quantum was released, they didn't have an ETA for fixing it, their support is completely crap. I gave up no LastPass with 9 months left on my subscription and moved to 1Password. Also, LastPass UX is still awful to this day (I have to use it for work). Migrating from LastPass to 1Password was like migrating from Linux to Mac. It's more expensive, but it's sooooo much better and polished.

Re: Ask HN: How did my LastPass master password get leaked?

#510
post #500

Same thing for me. I last changed my master password on Oct 4 2021. password never used elsewhere and stored only in my head, which makes me suspect a bad chrome extension. ``` Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look. Was this you? Account xxx@xxx.com Time Monday, December 27…

It’s unlikely to be due to a browser extension. A browser extension that can steal your master password can steal all the other passwords as well, it doesn’t need LastPass for that. More importantly, an extension can only steal your master password when it is used – yet several people reported not having used LastPass for a year or more. It’s still not impossible that an extension has been stealing master passwords f…

>Given that most people write about old accounts, my original suspicion

No - there are now reports of same thing happening with recent changes to password

https://twitter.com/Valcristerra/status/1475734357805572098

Post reply on HN