Earlier quoted context omitted.
Wouldn’t that be susceptible to the same attack?
No? You'd have to carry out the third-party software RCE on each individual user to install a keylogger. This attack installed a keylogger on a single computer, then exfiltrated millions of passwords. Centralization is a bad thing. Same modus operandi maybe, but nowhere near the same impact.
LastPass says DevOps engineer’s hacked computer led to security breach in 2022
31–40 of 270 posts
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#32> “More specifically, the credentials for the servers were stolen from a DevOps engineer who had access to cloud storage at the company. This made it more difficult for LastPass to detect the suspicious activity.” This comes off as spin to me by LastPass or LogMeIn’s PR department. Even if this was the case, how is it possible for intrusion detection systems to not observe and report abnormally high egress traffic? D…
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#33So, with most password managers, when you authenticate on a new device, you are prompted for MFA. The user had a keylogger installed on their machine, so the attacker could collect the master password, but how did they login to the vault on a new machine without MFA? Did they get the MFA seed and login on a different machine, and nobody received a "You're using LastPass on a new machine, if this wasn't you..." messag…
Better trust nobody when it comes to security. I'm using offline keypass. It's great.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#34Am I assuming in this case the engineer was using his home PC to work? This isn't unheard of in the industry, Engineers using BYOD devices or similar to work from home. But with a company with a risk profile as high as LastPass this seems _incredibly dumb_. You would assume anyone with the keys to the kingdom was working on a company provided device, or any device that fits a compliance framework based on their own r…
My company isn't nearly as high profile or security focused and we're not allowed to use our own computers for any work related purposes,and our work laptops run threat detection software and we have a whitelist of software we're allowed to install. I'm surprised that LastPass's policies aren't at least that strict. My company has what I think is a big hole in this policy in that we're allowed to use our own phone fo…
Waiting for the rebrand and the incoming lawsuits.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#35I'm listed as a janitor of where I work. Only those that know me, know what I really do.
I've tried to sell the policy forbidding employees from listing their positions or where they work on linkedin, each time management frowns and says no. One day they'll come around...
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#36>In December, we notified a subset of customers whose SCIM, Enterprise API, and SAML keys were stored in unencrypted form. This only affected customers who joined LastPass and used these services in 2019 or before.
This part just blew my mind.
>Important: Since resetting MFA shared secrets destroys all LastPass sessions and trusted devices for these users, these users will need to log back in, go through location verification, and re-enable their respective MFA apps to continue using the service.
I feel sorry for everyones internal helpdesk. This is going to be brutal.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#37Only 4 engineers had this level of privilege at lastpass, how did the attacker identify the target? Linkedin... that's why you should not list where you work until you're no longer working there or list a completely different role than what you're currently in. I'm listed as a janitor of where I work. Only those that know me, know what I really do. I've tried to sell the policy forbidding employees from listing their…
Forbidding employees from listing their role on LinkedIn would put them at a major disadvantage in job searching and recruiting.
Forcing employees to hide their role is unreasonable. The company doesn’t own the employee.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#38Only 4 engineers had this level of privilege at lastpass, how did the attacker identify the target? Linkedin... that's why you should not list where you work until you're no longer working there or list a completely different role than what you're currently in. I'm listed as a janitor of where I work. Only those that know me, know what I really do. I've tried to sell the policy forbidding employees from listing their…
*Please don’t pay this mob money, they are rent seeking, bottom feeding scum.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#39Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#40Am I assuming in this case the engineer was using his home PC to work? This isn't unheard of in the industry, Engineers using BYOD devices or similar to work from home. But with a company with a risk profile as high as LastPass this seems _incredibly dumb_. You would assume anyone with the keys to the kingdom was working on a company provided device, or any device that fits a compliance framework based on their own r…
I don’t think he’s necessarily working on his pc. He probably just had a shared LastPass account between work and his pc.