> “More specifically, the credentials for the servers were stolen from a DevOps engineer who had access to cloud storage at the company. This made it more difficult for LastPass to detect the suspicious activity.” This comes off as spin to me by LastPass or LogMeIn’s PR department. Even if this was the case, how is it possible for intrusion detection systems to not observe and report abnormally high egress traffic? D…
LastPass says DevOps engineer’s hacked computer led to security breach in 2022
41–50 of 270 posts
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#42Because the attacker did not need a separate __physical__ MFA (2nd F) after collecting the master password (1st F).
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#43This is not just to do with LastPass. It doesn't make sense why one would put their personal, most valuable passwords in the hand of another party. Of course, it's handy on a team between people.
When it comes to our bank accounts, do we trust someone like that with the pin numbers to our credit and bank cards?
One positive that comes out of this is that it raises awareness of thinking about the difference between security and convenience to manage one's own passwords.
One solution? Locating a zero, or no knowledge file storage system which is encrypted at rest and transit and placing your own files on it is the first start.
Spideroak used to fill that slot nicely (not sure if it's available anymore), and others I have heard about are sync.com and syncthing which do this just fine. Are there any other solutions that would be reasonably teachable to the average user?
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#44Am I assuming in this case the engineer was using his home PC to work? This isn't unheard of in the industry, Engineers using BYOD devices or similar to work from home. But with a company with a risk profile as high as LastPass this seems _incredibly dumb_. You would assume anyone with the keys to the kingdom was working on a company provided device, or any device that fits a compliance framework based on their own r…
My company isn't nearly as high profile or security focused and we're not allowed to use our own computers for any work related purposes,and our work laptops run threat detection software and we have a whitelist of software we're allowed to install. I'm surprised that LastPass's policies aren't at least that strict. My company has what I think is a big hole in this policy in that we're allowed to use our own phone fo…
It’s also possible that the stuff mobile devices can access are walled off from the internal network with a DMZ or firewall.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#45One benefit is that it made me audit my online accounts -- I removed many.
So: Be prepared to switch if you want this type of service. New normal.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#46Does this breach mean that LastPass effectively "transforms" 2FA into 1FA? Because the attacker did not need a separate __physical__ MFA (2nd F) after collecting the master password (1st F).
>Backup of LastPass MFA/Federation Database – contained copies of LastPass Authenticator seeds, telephone numbers used for the MFA backup option (if enabled), as well as a split knowledge component (the K2 “key”) used for LastPass federation (if enabled). This database was encrypted, but the separately-stored decryption key was included in the secrets stolen by the threat actor during the second incident.
Unless I am misunderstanding this, they mention to business users the need to reset shared secrets from OTP providers.
>For users of Duo Security, Symantec VIP, RSA SecurID, or SecureAuth, regenerate the shared secret for each respective MFA solution and paste the new shared secret into the respective MFA app configuration in the Admin Console.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#47Am I assuming in this case the engineer was using his home PC to work? This isn't unheard of in the industry, Engineers using BYOD devices or similar to work from home. But with a company with a risk profile as high as LastPass this seems _incredibly dumb_. You would assume anyone with the keys to the kingdom was working on a company provided device, or any device that fits a compliance framework based on their own r…
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#48Am I assuming in this case the engineer was using his home PC to work? This isn't unheard of in the industry, Engineers using BYOD devices or similar to work from home. But with a company with a risk profile as high as LastPass this seems _incredibly dumb_. You would assume anyone with the keys to the kingdom was working on a company provided device, or any device that fits a compliance framework based on their own r…
I don’t think he’s necessarily working on his pc. He probably just had a shared LastPass account between work and his pc.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#49Earlier quoted context omitted.
No? You'd have to carry out the third-party software RCE on each individual user to install a keylogger. This attack installed a keylogger on a single computer, then exfiltrated millions of passwords. Centralization is a bad thing. Same modus operandi maybe, but nowhere near the same impact.
Yes, but the article made it seem like they had RCE to his home PC. With that they installed the keylogger to retrieve the master key which they then used to decrypt the offline vault.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#50Only 4 engineers had this level of privilege at lastpass, how did the attacker identify the target? Linkedin... that's why you should not list where you work until you're no longer working there or list a completely different role than what you're currently in. I'm listed as a janitor of where I work. Only those that know me, know what I really do. I've tried to sell the policy forbidding employees from listing their…