Live data from Hacker News

LastPass says DevOps engineer’s hacked computer led to security breach in 2022

9to5mac.com

41–50 of 270 posts

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#41
post #3

> “More specifically, the credentials for the servers were stolen from a DevOps engineer who had access to cloud storage at the company. This made it more difficult for LastPass to detect the suspicious activity.” This comes off as spin to me by LastPass or LogMeIn’s PR department. Even if this was the case, how is it possible for intrusion detection systems to not observe and report abnormally high egress traffic? D…

It did, AWS alerted them on the traffic. It reads like they ignored it and when investigators later started going over that data it jumped up and slapped them.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#43
We're reminded that cloud services are ultimately someone else's computer. Putting one's secrets someone else's computer under the marketing of convenience is just that.

This is not just to do with LastPass. It doesn't make sense why one would put their personal, most valuable passwords in the hand of another party. Of course, it's handy on a team between people.

When it comes to our bank accounts, do we trust someone like that with the pin numbers to our credit and bank cards?

One positive that comes out of this is that it raises awareness of thinking about the difference between security and convenience to manage one's own passwords.

One solution? Locating a zero, or no knowledge file storage system which is encrypted at rest and transit and placing your own files on it is the first start.

Spideroak used to fill that slot nicely (not sure if it's available anymore), and others I have heard about are sync.com and syncthing which do this just fine. Are there any other solutions that would be reasonably teachable to the average user?

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#44
post #2

Am I assuming in this case the engineer was using his home PC to work? This isn't unheard of in the industry, Engineers using BYOD devices or similar to work from home. But with a company with a risk profile as high as LastPass this seems _incredibly dumb_. You would assume anyone with the keys to the kingdom was working on a company provided device, or any device that fits a compliance framework based on their own r…

My company isn't nearly as high profile or security focused and we're not allowed to use our own computers for any work related purposes,and our work laptops run threat detection software and we have a whitelist of software we're allowed to install. I'm surprised that LastPass's policies aren't at least that strict. My company has what I think is a big hole in this policy in that we're allowed to use our own phone fo…

If your company uses something like Duo they still can do some security posture on mobile devices like prevent rooted/jail broken devices or have a minimum iOS/Android version.

It’s also possible that the stuff mobile devices can access are walled off from the internal network with a DMZ or firewall.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#45
For anyone that had been deep in LastPass with passwords, I recently switched myself and convinced my family also. We switched to another [read recommendations] online centralized password manager. It takes a couple hours of your time-off; totally can stream some whatever show in the meantime to pass the time.

One benefit is that it made me audit my online accounts -- I removed many.

So: Be prepared to switch if you want this type of service. New normal.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#46
post #42

Does this breach mean that LastPass effectively "transforms" 2FA into 1FA? Because the attacker did not need a separate __physical__ MFA (2nd F) after collecting the master password (1st F).

Pretty much, limiting mfa options to otp only. Then the attacker getting access to customer shared secrets means they basically just have to guess the master password.

>Backup of LastPass MFA/Federation Database – contained copies of LastPass Authenticator seeds, telephone numbers used for the MFA backup option (if enabled), as well as a split knowledge component (the K2 “key”) used for LastPass federation (if enabled). This database was encrypted, but the separately-stored decryption key was included in the secrets stolen by the threat actor during the second incident.

Unless I am misunderstanding this, they mention to business users the need to reset shared secrets from OTP providers.

>For users of Duo Security, Symantec VIP, RSA SecurID, or SecureAuth, regenerate the shared secret for each respective MFA solution and paste the new shared secret into the respective MFA app configuration in the Admin Console.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#47
post #2

Am I assuming in this case the engineer was using his home PC to work? This isn't unheard of in the industry, Engineers using BYOD devices or similar to work from home. But with a company with a risk profile as high as LastPass this seems _incredibly dumb_. You would assume anyone with the keys to the kingdom was working on a company provided device, or any device that fits a compliance framework based on their own r…

This is completely unheard of for any company with any level of security. I’ve worked for 60 person startups that wouldn’t allow this.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#48
post #2

Am I assuming in this case the engineer was using his home PC to work? This isn't unheard of in the industry, Engineers using BYOD devices or similar to work from home. But with a company with a risk profile as high as LastPass this seems _incredibly dumb_. You would assume anyone with the keys to the kingdom was working on a company provided device, or any device that fits a compliance framework based on their own r…

I don’t think he’s necessarily working on his pc. He probably just had a shared LastPass account between work and his pc.

That’s absolutely no better.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#49
post #24

Earlier quoted context omitted.

No? You'd have to carry out the third-party software RCE on each individual user to install a keylogger. This attack installed a keylogger on a single computer, then exfiltrated millions of passwords. Centralization is a bad thing. Same modus operandi maybe, but nowhere near the same impact.

Yes, but the article made it seem like they had RCE to his home PC. With that they installed the keylogger to retrieve the master key which they then used to decrypt the offline vault.

I think the point is that all of the users of Lastpass whose passwords were put at risk through this one breach. Using Lastpass means that a single, high-value target is now an attack vector that can affect you. If you keep it offline yourself, you're not likely to be a high value target, and you won't have to worry about the 3rd party with your passwords being compromised.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#50

Only 4 engineers had this level of privilege at lastpass, how did the attacker identify the target? Linkedin... that's why you should not list where you work until you're no longer working there or list a completely different role than what you're currently in. I'm listed as a janitor of where I work. Only those that know me, know what I really do. I've tried to sell the policy forbidding employees from listing their…

I have an extra colleague that works for a company called [redacted] which looks strange on his linkedin updates.

https://www.linkedin.com/company/redacted/

Post reply on HN