Earlier quoted context omitted.
> like having one 2fa verification each time you use a credential would work I'm interested in the technical idea here. You have a set of credentials encrypted with AES. So each vault item is encrypted with a symmetric key. How would you build a system to generate those keys using a rotating 2FA that isn't reversible by an attacker that can watch the entire process and can fake the timestamp or other elements on the…
Don't store the encrypted passwords locally. Have them on a server that deliver them only against a valid otp/push notification confirmation on your phone/yubikey tap etc.
LastPass says DevOps engineer’s hacked computer led to security breach in 2022
221–230 of 270 posts
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#222Earlier quoted context omitted.
Depends on what you mean by "the data decryption values". If you mean the encryption keys for the vaults themselves, no. Those are derived from the individual master passwords (in non-SSO setups, with SSO it's more complicated, and I don't fully understand the impact). So the attackers have a bunch of encrypted vaults from a backup. They can now brute-force the vaults, but if the original Master Passwords were secure…
the exposed passwords isn't even the worst part. it's the fact that user vaults sites are unencrypted so now attackers know every website that you thought was important enough to save. they know what bank you use, which adult sites you visit, what medical conditions you might have
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#223In my experience the majority of hacks are from a compromised laptop of a production engineer. Everyone blindly NPM installs away all their problems and no one checks signatures anymore. Most are using package managers like Brew that don't sign anything to begin with. At Distrust, my security consulting firm, we train all our clients to build production systems that require a minimum of two engineers to mutate and th…
In this case, the anonymous source says that Plex server was compromised, so I assume it was a developer's home PC, not a work laptop. The breach was preceded a couple of days by Plex corporate breach which devulged the engineer's credentials and home IP address. This would have allowed the attackers to access Plex sever remotely, after which the source claims they used an RCE to install a keylogger (and probably a b…
I think it's pretty dubious that they could pin it on a plex media server breach though. This is from the same company that sells logmein and goto; I haven't heard definitively that those pieces of software weren't installed on there.. Unless this machine was used for Plex and the occasional log in to work from home type thing, I doubt you could do the forensics on it with much reliability unless you got to it within days of the attack. If this is a normal devops guy? He's got 3 different chat apps, probably Steam, who knows what pirated crap is on there... Plex seems like a very convenient target; the plex corporate attack seems very very plausible as giving the attacker information though.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#224Earlier quoted context omitted.
Low value comment.
https://password-managers.bestreviews.net/faq/which-password...
One key thing however is I'm not seeing Bitwarden in this list, big ups to them.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#225Earlier quoted context omitted.
Eh banks run securely because it’s very difficult to steal money. Hard currency theft requires a physical attack and “digital currency” is just essentially a spreadsheet that requires a settlement mechanism such as correspondent banking to work. Banks transfers are nothing more than messages going between different branches and banks there is nothing being transferred other than orders. The attack surface on modern b…
All this might be true in the US where realtime transfers don’t really exist. But here in true UK where we‘be had realtime, high volume transfers for at least a decade, it’s very possible to steal digital money and move it on before the bank notices. Faster Payments in the UK are expected to be credited and spendable within 20min, normally it’s spendable within milliseconds. The actual settlements happen every few ho…
If your account all of a sudden has 10’s yet alone of 100’s 1000’s or of transfers in it will be quarantined.
HSBC locked my account just last week for 7 or 8 transfers of circa £10 all being made all in the same day from colleagues from my work since we bought a gift for someone that was leaving and settled the payment.
Authorized push payment fraud still does happen but it’s fairly negligible in the big scheme of things.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#226Earlier quoted context omitted.
Banks are a lot less secure than eg Google. And Google has fewer government mandates on them than banks do. (I worked both in banks and at Google.) However you are right that Google thinks they would lose a lot from being less secure.
Banks' true security is rooted in the real world.
Stealing cash from the vault: sure, that's 'real world' security.
Protecting their customers' data: nope, that's all digital.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#227Earlier quoted context omitted.
https://password-managers.bestreviews.net/faq/which-password...
Interesting that the article you link is from a website that recommends password managers? One key thing however is I'm not seeing Bitwarden in this list, big ups to them.
For myself, I just use google's password manager for non-critical passwords, and I use a single password for all my banking. I feel that is safer than using a password manager.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#228Only 4 engineers had this level of privilege at lastpass, how did the attacker identify the target? Linkedin... that's why you should not list where you work until you're no longer working there or list a completely different role than what you're currently in. I'm listed as a janitor of where I work. Only those that know me, know what I really do. I've tried to sell the policy forbidding employees from listing their…
> I'm listed as a janitor of where I work Do you get a lot of janitorial service headhunting spam?
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#229Only 4 engineers had this level of privilege at lastpass, how did the attacker identify the target? Linkedin... that's why you should not list where you work until you're no longer working there or list a completely different role than what you're currently in. I'm listed as a janitor of where I work. Only those that know me, know what I really do. I've tried to sell the policy forbidding employees from listing their…
Doesn't sound good for the employee. Why would people wanna work somewhere you can't speak about their job role? I think that'd filter out tons of applicants.
Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022
#230Only 4 engineers had this level of privilege at lastpass, how did the attacker identify the target? Linkedin... that's why you should not list where you work until you're no longer working there or list a completely different role than what you're currently in. I'm listed as a janitor of where I work. Only those that know me, know what I really do. I've tried to sell the policy forbidding employees from listing their…
Thank you for proposing to cure the lack of competence with the lack of freedom, but the easier source of target identity is the August 2022 breach of LastPass
Edit: Also wanted to mention 3 out of 4 incidents I am involved in is related to insider threat.