Live data from Hacker News

LastPass says DevOps engineer’s hacked computer led to security breach in 2022

9to5mac.com

221–230 of 270 posts

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#221
post #216

Earlier quoted context omitted.

> like having one 2fa verification each time you use a credential would work I'm interested in the technical idea here. You have a set of credentials encrypted with AES. So each vault item is encrypted with a symmetric key. How would you build a system to generate those keys using a rotating 2FA that isn't reversible by an attacker that can watch the entire process and can fake the timestamp or other elements on the…

Don't store the encrypted passwords locally. Have them on a server that deliver them only against a valid otp/push notification confirmation on your phone/yubikey tap etc.

That's a valid solution, but I would not select a password vault that was dependent on network access. Offline access to secrets is important to me. Other people might feel differently, of course.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#222

Earlier quoted context omitted.

Depends on what you mean by "the data decryption values". If you mean the encryption keys for the vaults themselves, no. Those are derived from the individual master passwords (in non-SSO setups, with SSO it's more complicated, and I don't fully understand the impact). So the attackers have a bunch of encrypted vaults from a backup. They can now brute-force the vaults, but if the original Master Passwords were secure…

the exposed passwords isn't even the worst part. it's the fact that user vaults sites are unencrypted so now attackers know every website that you thought was important enough to save. they know what bank you use, which adult sites you visit, what medical conditions you might have

I understand that some people feel that that is sensitive data. It's not a big threat for me. My ISP and Google already has that data in many cases (IP destination data, DNS lookups, etc.) YMMV.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#223
post #202
post #168

In my experience the majority of hacks are from a compromised laptop of a production engineer. Everyone blindly NPM installs away all their problems and no one checks signatures anymore. Most are using package managers like Brew that don't sign anything to begin with. At Distrust, my security consulting firm, we train all our clients to build production systems that require a minimum of two engineers to mutate and th…

In this case, the anonymous source says that Plex server was compromised, so I assume it was a developer's home PC, not a work laptop. The breach was preceded a couple of days by Plex corporate breach which devulged the engineer's credentials and home IP address. This would have allowed the attackers to access Plex sever remotely, after which the source claims they used an RCE to install a keylogger (and probably a b…

If you don't need remote access to your plex, you should disable it. The cache features are pretty good, so you could download media while at home and have it on a device in the car or at work pretty easily.

I think it's pretty dubious that they could pin it on a plex media server breach though. This is from the same company that sells logmein and goto; I haven't heard definitively that those pieces of software weren't installed on there.. Unless this machine was used for Plex and the occasional log in to work from home type thing, I doubt you could do the forensics on it with much reliability unless you got to it within days of the attack. If this is a normal devops guy? He's got 3 different chat apps, probably Steam, who knows what pirated crap is on there... Plex seems like a very convenient target; the plex corporate attack seems very very plausible as giving the attacker information though.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#224

Earlier quoted context omitted.

Low value comment.

https://password-managers.bestreviews.net/faq/which-password...

Interesting that the article you link is from a website that recommends password managers?

One key thing however is I'm not seeing Bitwarden in this list, big ups to them.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#225

Earlier quoted context omitted.

Eh banks run securely because it’s very difficult to steal money. Hard currency theft requires a physical attack and “digital currency” is just essentially a spreadsheet that requires a settlement mechanism such as correspondent banking to work. Banks transfers are nothing more than messages going between different branches and banks there is nothing being transferred other than orders. The attack surface on modern b…

All this might be true in the US where realtime transfers don’t really exist. But here in true UK where we‘be had realtime, high volume transfers for at least a decade, it’s very possible to steal digital money and move it on before the bank notices. Faster Payments in the UK are expected to be credited and spendable within 20min, normally it’s spendable within milliseconds. The actual settlements happen every few ho…

I’m from the UK that’s for relatively very small amounts and it’s insured, this is the cost of doing business and there are still a lot of fraud checks especially for new payees.

If your account all of a sudden has 10’s yet alone of 100’s 1000’s or of transfers in it will be quarantined.

HSBC locked my account just last week for 7 or 8 transfers of circa £10 all being made all in the same day from colleagues from my work since we bought a gift for someone that was leaving and settled the payment.

Authorized push payment fraud still does happen but it’s fairly negligible in the big scheme of things.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#226
post #108

Earlier quoted context omitted.

Banks are a lot less secure than eg Google. And Google has fewer government mandates on them than banks do. (I worked both in banks and at Google.) However you are right that Google thinks they would lose a lot from being less secure.

Banks' true security is rooted in the real world.

Depends on what you are talking about.

Stealing cash from the vault: sure, that's 'real world' security.

Protecting their customers' data: nope, that's all digital.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#227

Earlier quoted context omitted.

https://password-managers.bestreviews.net/faq/which-password...

Interesting that the article you link is from a website that recommends password managers? One key thing however is I'm not seeing Bitwarden in this list, big ups to them.

Well, that's probably because they're making money off adverts for password managers. Just because a service hasn't been hacked yet doesn't mean it is secure.

For myself, I just use google's password manager for non-critical passwords, and I use a single password for all my banking. I feel that is safer than using a password manager.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#228

Only 4 engineers had this level of privilege at lastpass, how did the attacker identify the target? Linkedin... that's why you should not list where you work until you're no longer working there or list a completely different role than what you're currently in. I'm listed as a janitor of where I work. Only those that know me, know what I really do. I've tried to sell the policy forbidding employees from listing their…

> I'm listed as a janitor of where I work Do you get a lot of janitorial service headhunting spam?

I get a few every month, all contract gigs working mostly at schools / government places.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#229

Only 4 engineers had this level of privilege at lastpass, how did the attacker identify the target? Linkedin... that's why you should not list where you work until you're no longer working there or list a completely different role than what you're currently in. I'm listed as a janitor of where I work. Only those that know me, know what I really do. I've tried to sell the policy forbidding employees from listing their…

Doesn't sound good for the employee. Why would people wanna work somewhere you can't speak about their job role? I think that'd filter out tons of applicants.

Plenty of people work in roles they can't speak about when engaging with the government. All I'm advocating is not to broadcast it to the world, as it puts the person and their employer in danger.

Re: LastPass says DevOps engineer’s hacked computer led to security breach in 2022

#230
post #173

Only 4 engineers had this level of privilege at lastpass, how did the attacker identify the target? Linkedin... that's why you should not list where you work until you're no longer working there or list a completely different role than what you're currently in. I'm listed as a janitor of where I work. Only those that know me, know what I really do. I've tried to sell the policy forbidding employees from listing their…

Thank you for proposing to cure the lack of competence with the lack of freedom, but the easier source of target identity is the August 2022 breach of LastPass

Insider Threat is real, can't discount that at all. What I can tell you as someone who participates in OSINT competitions and has engaged in red team activities, Linkedin is always the first stop when shopping for info.

Edit: Also wanted to mention 3 out of 4 incidents I am involved in is related to insider threat.

Post reply on HN