Live data from Hacker News

Feds Link Cyberheist to 2022 LastPass Hacks

krebsonsecurity.com

31–40 of 266 posts

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#31
post #23

Earlier quoted context omitted.

Bitcoin has never been hacked. The victims did not practice proper key management. The victims got hacked because of their own insecure key management, not because of any vulnerability in Bitcoin. To claim otherwise is like claiming that because people can steal improperly secured code signing or TLS certificate private keys, all code signing and TLS certificates are inherently, fundamentally, and automatically broke…

You know what every other online money transfer mechanism has? An ability to reverse transactions in the case or error or fraud. Because those things happen all of the time.

I heard that there some block chain rollback thing that may be possible. I'm with ya. I don't put my money into high risk digital collectibles.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#32

LastPass understandably finds there to be no evidence linking the two. Uhm, OK. But what's also hard to believe is that people storing millions of dollars of "collectables" would not change their passwords on at least a yearly basis. I know that password rotation for its own sake is no longer best practice, but in this case it still seems quite prudent. No?

You can’t change the seed phrase for a derived wallet. You’d have to create a new one and transfer the assets.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#34

1Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially inconsequential.

Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…

One of the reasons I’m using Passwoed Store: https://www.passwordstore.org/

Though the tooling isn’t great – I’ll probably switch to Vaultwarden sometime this year.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#35
post #20
post #18

I'm a bit confused on how the LastPass hack enabled the loss of passwords. I assume it works the way that I understand 1Password to work which should mean this would still be very difficult to impossible to do. Can anyone explain what I'm wrong about in terms of how the password managers work or how LastPass works differently? So the way that I understand 1Password to work is that the decryption key is split in two:…

LastPass does not use the secret key concept that 1Password uses, it only uses a key derived from your password. After the breach they rushed to increase the hash iterations [1] and added features to let enterprise admins set minimum iterations [2] but of course it was too late at that point. [1] https://palant.info/2022/12/28/lastpass-breach-the-significa... [2] https://support.lastpass.com/s/document-item?language=…

Got it, thanks!

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#36

1Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially inconsequential.

Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…

It's such a pity that bitwarden's client doesn't work offline for modifying vaults (need to be online to be able to access the server implementation). I would switch from my old local vault 1password in an instant.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#37
post #30

Earlier quoted context omitted.

Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…

>But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file. technical possibilities aside, do you presume your grandchildren will be technically apt? I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.

Chances are, at least one of them will be.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#38
post #23

Earlier quoted context omitted.

Bitcoin has never been hacked. The victims did not practice proper key management. The victims got hacked because of their own insecure key management, not because of any vulnerability in Bitcoin. To claim otherwise is like claiming that because people can steal improperly secured code signing or TLS certificate private keys, all code signing and TLS certificates are inherently, fundamentally, and automatically broke…

You know what every other online money transfer mechanism has? An ability to reverse transactions in the case or error or fraud. Because those things happen all of the time.

Those mechanisms will abuse that power if pressured to do so. Which alternative is best depends on your threat model.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#39

Earlier quoted context omitted.

Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…

It's such a pity that bitwarden's client doesn't work offline for modifying vaults (need to be online to be able to access the server implementation). I would switch from my old local vault 1password in an instant.

I just have KeePass in a syncthing folder with a trigger to sync on open.

Technically I think I could drop the trigger if the desktop app would open by making a temporary file copy and syncing back (ironically Keepass2Android is very good at this).

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#40

“Bitcoin has never been hacked” Don’t have to hack crypto to steal all the crypto.

Bitcoin has never been hacked. The victims did not practice proper key management. The victims got hacked because of their own insecure key management, not because of any vulnerability in Bitcoin. To claim otherwise is like claiming that because people can steal improperly secured code signing or TLS certificate private keys, all code signing and TLS certificates are inherently, fundamentally, and automatically broke…

Has the dollar been hacked?
Post reply on HN