Live data from Hacker News

How did LastPass master passwords get compromised?

palant.info

111–120 of 189 posts

Re: How did LastPass master passwords get compromised?

#111

Earlier quoted context omitted.

Which is exactly what you say when facing an existential crisis. If you have a master password leak you either: 1. lie about it and the truth never comes to light 2. lie about it and get caught and the consequences are the same as if you came clean If LP suffered a master password leak then there is no benefit to telling the truth.

One advantage of telling the truth is that you don't go to prison for fraud. When evaluating this kind of conspiracy theory, it's important to consider the number of people who would have to remain silent for the conspiracy to survive, and to consider how much it would cost to keep that many people silent. In this case, it's at least a few dozen so I think it's fair to assume that such a lie would not survive very lo…

you’d need a microscope to see the overlap in the vein diagram of people who lie at work and the people who go to prison for lying at work.

Re: How did LastPass master passwords get compromised?

#112
post #69

Earlier quoted context omitted.

No, there is nothing. The complication with challenge/response schemes is that the server doesn’t know the master password – it only has that one hash, so it’s always comparing against it. There are PAKE protocols which work around this issue, but LastPass didn’t implement any of them (probably for historical reasons already, I think LastPass is older than most of these approaches). Normally, it isn’t such a huge vul…

Can you explain how PAKE would help here? Going just off Wikipedia, it is a key-establishment protocol "based only on their knowledge of a shared password". So I would expect that the shared password is the master password or its hash and the parties are the user and the LP server. So wouldn't using PAKE require the server to know your master password or its hash? That sounds the same as before. Is the idea that they…

No, modern PAKE protocols work without the server actually knowing the password. The server has a “verifier” that lets them tell whether the client’s response to a given challenge is correct. I’m no expert on this topic but https://blog.cryptographyengineering.com/2018/10/19/lets-tal... is a good start.

Re: How did LastPass master passwords get compromised?

#113

Earlier quoted context omitted.

I'm curious how that balances with everyone sharing random IP's from attempted account access. Where did those addresses come from? Why are users seeing them? Did the bug they're talking about cause bad data to be pushed to users dashboards?

Several people have reported that if you tried to log on from a new IP with incorrect master password, then you got an email saying that someone tried to log on using your master password even though that was not the case.

I was referring to the IP's being shown to users.[1]

So then; Is the bug also responsible for pushing bad data to the users dashboards? If this is really a bug, it's a complicated one. I'd be curious if those IP's are still being shown on the users end.

[1]: https://news.ycombinator.com/item?id=29705957

Re: How did LastPass master passwords get compromised?

#114

Earlier quoted context omitted.

LastPass's statement is extremely vague. _Why_ were these alerts triggered in error? What error triggered them?

The lack of that specific information doesn't make it vague in my view. If I tell to that the world appears to be shaped as a globe then that statement isn't vague just because I don't explain _why_ it appears shaped as a globe.

It's vague because we don't know why you consider it to appear to be a globe. Did you fly in a rocket and saw it or do you just think that round is the perfect shape and God wouldn't create the world in any other way?

Re: How did LastPass master passwords get compromised?

#115
post #27
post #25

So this blog seems to completely ignores LastPass statement from 2021-12-28: > Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. As a result, we have adjusted our security alert systems and this issue has since been resolved. Source: https://blog.lastpass.com/2021/12/unusual-attempted-login-ac... Source2: https:…

That statement is too squirrelly for me to trust if my passwords were stored with them. “SOME of these security alerts” “were LIKELY triggered” “HAS BEEN solved” (Emphasis mine) How can the issue be definitely solved if you aren’t sure that they were actually triggered in error, if they were in error then it’s only some of them.

That is the wording they have to use, right? They can't be certain that ALL the people who have seen these emails are caused by the buggy email notification code... I am sure some legitimate notifications were also sent out during the time, so how would they know if any of those were caused by something else?

Re: How did LastPass master passwords get compromised?

#116
Ongoing related thread: Unusual login activity was due to bug - https://news.ycombinator.com/item?id=29737973

Recent and related:

LastPass Login Attempted Activity Blocked – More Information - https://news.ycombinator.com/item?id=29731317 - Dec 2021 (12 comments)

LastPass says no passwords were compromised following breach scare - https://news.ycombinator.com/item?id=29723319 - Dec 2021 (68 comments)

LastPass users warned their master passwords are compromised - https://news.ycombinator.com/item?id=29716715 - Dec 2021 (313 comments)

Ask HN: How did my LastPass master password get leaked? - https://news.ycombinator.com/item?id=29705957 - Dec 2021 (508 comments)

Re: How did LastPass master passwords get compromised?

#117
post #27

Earlier quoted context omitted.

That statement is too squirrelly for me to trust if my passwords were stored with them. “SOME of these security alerts” “were LIKELY triggered” “HAS BEEN solved” (Emphasis mine) How can the issue be definitely solved if you aren’t sure that they were actually triggered in error, if they were in error then it’s only some of them.

That is the wording they have to use, right? They can't be certain that ALL the people who have seen these emails are caused by the buggy email notification code... I am sure some legitimate notifications were also sent out during the time, so how would they know if any of those were caused by something else?

It's not the wording they could use if they were sure that at least one alert was sent in error; then they wouldn't say it was likely, they'd say they know there were erroneous alerts. As it is, they're just speculating the alerts were wrong, which bodes very poorly.

Re: How did LastPass master passwords get compromised?

#118

Earlier quoted context omitted.

Oh absolutely. My point was strictly the assumption that many people can’t keep secrets. Depending on ideology, reprisals, or personal ethics (good and bad), secrets can be kept by a startlingly large group of people. I’ve seen estimates as high as 10% of the population of east Germany were spying on their neighbors.

I agree. Humans like sharing things, even if they shouldn't. We're bad at keeping secrets. I was just making the point that your claim of leaks in the military isn't necessarily comparable to a leak about a company. You do have a point about the large numbers of service members - that would raise the chances of something happening.

They are indeed different. But if they were compromised, it doesn't mean that all employees there know. It would probably be a handful of engineers only. Maybe one day one of them will make a blog post with all the details, however, there are more incentives to keep their mouths shut than otherwise. If they come publicly about this, they will get a lot of unwanted exposure (which most people don't like), they will certainly lose their jobs, they will have to talk about that in every job interview they do, they will likely get sued due to NDA breaches, etc which will actually prevent them from being hireable in many places (specially security firms). So, it's much easier for these people, if they morally object this, to just quit, find another job and move on. They'll likely tell their friends and family not to use lastpass, but that will only travel so far.

Re: How did LastPass master passwords get compromised?

#119
post #88
post #37

Earlier quoted context omitted.

It's easy for me to imagine how you get here. - Eng are still writing the postmortem - Marketing want to put out a statement - Eng know or suspect a bug exists that can trigger spurious notifications, but don't have sufficient logs to be able to reconstruct if that bug was in fact in play in production - Legal advises not to say anything definitive that they can't stand behind later I don't see any of that as particu…

No, they say "As a result, we have adjusted our security alert systems and this issue has since been resolved." They are claiming they know what the bug was.

They *need* to go into great detail if people are supposed to trust them with their digital life. That statement isn't nearly enough.

Re: How did LastPass master passwords get compromised?

#120
post #110

Earlier quoted context omitted.

> What I want to know is have I been compromised or not, They have been extremely clear that they have not found any signs of compromise. Did you miss that? Of course no company can technically guarantee that they have not being compromised. If you are looking for someone telling you at any point they are 100% confident no user accounts have been compromised, then you will pick a company lying to you.

They should be able to explain why so many people received the email though. Was there a fault in the notification system or not? Are they going to send messages to the individuals which received the notification in error? I get that direct evidence of a leak is difficult. However, a sudden surge of master passwords being known by third parties in uncorrelated accounts is a very good evidence that something happened.…

combine that with lastpass' history of security mistakes, the people in on hn claiming that they didn't reuse the master password, and the press releases gas lighting their users, I'm not buying their story for a second.
Post reply on HN