Ask HN: How did my LastPass master password get leaked?
141–150 of 529 posts
Re: Ask HN: How did my LastPass master password get leaked?
#142was it a login attempt or an actual login?
Re: Ask HN: How did my LastPass master password get leaked?
#143Re: Ask HN: How did my LastPass master password get leaked?
#144My girlfriend once asked me why I don't use a password manager like LastPass. A week later she got locked out of her LastPass account because she was inadvertently using an enterprise account that one of her clients forced her to use while on a project. And even though she was paying for her own premium LastPass subscription, the support experience had was terrible. Issue was resolved when the client was able to unlo…
Re: Ask HN: How did my LastPass master password get leaked?
#145Earlier quoted context omitted.
Hmm. So I don't know if this means anything, but I was googling for the IP address and wound up at https://ipinfo.io/160.116.88.235 which says hostname: visit.keznews.com. When you go to that hostname, it's one of the best phishing sites I've ever seen. They dynamically inserted my ISP's logo (Spectrum) and tried to do a phishing attempt: https://i.imgur.com/C9HQw1c.png The full non-clickable URL: https://us.poonstat…
That’s not a phishing site. That’s standard zero-click /smartlink monetization. It’s a lot to explain and I’m on mobile but it isn’t anything to do with phishing.
I agree that it could be totally unrelated to the root mystery though. But "everyone here fell for malware or got phished" seems like the most likely explanation, even if my answer happens to be otherwise incorrect.
Re: Ask HN: How did my LastPass master password get leaked?
#146Earlier quoted context omitted.
Hey, That's quite possible, for sure. I am not beyond/above/below being phished like anyone else, ha! The issue -- what makes it perplexing -- is that I haven't used this LastPass password since 2017. I know because this LastPass account was only used to share passwords within an org that I left back then. Is it possible that I was phished 4 years ago, and they sat on the password? Sure. But 2 other people in this th…
Couldn't it just be that someone got a copy of the password some years ago and now sold the list of credentials to someone else, who then tried to use it? Maybe the original owner of the list didn't realize some of the credentials was for LastPass, for example. I'm still seeing hackers trying to log on using passwords I haven't used in ~10 years, because it's on a list somewhere.
Re: Ask HN: How did my LastPass master password get leaked?
#147Earlier quoted context omitted.
just checked my email. last pass account was created in 2015, not sure if the current leaked password has been in use that whole time, but it has definitely been quite a few years. moved over to 1passward in march of this year and likely have not used last pass at all since.
What prompted the move to 1password? Curious as I am deciding myself which service to use.
Edit: I found an old post from about 5 years ago on a vulnerability in LastPass’s extension [0]
Re: Ask HN: How did my LastPass master password get leaked?
#148This just happened to me today, but login location was Bangkok. I also haven’t used my lastpass account in almost 2 years since I switched to Bitwarden, so no way this could have stolen from my computer recently
Re: Ask HN: How did my LastPass master password get leaked?
#149People are always saying (smugly) how crucial LastPass is...
If the former: I haven't noticed that -- usually folks on HN seem to recommend 1Password or BitWarden.
If the latter: Password managers are important to resist credential stuffing attacks through password reuse.
While I don't like that many of them force you to upload your secrets to the cloud (LastPass, 1Password 8, etc), it's still a better security posture than having your weakest link be every site on which you've used the same password.
Re: Ask HN: How did my LastPass master password get leaked?
#150You can kill existing sessions - see account settings destroy sessions.
Edit: All looks normal my side. No emails, no login attempts, but will change pass just in case