Live data from Hacker News

GoToMyPC has been hacked, all customer passwords reset

status.gotomypc.com

161–170 of 171 posts

Re: GoToMyPC has been hacked, all customer passwords reset

#161

Earlier quoted context omitted.

Well as long as you 'feel' that way, it must be true. Lastpass (supposedly) stores the encrypted password vault, never the decrypted. Decryption occurs on the users end. You would need to either have a keylogger on the target users machine to grab their master password, or compromise the software. Neither is impossible, but both are a little harder than simply break in and access Lastpass's storage. I say supposedly…

I didn't make that claim; why add that attitude to an otherwise pleasant conversation? When disagreeing, please reply to the argument instead of calling names. E.g. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3." https://news.ycombinator.com/newsguidelines.html

Yes you did make that claim. You said that you feel there is a high likelihood that lastpass is compromised. You have no evidence or proof of this, just a gut feeling presented as some sort of fact or 'just asking questions.'

"I feel like it's almost certain that Lastpass is owned"

Re: GoToMyPC has been hacked, all customer passwords reset

#162
post #128
post #48

They don't really say it has been hacked, just that being a target of an advanced password attack. It might mean attackers are using password lists from previous leaks (linkedin), so they decided to force a pass reset to everyone. Or maybe they got hacked. Who knows, not very clear.

As has been proven many times before, "very sophisticated", "advanced", "highly complex" etc. actually generally means "our staff was humiliatingly negligent" in some regard. i.e. they were spearphished and the attacker pulled a password database from their internal network. It seems very odd that they resorted to resetting all passwords instead of just affected or potentially affected accounts as Github did recently…

Well since its a botnet that is trying to login with lots of different passwords and lots of different accounts its fairly obvious what the attack vector is. That's also why its safer to force a password reset than to just continue to reset passwords after they get compromised.

Re: GoToMyPC has been hacked, all customer passwords reset

#163
If you have ever been a victim of any online scam, Bank account hack and you want to get your funds back as much as possible and even Gather enough evidence to prosecute as well as identify these actual identities or need to check on your partners Criminal records or Investigate a cheating spouse (consultanthackers@outlook.com) he just helps you out with whatever hack or spying activity, anything ! all you need do is get in touch . classified, certified,and highly professional . call (302) 365-0294 and Thank me later..

Re: GoToMyPC has been hacked, all customer passwords reset

#164
post #121

Earlier quoted context omitted.

Your mistake here is failing to consider that sharing an entropy pool does not (and in fact should not, it must be shared out-of-band anyway) need to be real time. Fundamentally, OTPs involve leveraging physical security and fleeting points of physical contact to create a pre-shared perfectly secure future communication channel. Ie., two people meet up an exchange a USB stick (or HDD), then consume the entropy pool o…

> The issues with OTP [...] The primary issue is that through misuse it degrades almost instantly from unbreakable to "little better than ROT13". And, it still appears secure to the hapless user.

>The primary issue is that through misuse it degrades almost instantly from unbreakable to "little better than ROT13". And, it still appears secure to the hapless user.

Please explain how this does not apply identically to every form of encryption, particularly as we have directly seen vulnerability after vulnerability. That implementation matters goes without saying in these discussions, but if you want to go there then in that respect OTP is fundamentally much simpler and easier to get right then public-key crypto. Generating decent random noise, storing it in an ordered way, then deleting it automatically after use are comparatively straight forward operations to automate. Using each bit is just a matter of an XOR operation and that's it.

So I disagree with you that technical challenges are in any way even remotely the "primary issue" when it comes to OTP. If there was a need for it it'd be rapidly adopted. But outside of certain very niche scenarios, maybe, there simply isn't any need for it, nor will there be in the foreseeable future.

Re: GoToMyPC has been hacked, all customer passwords reset

#165
post #49

This is not a good suggestion on their part, and has long been proven ineffective: Substitute numbers for letters that look similar (for example, substitute “0” for “o” or “3” for “E”.

> This is not a good suggestion on their part, and has long been proven ineffective: Agreed; that is bad advice. I tell people: If you think of a trick then the attackers, who have expertise and think about these issues all the time, have thought of it long ago and have written it into their password-cracking software. That applies to visual substitutions (such as GoToMyPC recommended), phonetic substitutions (e.g.,…

This is what I tell people about the + notation in their email addresses. Spammers know what it's for, and can easily strip it out if they wish to conceal their address source.

Re: GoToMyPC has been hacked, all customer passwords reset

#166

Earlier quoted context omitted.

Of course you do. That's why you don't reuse passwords. Why would you trust your other accounts to their internal investigation + PR interpretation anyway?

Because I'm human and can't maintain 30+ passwords?

> Because I'm human and can't maintain 30+ passwords?

The original question was about GoToMyPC providing more details so someone could "estimate the risk".

If you're already reusing passwords, that becomes rather easy: Your risk is dominated by the fact that you reuse passwords across services. No amount of details from GoToMyPC is going to affect that very much--whether you even used their service or not.

Seriously, just start using a password manager. It's not that much effort, even just for the peace of mind that you're finally setting passwords with the desired strength that you already know is necessary, but couldn't afford to maintain / memorize.

The hardest part for me was trying to decide which one to use :) I settled on KeePassX, because it's free and open source, has an Android app, doesn't store your stuff on their servers (just one encrypted database-file you can safely keep synced between devices via whatever method/cloud storage you prefer). I've been keeping an eye on the pro's and cons between various password manager options, and as far as I've seen the biggest downside to KeepassX was that one security researcher didn't like the user interface (it's fine, IMO) whereas the others either keep your stuff on a server somewhere, are not open source, or both.

Re: GoToMyPC has been hacked, all customer passwords reset

#167
post #125
post #46

Earlier quoted context omitted.

KeePassX ( https://www.keepassx.org/ ) is free and open source password manager. Having never tried LastPass I can't vouch that it's feature compatible, but it covers all my needs.

I did look at KeePassX - but it doesn't seem to have reliable autofill in Chrome & Firefox (where I use 99% of my passwords). It also means I have to manually synchronise the database between phone, PC, etc. The hunt continues!

I just keep the keepass.db file in a cloud storage folder that is synced across devices. Works perfectly and because of the encryption it hardly even matters that cloud storage is (currently) on a US server.

The "perform autotype" option in KeepassX Linux seems to work well enough for me in Firefox, Chromium and most applications (it basically seems to send which usually does the trick--and afaik it has some settings you can tweak when it doesnt, but I never bothered with those).

But if Lastpass works for you, that's cool. Getting to use a password manager in the first place is the most important step, IMHO.

Re: GoToMyPC has been hacked, all customer passwords reset

#168

Earlier quoted context omitted.

> I use https://lastpass.com/ I feel like it's almost certain that Lastpass is owned, as are other popular online password stores. No security is perfect; all you can do is make it more expensive than it's worth to the attacker. How much would it be worth to have all the passwords to every account of every Lastpass user? Does Lastpass really have the resources and skill to protect something that valuable? Is it even…

Well as long as you 'feel' that way, it must be true. Lastpass (supposedly) stores the encrypted password vault, never the decrypted. Decryption occurs on the users end. You would need to either have a keylogger on the target users machine to grab their master password, or compromise the software. Neither is impossible, but both are a little harder than simply break in and access Lastpass's storage. I say supposedly…

> You would need to either have a keylogger on the target users machine to grab their master password, or compromise the software. Neither is impossible, but both are a little harder than simply break in and access Lastpass's storage.

That reasoning only holds if it's in fact significantly harder to compromise the software than it is to "simply break in and access Lastpass's storage". If you believe that might be possible, then the security of your password vault basically depends on the differential difficulty compared to "simply break in and compromise the login form / browser extension / update channel to make it do ".

My point is not that this would be easy, rather that if someone went as far to break in and grab the storage[0], given the sheer value of the data, the barrier to go a step further and compromise the software isn't big enough to make me go "okay well that's all right then, that might happen, but this surely won't".

The biggest difference in risk between those two scenarios is that yes some cybercriminal that is "just poking around" might easier stumble upon access and just grab the vault than to set up a compromised login form and wait--not so much more difficult but just more effort.

[0] which I agree is fair to trust Lastpass to have properly encrypted, cause if you can't trust the people you pay $12/year to keep your most sensitive data secure, then who can you trust?

Re: GoToMyPC has been hacked, all customer passwords reset

#169

Earlier quoted context omitted.

I use LastPass, but I'm still fearful about it. It's such a rich target, and all a hacker would really have to do is to intercept when you put your decryption key in and send it off to their own server. Then they'd have access to all your accounts. They'd have to put that backdoor into the extension, but the point is, it's doable, and most people wouldn't have any way of knowing that it happened.

LastPass doesn't have you send the master key to log in or decrypt, Decryption does not occur on their servers. https://lastpass.com/support.php?cmd=showfaq&id=6926 "LastPass says they never receive my Master Password. Don’t I send it to the LastPass servers when I log in? No, when you login to LastPass, two things are generated from your Master Password using our code discussed previously before anything is sent to…

Well no they better not, obviously!

The point was "all a hacker would really have to do is to intercept when you put your decryption key in and send it off to their own server" (emphasis added).

However this is more about keeping the Lastpass software secure than it is about keeping the encrypted user vaults secure. The documentation you quoted really obscures this by use of the passive voice, casting the end-user somehow as an active agent deliberately doing all the encryption/hashing and sending, implying that they are in full control :) Try this on for a change:

"LastPass says they never receive my Master Password. Doesn't the LastPass Software send it to the LastPass servers when I log in?

No, when you login to LastPass, the LastPass Software generates two things when you give it your Master Password, before the LastPass Software sends anything to the server: the password hash and the decryption key. The LastPass Software does all this locally.

The LastPass Software sends your password hash to our servers to verify you. Once verified, our server sends back your encrypted Vault. The LastPass Software only sends your hash to our server, not your Master Password that you just entered into the LastPass Software.

The LastPass Software then uses this decryption key, which should NEVER leave your computer, to decrypt your Vault once it comes back."

-

The above is IMHO a much better way to word the same documentation, since it doesn't try to gloss over a rather important part of the attack surface. It's not really fair to on the one hand congratulate a user for being security-aware enough to use a password manager, but then ignore this part. Good security software documentation should proudly present the last few exposed parts of the attack surface, especially if they are minor ones, so that a user can assess the limits of their trust--there are always limits, no sense in pretending there aren't, and it's better to know them so that the user gets to decide what they're okay with.

Re: GoToMyPC has been hacked, all customer passwords reset

#170
post #20

Earlier quoted context omitted.

A unique password, 2FA, AND a unique email address. I use https://lastpass.com/ for generating passwords. $12/year and works on Linux & Android. Would prefer open source, but nothing else comes close. I tend to generate 32 char passwords with a mix of upper, lower, number, and special. Only a few websites insist on shorter passwords - or have character restrictions. For 2FA I use either SMS or Authy https://www.authy…

Yep, I highly recommend LastPass as well. The password generation, sync, platform support, and browser extension features are great. It's fairly easy to setup exclusion filters for not remembering passwords, as well as controlling if matching works on the first level domain (*.domain.com) or exact host.. The former generally works well for most sites, but the latter is essential for my own domains (where I have multi…

> For the last many years, I just forward it to a gmail account

How do you do this?

Post reply on HN