Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

161–170 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#161

Earlier quoted context omitted.

Hey, That's quite possible, for sure. I am not beyond/above/below being phished like anyone else, ha! The issue -- what makes it perplexing -- is that I haven't used this LastPass password since 2017. I know because this LastPass account was only used to share passwords within an org that I left back then. Is it possible that I was phished 4 years ago, and they sat on the password? Sure. But 2 other people in this th…

Hey guys I think that maybe this has to do with an exploit in the web browser LastPass extension about 5 years ago: HN POST: [0]. [0] https://news.ycombinator.com/item?id=12171547

Yeah, that's not impossible. Surprising that they sat on the passwords for so long, but this is quite possible. Thanks for the reference/link!

Re: Ask HN: How did my LastPass master password get leaked?

#162

Earlier quoted context omitted.

Hey, That's quite possible, for sure. I am not beyond/above/below being phished like anyone else, ha! The issue -- what makes it perplexing -- is that I haven't used this LastPass password since 2017. I know because this LastPass account was only used to share passwords within an org that I left back then. Is it possible that I was phished 4 years ago, and they sat on the password? Sure. But 2 other people in this th…

Couldn't it just be that someone got a copy of the password some years ago and now sold the list of credentials to someone else, who then tried to use it? Maybe the original owner of the list didn't realize some of the credentials was for LastPass, for example. I'm still seeing hackers trying to log on using passwords I haven't used in ~10 years, because it's on a list somewhere.

I agree, that could make sense.

So LastPass (their extension) may have been hacked ~5 years ago ish, a few people here on the thread were all hacked in the same way, our passwords were sold off, and now the same Brazil IP range just tried all of those passwords.

Re: Ask HN: How did my LastPass master password get leaked?

#163
May be a dumb question, but how much are we trusting Lastpass that whoever tried these logins actually used the correct master password? The posted statements sound a bit ambiguous, maybe they're mistaken? Does it show as a login attempt if somebody uses your correct account email address and the wrong password?

Of course if Lastpass is sending ambiguous or mistaken communication about whether someone else has your master password, that's a really bad sign for them as a company too.

On the "bright" side, if somebody had your KeePassX file and master password to that, I would think they'd be doing things a lot worse than trying to log into your LastPass account from Brazil. If they had that data and were serious about LastPass for some reason, they'd probably at least break into your email too and try and intercept those warning emails. Keep an eye on email, banking, credit card, hosting systems, any other higher-value accounts that might have credentials in that file for any signs of suspicious activity. If there's none, then a successful exfiltration of that data seems unlikely.

Re: Ask HN: How did my LastPass master password get leaked?

#164
post #128

My girlfriend once asked me why I don't use a password manager like LastPass. A week later she got locked out of her LastPass account because she was inadvertently using an enterprise account that one of her clients forced her to use while on a project. And even though she was paying for her own premium LastPass subscription, the support experience had was terrible. Issue was resolved when the client was able to unlo…

Your friend used a commercial service under contract for someone else for private purposes, and you conclude that therefore all password management software must be bad? This is definitely not what I have in mind when I recommend people to use a password manager.

And regardless, people should finally take this to heart:

If something is important to you, back it up in a format that you can read with offline software. I don't care if you store it on punch cards under your pillow or in The Cloud, so long as it's independent of the primary copy (such that you can access it regardless of access to the primary copy, and such that you don't need the original service to load the data in order to read it). It doesn't sound like that was the case for your friend.

Re: Ask HN: How did my LastPass master password get leaked?

#165

Hey, this _just_ happened to me too....my password would be near impossible to guess and is not used elsewhere... Just deleted my last pass account! here's the info that came with the email Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235

got one at 1528EST from 23[.]236[.]213[.]5 - OSINT shows it part of BLAZING_SEO_PROXY pw was only ever used here and stored offline

That's a different IP range, but the fact that it's all happening at once (i.e. these unique, never used elsewhere LastPass master passwords being used to login) is rather strange..?

Or I am drawing a random line through a cloud of dots..? :-)

What other IPs are part of BLAZING_SEO_PROXY?

Re: Ask HN: How did my LastPass master password get leaked?

#166

Earlier quoted context omitted.

WHAT!! Same IP range for me. How is this possible????

Is the date / time exactly the same? It seems like they might have emailed _everyone_ at this point. Maybe it's just a bug.

I have a LastPass account (also not used for some time) and have not received this email.

Re: Ask HN: How did my LastPass master password get leaked?

#167
post #155

You trusted an online service to look after your passwords. Use something local, like 1password. I have no idea why anyone would use a hosted solution like LastPass. Of course something will happen?

> I have no idea why anyone would use a hosted solution like LastPass. Convenience. I use Bitwarden. I get a lot of value from having my passwords synced across multiple PCs and my phone.

1Password allows you to use a local vault, encrypted with a master password, that can be synced across devices in multiple ways, for instance using Dropbox. There's no web logins going, no 'someone elses database' accessed over the web. I have used this solution for a number of years, and would _never_ go for a cloud option like lastpass, for important personal data.

Re: Ask HN: How did my LastPass master password get leaked?

#168
post #163

May be a dumb question, but how much are we trusting Lastpass that whoever tried these logins actually used the correct master password? The posted statements sound a bit ambiguous, maybe they're mistaken? Does it show as a login attempt if somebody uses your correct account email address and the wrong password? Of course if Lastpass is sending ambiguous or mistaken communication about whether someone else has your m…

Unfortunately, the email sent from LastPass specifically says "Someone just used your master password to try to log in to your account from a device or location we didn't recognize"

LastPass support did confirm that the IP from Brazil did have the master password.

I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the master password.

Re: KeePassX, I agree. It's a catastrophic scenario if true, but it does seem improbable.

Re: Ask HN: How did my LastPass master password get leaked?

#170
post #169

It happened to me to but I'm no longer using LastPass for years now. I got an email saying that somebody tried to access my account from the US (the attacker is using a VPN) and changed password and recovery email on my Outlook account

Did it just happen to you today?

Did the email say that "Someone just used your master password to try to log in to your account from a device or location we didn't recognize"

And was that master password generally secure / wasn't used anywhere else?

Thanks!

Post reply on HN