Live data from Hacker News

How did LastPass master passwords get compromised?

palant.info

171–180 of 189 posts

Re: How did LastPass master passwords get compromised?

#171
post #88

Earlier quoted context omitted.

No, they say "As a result, we have adjusted our security alert systems and this issue has since been resolved." They are claiming they know what the bug was.

Not necessarily. That could be read as them simply turning off the alerts (ideally, until they figure out and fix the bug).

Eurgh, I suppose it could mean that. Very misleading if so.

Re: How did LastPass master passwords get compromised?

#173
The actual security event and the email bug are two separate problems they are combining to obscure one with the other. Accounts were compromised by credential stuffing and password reuse, a bug did break some of the security controls that would normally protect accounts when a specially crafted request was sent to authentication services (allowing some of the stuffing to occur). Weak securoty controls design allowed attacks to continue in other scenarioa. What probably stopped this from being a bigger story the MONTHS ago that it took place was the fact so many lastpass accounts are abondoned accounts that don’t get run through a garbage process, or primary email account was also compromised, or users with weak passwords that are low tech IQ and not aware of the activity in their account or unsure how to handle it. Check Twitter, it started with a user complaining about account takeover and losing their coin wallet (and thousands of dollars) (stored password in LP). There were thousands of accounts compromised this way.

Re: How did LastPass master passwords get compromised?

#175

The actual security event and the email bug are two separate problems they are combining to obscure one with the other. Accounts were compromised by credential stuffing and password reuse, a bug did break some of the security controls that would normally protect accounts when a specially crafted request was sent to authentication services (allowing some of the stuffing to occur). Weak securoty controls design allowed…

Can you talk more about the specially crafted request?

Were those requests the ones that triggered the emails that many of us received, and were those requests made with the correct or incorrect passwords?

Do you have an explanation why some people changed their LP passwords, and then received another login attempt alert email after that? Is that a coincidence (i.e. it was just more incorrect credentials still being tried on the same accounts) or was the attacker aware of the password change? Did the attacker have access to the new password or not?

Many of us received the alert email that our passwords had been used (i.e. an attempted login with the correct password from a new IP), but swear that those were unique passwords (in my case, it was computer generated, locally stored in KeePass and never re-used -- many other cases like that). Did the attackers have our passwords in their possession, or no?

Re: How did LastPass master passwords get compromised?

#176
post #77
post #74

I've found LastPass to be increasingly buggy and less reliable as time goes on. Do they have security problems as well? Should I switch to a different service as a paying customer (for me and my family?) If so, any recommendations?

I’ve written about their security story a while ago here, not much has changed since AFAIK: https://security.stackexchange.com/questions/45170/how-safe-... The trouble is that the majority of their competitors isn’t great either. I used to recommend 1Password, but another knowledgeable security researcher isn’t really fond of them.

Just curious if you had any information on the security concerns of 1Password from that researcher?

Re: How did LastPass master passwords get compromised?

#177
post #2

I am the author of this article. I’ve kept it short, some points made there could have been expanded considerably. So if there are questions, feel free to ask here.

I haven't seen any mentions discussing HTTP request smuggling try. This could cause LP's internal or external load balancers to misdirect requests/responses.

Thoughts on this as a possible root cause?

Re: How did LastPass master passwords get compromised?

#178
post #169

Earlier quoted context omitted.

After all the problems with lastpass, who was even trusting them at this point?

My employer tried to move off them 2 years ago and didn't manage it. The problem is the year subs. To avoid wasting money you need to do it at the end of a year, but you also need to get your users trained up before the switch. We hit a complication and ran out of time and so had to re-up.

Surely the cost of the subs is trivial compared to the cost of training users etc?

Re: How did LastPass master passwords get compromised?

#179
post #141

Earlier quoted context omitted.

> In this case, it's at least a few dozen so I think it's fair to assume that such a lie would not survive very long. This is a very unlikely expectation. Employees are under NDA so nobody will talk publically about it unless one of them feel so strongly about it to sacrifice their career (they'd certainly get fired, and being sued for breaching the NDA isn't going to make finding a new job easier). Employees at all…

>being sued for breaching the NDA isn't going to make finding a new job easier NDAs are unenforceable against whistleblowers who report illegal activity.

Would it actually be illegal to cover up/lie about? I assume the company is US based, there is certainly breach regulations in Aus (with a 12 month notification window). I guess if it’s publicly traded then it would be a breach of law, but what about if it was privately owned?

Re: How did LastPass master passwords get compromised?

#180
post #152

Earlier quoted context omitted.

I was self-hosted enthusiast myself, until I found out that self- updating is not fun, not always compatible and thus not secure*. And therefore, I take the hard pill of SaaS even if security wise, it is hard to swallow. *Not secure: It will always catch you off guard, and will require a lot of work, so you will postpone it which is, not secure.

What about an offline password manager? Like pass[1] or one that supports the KeePass format. Then you could use your regular file synchronization tool to synchronize the database files. You could also use a P2P sync tool like Syncthing. (Of course this makes more sense if you already have some kind of file sync setup.) [1] https://www.passwordstore.org/

That would be roughly equivalent to lastpass then.
Post reply on HN