Earlier quoted context omitted.
No, they say "As a result, we have adjusted our security alert systems and this issue has since been resolved." They are claiming they know what the bug was.
Not necessarily. That could be read as them simply turning off the alerts (ideally, until they figure out and fix the bug).
How did LastPass master passwords get compromised?
171–180 of 189 posts
Re: How did LastPass master passwords get compromised?
#172Re: How did LastPass master passwords get compromised?
#173Re: How did LastPass master passwords get compromised?
#174Having intimate knowledge of this event, they are not being honest.
Re: How did LastPass master passwords get compromised?
#175The actual security event and the email bug are two separate problems they are combining to obscure one with the other. Accounts were compromised by credential stuffing and password reuse, a bug did break some of the security controls that would normally protect accounts when a specially crafted request was sent to authentication services (allowing some of the stuffing to occur). Weak securoty controls design allowed…
Were those requests the ones that triggered the emails that many of us received, and were those requests made with the correct or incorrect passwords?
Do you have an explanation why some people changed their LP passwords, and then received another login attempt alert email after that? Is that a coincidence (i.e. it was just more incorrect credentials still being tried on the same accounts) or was the attacker aware of the password change? Did the attacker have access to the new password or not?
Many of us received the alert email that our passwords had been used (i.e. an attempted login with the correct password from a new IP), but swear that those were unique passwords (in my case, it was computer generated, locally stored in KeePass and never re-used -- many other cases like that). Did the attackers have our passwords in their possession, or no?
Re: How did LastPass master passwords get compromised?
#176I've found LastPass to be increasingly buggy and less reliable as time goes on. Do they have security problems as well? Should I switch to a different service as a paying customer (for me and my family?) If so, any recommendations?
I’ve written about their security story a while ago here, not much has changed since AFAIK: https://security.stackexchange.com/questions/45170/how-safe-... The trouble is that the majority of their competitors isn’t great either. I used to recommend 1Password, but another knowledgeable security researcher isn’t really fond of them.
Re: How did LastPass master passwords get compromised?
#177I am the author of this article. I’ve kept it short, some points made there could have been expanded considerably. So if there are questions, feel free to ask here.
Thoughts on this as a possible root cause?
Re: How did LastPass master passwords get compromised?
#178Earlier quoted context omitted.
After all the problems with lastpass, who was even trusting them at this point?
My employer tried to move off them 2 years ago and didn't manage it. The problem is the year subs. To avoid wasting money you need to do it at the end of a year, but you also need to get your users trained up before the switch. We hit a complication and ran out of time and so had to re-up.
Re: How did LastPass master passwords get compromised?
#179Earlier quoted context omitted.
> In this case, it's at least a few dozen so I think it's fair to assume that such a lie would not survive very long. This is a very unlikely expectation. Employees are under NDA so nobody will talk publically about it unless one of them feel so strongly about it to sacrifice their career (they'd certainly get fired, and being sued for breaching the NDA isn't going to make finding a new job easier). Employees at all…
>being sued for breaching the NDA isn't going to make finding a new job easier NDAs are unenforceable against whistleblowers who report illegal activity.
Re: How did LastPass master passwords get compromised?
#180Earlier quoted context omitted.
I was self-hosted enthusiast myself, until I found out that self- updating is not fun, not always compatible and thus not secure*. And therefore, I take the hard pill of SaaS even if security wise, it is hard to swallow. *Not secure: It will always catch you off guard, and will require a lot of work, so you will postpone it which is, not secure.
What about an offline password manager? Like pass[1] or one that supports the KeePass format. Then you could use your regular file synchronization tool to synchronize the database files. You could also use a P2P sync tool like Syncthing. (Of course this makes more sense if you already have some kind of file sync setup.) [1] https://www.passwordstore.org/