I got the same thing in the last month. Then my bank account had 7 transactions from ali express about a week later. Nine were mine. I deleted everything in lastpass and deleted my account.
Ask HN: How did my LastPass master password get leaked?
201–210 of 529 posts
Re: Ask HN: How did my LastPass master password get leaked?
#202May be a dumb question, but how much are we trusting Lastpass that whoever tried these logins actually used the correct master password? The posted statements sound a bit ambiguous, maybe they're mistaken? Does it show as a login attempt if somebody uses your correct account email address and the wrong password? Of course if Lastpass is sending ambiguous or mistaken communication about whether someone else has your m…
Unfortunately, the email sent from LastPass specifically says "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" LastPass support did confirm that the IP from Brazil did have the master password. I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the mas…
Given the widespread nature of this issue, I'd guess someone has discovered a flaw in the LastPass login process which is allowing a bad hash to pass the master password hash check: that contradicts what the support agent said, but I'd assume they're mistaken, rather than LastPass are lying in their documentation about how their system works.
[1] https://support.logmeininc.com/lastpass/help/about-password-...
Re: Ask HN: How did my LastPass master password get leaked?
#203Re: Ask HN: How did my LastPass master password get leaked?
#204Just happened to me one hour ago and got scared shitless. Time Monday, December 27, 2021 at 3:50 PM EST Location UNITED STATES IP address 107.173.195.83 Actions taken, in this order: - Head to *Advanced Options* -> *View account history* to see if anything suspicious is going on (nothing so far) - Disable Lastpass MFA and use Google Authenticator (Authy) - *Account Settings* -> click on *Show Advanced Settings* -> *D…
I wonder if password managers should be designed around, and encourage the use of, an undocumented PIN that’s appended to every stored password. You could use the same PIN for everything and if someone got your vault decrypted there would at least be a chance they didn’t get the secondary PIN too.
Re: Ask HN: How did my LastPass master password get leaked?
#205Just happened to me one hour ago and got scared shitless. Time Monday, December 27, 2021 at 3:50 PM EST Location UNITED STATES IP address 107.173.195.83 Actions taken, in this order: - Head to *Advanced Options* -> *View account history* to see if anything suspicious is going on (nothing so far) - Disable Lastpass MFA and use Google Authenticator (Authy) - *Account Settings* -> click on *Show Advanced Settings* -> *D…
You received a "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email? And your master password was secure/not used anywhere else, etc.? Did we all (that's 8 of us now in the thread) get compromised a few years ago (using the LastPass extension?) and someone just mass attempted to try all of those passwords..? Edit: since you're tracking IPs found…
Could be... I haven't rotated my password in a while. Could you link me to more info about the LastPass compromise that you mentioned?
p.s. My master password is definitely not dictionary material, and it's not used anywhere else, so I am 100% sure it's not a bruteforce / phishing attempt.
Re: Ask HN: How did my LastPass master password get leaked?
#206Time Monday, December 27, 2021 at 3:55 PM EST
Location UNITED STATES
IP address 154.202.117.78
Password is only used for lastpass. It was caught since I use 2FA. I did previously have "The Great Suspender" chrome extension, which changed hands and had an update including malware, I wonder if this was the culprit.
I last changed my master password on November 24, 2017, the previous exploit was apparently resolved in July 2016.
Re: Ask HN: How did my LastPass master password get leaked?
#207Earlier quoted context omitted.
Unfortunately, the email sent from LastPass specifically says "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" LastPass support did confirm that the IP from Brazil did have the master password. I also tried to login with a wrong password and that shows up as "Failed Login Attempt". This is different -- the person on the other side did have the mas…
I thought that LastPass didn't send your master password over the wire, rather it uses client-side code to take your Master Password and turn it into a hash which is then sent to LastPass for comparison[1]. If that is the case, how can LastPass claim to know that your master password was used? At best, they can claim that the hash sent to the server matches your password's hash but that is not the same as your master…
What's a bit surprising is how "low effort" the rest of the attack was: presumably if they found this flaw to bypass passwords, they then attempted to login (which caused an email to be sent out), but LastPass stopped them because they (i.e. the folks on the Brazil IP range) were logging in from a new IP.
So this would be a case of one protective layer (the new IP detection) compensating for a vulnerability in the other one (the password protection).
That would be "re-assuring" in a certain way (as the passwords themselves did not leak -- presumably!).
Thanks
Re: Ask HN: How did my LastPass master password get leaked?
#208Just got the same notification 2 hours ago, from IP address 107.173.195.213
Just trying to verify that we're all concerned with the same problem.
Thank you
Re: Ask HN: How did my LastPass master password get leaked?
#209My Evernote account which I don’t use any more is showing logins from Brazil. I’ve disabled and asked for an count deletion. Ive got a bad feeling about this.
Re: Ask HN: How did my LastPass master password get leaked?
#210Earlier quoted context omitted.
They appear to have sunset their phpBB instance. It was the main hub and support portal on their website with up to thousands of active visitors at any given time. You can see it archived here: https://web.archive.org/web/20150629081250/https://forums.la... Here's the archived phpBB login page. It asks for your LastPass login and password (not your forum account, your actual LastPass login and actual LastPass master…
Unless I’m misremembering, the login to their general system was done by never sending the password over the wire. Instead they used js to do some sort of hashing type system locally. But during the heartbleed attack when their systems were shown to be vulnerable, that was one of their arguments as to why it wasn’t so bad.
LastPass is full of clowns. There's already two examples of their cavalier approach to what should be simple security in this thread and I'm pretty sure there are more.