LastPass users warned their master passwords are compromised
201–210 of 326 posts
Re: LastPass users warned their master passwords are compromised
#202Earlier quoted context omitted.
You can add multiple keys to the account.
So is the recommendation to get something like 3 keys and keep them in different safe places and bring one when you travel? I’ve been considering getting a Yubikey. Do they work on mobile? Edit: Looks like some Yubikey work via nfc for mobile.
The Yubikey OTPs work if Yubikey is connected to a phone via USB (Type-C). Not sure about Fido/U2f etc though.
Re: LastPass users warned their master passwords are compromised
#203Confession: I store all my passwords in a plaintext file on my local desktop. I'm sure some people will look at me very funny for doing this, but it seems to me that I have both fewer hassles logging in and fewer breaches than people using more "secure" methods (like handing your passwords over to LastPass's mystery Chrome extension). Think about today's threat landscape and tell me I'm wrong. I may not be more secur…
You could just use KeePass: https://keepass.info/ It's a free open source app that runs on your local machine and stores your passwords locally - never uploads your passwords to a server. But it does this securely. And you can run it on multiple machines (and phones) and transfer the passwords (the vault) without ever uploading anything to servers.
Re: LastPass users warned their master passwords are compromised
#204A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen.
The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098
"Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I changed it. What the hell is going on?"
https://twitter.com/shift_plusone/status/1475959354742525956
"Exactly the same thing happened to me last night. They tried again literally minutes after I changed the password to something not used on any other form."
https://twitter.com/Pablohere/status/1475966760130125828
"I had this same thing happen to me. Saw attempts yesterday, changed password last night to random generated pass from pass utility and had attempts today again from different countries."
---
I saw a few mentions of uBlock origin in yesterday's thread. I definitely might have used it in 2017 (the last time when my compromised LastPass password was used).
Could people that received the "Someone just used your master password to try to log in to your account from a device or location we didn't recognize" email please reply and confirm whether or not they have the uBlock origin extension installed?
The other alternative is for the LastPass extension itself to have been compromised (and to still be..?). There are other alternatives as well (some clipboard sniffing malware for example).
Let's try to rule out uBlock if possible. Thanks!
Re: LastPass users warned their master passwords are compromised
#205Re: LastPass users warned their master passwords are compromised
#206Earlier quoted context omitted.
An “Ask HN” was just trending about this yesterday ( https://news.ycombinator.com/item?id=29705957 ). Sounds like a good reason not to trust any third party service with my password database to me. I’ve always taken the route of managing my own local Keepass DB & key files. Sure it’s more cumbersome, but it prevents me from having to decide whether or not to trust some third party vendor or not. I know 100% that I’m…
I recommend this every time a similar news item gets posted. Password Safe (designed by Bruce Schneier). I use the iOS and Linux apps and keep them synced via DropBox. Been around for years (I've been using it almost as long). Still getting updates. Still works. https://pwsafe.org
Re: LastPass users warned their master passwords are compromised
#207This is framed so negatively toward LastPass, which is unfortunate. They stopped all usage of correct passwords they believed were compromised, which is exactly what I'd want them to do in this situation. Them warning users their master passwords are compromised is a good thing! Yet it's framed as though they're admitting to something. "However, users receiving these warnings have stated that their passwords are uniq…
It's negative because something's up and they haven't given a good explanation. > They stopped all usage of correct passwords they believed were compromised Immediate question: how the heck would they know which passwords are compromised, if it wasn't a compromise on their end? From the information provided, the only thing they have is the IP & geolocation data, which isn't going to be reliable when the attacker(s) a…
First thing's first, and yes I am "victim blaming" when I say this: 60% of users reuse their passwords. [0,1] It's a widespread problem. Maybe that number is lower for a technical site like HN, but I have encountered technical people who do not practice what they preach.
>how the heck would they know which passwords are compromised, if it wasn't a compromise on their end?
You can check for a compromised password the same way you check if a password is valid, both without having stored the original password in plaintext. You have a list of known-compromised hashes and see if the hashed password is in that list. [2]
>For everyone whose account was protected by blocking access from odd region, how many are there whose accounts were quietly accessed and no email was shot off to warn the owner?
None based on my experience with the service. Each time you login from an unrecognized device or IP, you receive an email and have to confirm the login. It's good hygiene to check the access logs, although I've been dirty in that regard.
>They are claiming that the master password was used on some other (compromised) service, but they provide zero evidence for this. And if they don't know your passwords, how on earth do they know that you've reused them on a compromised service? Can they name that service?
No. And they probably won't ever be able to. And probably neither will anyone else. See [2].
>That is true, but there are so many reports now that it's really hard for me to believe they were all dumb enough to reuse their master passwords elsewhere and are also bullshitting us on HN.
Well I can imagine a few things going on. Like that 60% reuse number in [0], there are probably a lot of people who did reuse their master password. I'd be embarrassed myself to admit I reused a password and it got compromised (correction: I have reused passwords and have been compromised, luckily not in a damaging way). You're kind of exemplifying that point by calling someone who would do that "dumb enough".
The other group of people who really didn't reuse their passwords may have done something I did a few weeks ago - forgot I was connected with a VPN. I SSH'd into a server, saw a weird IP and freaked out. Then after 15 minutes of investigation, I realized duh I was just connected through a VPN in Europe.
>bullshitting us on HN
I'd be careful about this assumption. I have seen people bullshitting here. I won't go as far as outright denying that people haven't reused their passwords, but I am always a little skeptical of things like this (i.e. where people say one thing because they're embarrassed about being associated with the other). It has certainly heightened my senses.
>I don't think we have a "smoking gun" or a site/service/extension that is common to everyone who reported this thing happening to them.
As has been theorized elsewhere, it's very possible we're seeing early signs of the results of the log4j exploits.
I'm in wait and watch mode to see if LP really is compromised.
[0]: https://spycloud.com/password-reuse/
[1]: https://www.troyhunt.com/password-reuse-credential-stuffing-....
[2]: https://haveibeenpwned.com/Passwords A password from my late childhood to early teens shows up 150 times
Re: LastPass users warned their master passwords are compromised
#208Earlier quoted context omitted.
I still use an older version of 1Pass specifically so I can run things locally. Sometimes, I wish I was ignorant to all of this stuff and could just be a plebe out in the wild using all of the convenient software out there. Just take the blue pill and put me back in the matrix. The knowing of all of this stuff just makes life so much more difficult.
Maybe look at BitWarden
Sometimes the devil you know, you know?
Re: LastPass users warned their master passwords are compromised
#209Earlier quoted context omitted.
I think for a security application you want to reduce your exposure as much as possible, and one way to do so is reducing the amount of dependencies in your application. I think a high dependency count is orthonogal to that.
Nitpick: "orthogonal" would mean "independent of"; that is, a high dependency count has no effect on exposure. I think you might have meant "antithetical", meaning "in opposition to".
Re: LastPass users warned their master passwords are compromised
#210This is framed so negatively toward LastPass, which is unfortunate. They stopped all usage of correct passwords they believed were compromised, which is exactly what I'd want them to do in this situation. Them warning users their master passwords are compromised is a good thing! Yet it's framed as though they're admitting to something. "However, users receiving these warnings have stated that their passwords are uniq…
LastPass has had enough other security issues that I am doubtful of them to this day. https://www.mcafee.com/blogs/enterprise/cloud-security/lastp... Unfortunately the only password solutions I would recommend at this point are 1Password for something turn key, and BitWarden if you want to self host.