Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

211–220 of 326 posts

Re: LastPass users warned their master passwords are compromised

#211
post #205

When using my password manager, I often provide only the password, not the user. In case of data breach they can not be exploited.

Wouldn't your username generally (or at least, quite often) be your email, which would be recoverable? Might slow an attacker down a little I suppose, or prevent automated attacks.

Re: LastPass users warned their master passwords are compromised

#212

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

>I saw a few mentions of uBlock origin in yesterday's thread

Statistically speaking it's probably because everyone has ublock origin installed, rather than it getting hacked. It's used by 5M+ users on firefox and "10,000,000+" on chrome. If ublock was really compromised you'd expect widespread reports of account compromise, rather than for only one password manager.

Re: LastPass users warned their master passwords are compromised

#214

Earlier quoted context omitted.

> Either the master passwords were reused and this is credential stuffing, or there is actually a LastPass breach affecting all users. As you mention yourself at the end, there are other plausible explanations (e.g. malware on the machines).

If there is a LastPass cache that is not encrypted, that is a breach since it is an application flaw. If it is something like a keylogger, not so much.

The LastPass extension can be told to remember your master password. They say it's not recommended. We might be seeing the result of people opting to store their master password and something that exploits this.

Re: LastPass users warned their master passwords are compromised

#215
post #212

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

>I saw a few mentions of uBlock origin in yesterday's thread Statistically speaking it's probably because everyone has ublock origin installed, rather than it getting hacked. It's used by 5M+ users on firefox and "10,000,000+" on chrome. If ublock was really compromised you'd expect widespread reports of account compromise, rather than for only one password manager.

That's a good point.

I'm happy to delete my message if this way of finding out doesn't make sense.

Re: LastPass users warned their master passwords are compromised

#216

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

I've been using LastPass for work since mid-2018 as well as uBlock origin for Chrome; no blocked login notification so far.

Re: LastPass users warned their master passwords are compromised

#217
A user posted this comment then deleted it. Is this true? If so. JFC.

>>> Take this with a grain of salt.

LogMeIn, the owners of LastPass, had a Chinese APT group in their servers for years. They only found out because the attackers started launching unoptimised SQL queries that started killing their database cluster. They didn’t have to report this breach, despite being based in Germany where it’s a legal requirement, because they didn’t have proof customer data was accessed. They didn’t have proof because they didn’t have any logging or auditing. Whatsoever.

Re: LastPass users warned their master passwords are compromised

#218

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

I'd be pretty surprised if uBlock Origin had been exfiltrating data since 2017 without being caught, and (as the sibling comment points out) I'd expect a lot more than LastPass to be compromised.

I think it exists at an intersection of (relatively) trustworthy and necessary that makes it extremely popular among the kinds of people participating in these discussions.

Re: LastPass users warned their master passwords are compromised

#219
For what it's worth, I haven't received a notification of an attempt to login to my LastPass account. My LastPass password is horrendous and for sure not used elsewhere, and even if someone does gain access, I don't store passwords to major financial or email accounts in there.

Re: LastPass users warned their master passwords are compromised

#220
post #128

Algorithmic passwords. Come up with an algorithm a(website, rules) that you can remember and that generates unique passwords per website. Store the rules (length restrictions, special character restrictions, number of times the password has changed, etc) in a google doc or something. Print out your algorithm on a physical piece of paper and put it in a safe place for after you die and people need to access your accou…

Sounds like a lot of mental work just to log in. Or... Try a self-hosted password manager, or one that generally has a much better reputation?

A self-hosted password manager works for me; I only ever log in with a password from a single machine, so I use a local password manager that is completely unintersted in networks. I don't use a plaintext file, because like most people I have secrets; and because I trust people, not bureacracies (so I don't trust either the police or the government to hold my secrets safely).

That isn't going to work for most people, obviously. Most people want to be able to use their credentials from arbitrary machines. I don't have that requirement.

Post reply on HN