When using my password manager, I often provide only the password, not the user. In case of data breach they can not be exploited.
LastPass users warned their master passwords are compromised
211–220 of 326 posts
Re: LastPass users warned their master passwords are compromised
#212Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…
Statistically speaking it's probably because everyone has ublock origin installed, rather than it getting hacked. It's used by 5M+ users on firefox and "10,000,000+" on chrome. If ublock was really compromised you'd expect widespread reports of account compromise, rather than for only one password manager.
Re: LastPass users warned their master passwords are compromised
#213Re: LastPass users warned their master passwords are compromised
#214Earlier quoted context omitted.
> Either the master passwords were reused and this is credential stuffing, or there is actually a LastPass breach affecting all users. As you mention yourself at the end, there are other plausible explanations (e.g. malware on the machines).
If there is a LastPass cache that is not encrypted, that is a breach since it is an application flaw. If it is something like a keylogger, not so much.
Re: LastPass users warned their master passwords are compromised
#215Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…
>I saw a few mentions of uBlock origin in yesterday's thread Statistically speaking it's probably because everyone has ublock origin installed, rather than it getting hacked. It's used by 5M+ users on firefox and "10,000,000+" on chrome. If ublock was really compromised you'd expect widespread reports of account compromise, rather than for only one password manager.
I'm happy to delete my message if this way of finding out doesn't make sense.
Re: LastPass users warned their master passwords are compromised
#216Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…
Re: LastPass users warned their master passwords are compromised
#217>>> Take this with a grain of salt.
LogMeIn, the owners of LastPass, had a Chinese APT group in their servers for years. They only found out because the attackers started launching unoptimised SQL queries that started killing their database cluster. They didn’t have to report this breach, despite being based in Germany where it’s a legal requirement, because they didn’t have proof customer data was accessed. They didn’t have proof because they didn’t have any logging or auditing. Whatsoever.
Re: LastPass users warned their master passwords are compromised
#218Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…
I think it exists at an intersection of (relatively) trustworthy and necessary that makes it extremely popular among the kinds of people participating in these discussions.
Re: LastPass users warned their master passwords are compromised
#219Re: LastPass users warned their master passwords are compromised
#220Algorithmic passwords. Come up with an algorithm a(website, rules) that you can remember and that generates unique passwords per website. Store the rules (length restrictions, special character restrictions, number of times the password has changed, etc) in a google doc or something. Print out your algorithm on a physical piece of paper and put it in a safe place for after you die and people need to access your accou…
Sounds like a lot of mental work just to log in. Or... Try a self-hosted password manager, or one that generally has a much better reputation?
That isn't going to work for most people, obviously. Most people want to be able to use their credentials from arbitrary machines. I don't have that requirement.