Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

231–240 of 326 posts

Re: LastPass users warned their master passwords are compromised

#231
post #212

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

>I saw a few mentions of uBlock origin in yesterday's thread Statistically speaking it's probably because everyone has ublock origin installed, rather than it getting hacked. It's used by 5M+ users on firefox and "10,000,000+" on chrome. If ublock was really compromised you'd expect widespread reports of account compromise, rather than for only one password manager.

Yes that is what is so weird about the whole thing.

1. If LastPass has been compromised, the scale of these attack would have been tens of thousands times higher. But it isn't. And I think it is reasonable to trust and assume Lastpass does not hold the masterpassword, as they have stated.

2. If it was browser extension, and clipboard sniffing, the scale would have been higher as well. But it is important to note there are many reports of those password have not been used for 3-4 years. They would have sat on a drove of password and decide today is the day. And yet report of these attacks, while scary, are still very very limited.

3. It is hard make a guess without everyone posting their OS, Computer, Browser, extensions, list of software, and even Router, Location, Network ( MITM ? ) etc.

4. We have tested the theory of Lastpass triggering the wrong email notification even with wrong password. So far doesn't seems to be the case here.

5. Nearly all reported cases are unique passwords. ( A few didn't specify )

6. There was a case where the whole Lastpass App and passcode was stored on an old laptop which hasn't been used for a long long time.

7. And yet there are also cases where account was only created in October / November this year. Meaning this activity is fairly recent. ( Doesn't rule out they could be two independent leaks or attack )

8. I was expecting someone working in InforSec would jump in, but I guess they are all on holiday at the moment.

9. This happened just after LogMeIn announced they will spin off Lastpass. I am thinking of the incident with Ubnt where the actual problem was internal, an employees hacking their own companies for bitcoin or something. Still I dont know how any Lastpass staff, without storing any Masterpassword could have gained access to it.

10. For now this doesn't seem like a coordinated PR attack on LastPass. If it was, seriously guys you need to do a better job with Social Media marketing. :P

Anyway It is an interesting thread to watch.

Re: LastPass users warned their master passwords are compromised

#232
post #212

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

>I saw a few mentions of uBlock origin in yesterday's thread Statistically speaking it's probably because everyone has ublock origin installed, rather than it getting hacked. It's used by 5M+ users on firefox and "10,000,000+" on chrome. If ublock was really compromised you'd expect widespread reports of account compromise, rather than for only one password manager.

Specifically, if uBlock was compromised you'd expect widespread reports of cryptocurrency theft!

Re: LastPass users warned their master passwords are compromised

#233
Why I just use Apple’s password manager system. But it also involves completely investing into the Apple ecosystem so I understand why that’s not an option for some.

I just enjoy how easy generating new passwords are. Still has some work to do, but they’re definitely on the right track.

Re: LastPass users warned their master passwords are compromised

#234

Earlier quoted context omitted.

Nope.

So that explains why it’s so small then.

If you measured the proportion of localized text and images in the 25MB of javascript mentioned above, please post these numbers. Otherwise nothing's been explained.

There's 4.3 megabytes of plain text in the KJV bible. Is LastPass' localization longer than the bible?

https://www.gutenberg.org/cache/epub/10/pg10.txt

Re: LastPass users warned their master passwords are compromised

#236
This is why I never liked that 1Password started moving to cloud based, subscription model.

I hate that they try so hard to hide the standalone version for which you just paid a fixed price. That's the only way that I still use 1Password.

Yes, there's not much redundancy or convenience without the cloud, especially if your computer's hard drive becomes damaged, but if I lose my master password at least it's on me.

Re: LastPass users warned their master passwords are compromised

#238

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

It still seems that the most likely answer might be that lastpass are incorrectly alerting that someone's correct passphrase had been used, and that the email is being triggered by a bug, or something like a login attempt using the wrong password from a suspicious IP.

The fact that lastpass support says that it means that the correct password was used doesn't mean it's true, the support staff might just be mistaken.

Re: LastPass users warned their master passwords are compromised

#239
post #205

When using my password manager, I often provide only the password, not the user. In case of data breach they can not be exploited.

Wouldn't your username generally (or at least, quite often) be your email, which would be recoverable? Might slow an attacker down a little I suppose, or prevent automated attacks.

Im thinking on txt files shared with leaked user and password. On those cases my credentials would not appear.

If somebody focus on hacking _me_, they already have my email, so this measure is not very effective.

Re: LastPass users warned their master passwords are compromised

#240

Not good news - I use Bitwarden, not LastPass, but if you're using a password manager make sure to use 2 factor authentication and this really wouldn't be an issue in the first place. I have my TOTP codes stored in Bitwarden for other services like Facebook etc, but I use Authy as an independent TOTP provider for Bitwarden. 1.5 factor I guess (2FA tokens in a password manager), but works a treat and is very convenien…

I've considered switching from Authy to Bitwarden for TOTP. But besides the headache of moving all my accounts...I worry about "having all my eggs in one basket". I mean, the purpose of TOTP is to have MULTI factor auth. With both the password and TOTP code in Bitwarden, you actually remove the multi factor part.

Yes - hence the "1.5" factor.

My Bitwarden account is protected by 2FA (via Authy - only backup method is SMS - which has become handy at one point when my phone was pick-pocketed abroad in Amsterdam as I'm able to get a replacement SIM card from my operator) but then if you get past that (and the master password) then you've 'pwned' me.

It's a trade-off of convenience and security really - I think I'm doing a lot more than the average Joe and feel relatively secure. For the majority of my accounts (FB/Twitter/Instagram etc. etc.) if you get the password you're getting nowhere. Even then using a password manager I have a different password for every service so unless you breach my password manager you've at most made it into one account - if that doesn't have 2FA via Bitwarden.

You might struggle a bit moving away from Authy though if you ever want to as it does a lot of 'proprietary' stuff. I had to use a bit of JavaScript to extract my TOTP codes from the Chrome Web App (e.g. for Twitch) otherwise you're unable to get them out of Authy.

Post reply on HN