Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

261–270 of 326 posts

Re: LastPass users warned their master passwords are compromised

#261

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

I'm one of the people that replied yesterday.

I haven't used LastPass since, at the latest, 2017. I had actually deleted all my passwords from my LastPass vault, but originally kept the account because of LastPass's password sharing feature, though I stopped using that as well. I believe I had the LastPass extension installed on both Chrome and Firefox, on both Mac and Ubuntu. I primarily used Chrome on Mac. I did have uBlock Origin on those setups as well, but I really doubt that's the vector, it's likely just incredibly popular with all users of Hacker News. My LastPass password was globally unique and between 15 and 20 characters long (with some symbols and digits). This password shows no matches at https://haveibeenpwned.com/Passwords . I considered sharing the password here, but just in case an old version of my vault is out there somewhere somehow I'm not going to. My understanding is that such a password would be so incredibly impractical to brute force that it's not worth considering. Unless I'm outdated/wrong on that, that means the password leaked in clear text (or hashed with a broken hashing method). As I haven't typed that password since at least 2017 and I can't imagine LastPass is storing passwords in clear text, I'm inclined to believe the password was stolen in clear text from client machines (either LastPass extension exploit or malware) in or before 2017. It's weird they were not used earlier, but as LastPass doesn't allow new IPs by default, maybe the attackers knew this and were sitting hoping an additional exploit would allow their user. But now they're just trying in the off chance someone clicks the "That's me" link in the email. This doesn't explain the more recent claims, personally I'm inclined to disregard them as unrelated noise (user confusion, reused password, etc).

Re: LastPass users warned their master passwords are compromised

#262
post #256

Earlier quoted context omitted.

> You can check for a compromised password the same way you check if a password is valid, both without having stored the original password in plaintext. You have a list of known-compromised hashes and see if the hashed password is in that list. That would require them to store password hashes unsalted and using the same hash function & number of rounds as the online dumps of compromised hashes. If that's what's going…

>That would require them to store password hashes unsalted and using the same hash function & number of rounds as the online dumps of compromised hashes. Even if you don't have the precomputed hashes, you can still bruteforce using a wordlist. >Password databases are supposed to encrypted, so without the master password they also won't see see the rest of the hashes in the db to see if they reused the master password…

True. And I guess that's the only way LastPass could be certain these passwords have been reused (assuming everything else works as they say). If they did that, then IMO it would be very nice of them to point out which dump(s) these passwords were found in.

I don't believe this happened though.

Re: LastPass users warned their master passwords are compromised

#263
post #3

Let this be your Last non-selfhosted Pass solution.

Selfhosting solution is not always the answer. It can be effective if everyone knows how to set it up. However, I imagine 90% (I want to say 99.99%) of world population don't have knowledge or the skill to set it up. I tried selfhosting in the past and it is painful process to set it up since I don't have an experience with it and the documentations on selfhosting are barely minimal. I tried selfhost an RSS Reader (F…

Let them use a single, tiny file from Keepass as an alternative to self hosting.

It's doable. I managed to teach a 50+ year old to do it.

Re: LastPass users warned their master passwords are compromised

#264

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

I'm one of the people that replied yesterday. I haven't used LastPass since, at the latest, 2017. I had actually deleted all my passwords from my LastPass vault, but originally kept the account because of LastPass's password sharing feature, though I stopped using that as well. I believe I had the LastPass extension installed on both Chrome and Firefox, on both Mac and Ubuntu. I primarily used Chrome on Mac. I did ha…

Thanks -- my own case is pretty much identical to yours. My LastPass account was from 2017, and haven't used it since. I can also suspect a LastPass extension exploit from 2017 i.e. that's maybe how my password was stolen.

(I actually found an email from LastPass dating back to 2017 where they were confirming that a vulnerability with their extension had been fixed. The subject of that email is "Security Update for LastPass Extensions" and it dates back to March 31st, 2017)

I also agree with you that the attackers may have been hoping this time that some people would click the email link by mistake.

What's most baffling to me are the 3 independent reports of people changing their passwords, and getting the "Someone just used your master password" emails again i.e. the same attackers that attacked you and me somehow also having access to these new passwords. That can be explained in some ways (those 3 people are currently infected with the same malware) but that explanation seems, to me, very unsatisfying.

Re: LastPass users warned their master passwords are compromised

#265

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

I haven't used uBlock and also got the LastPass email where someone had my password that wasn't stored or used anywhere else. I also haven't used my account in a few years.

Re: LastPass users warned their master passwords are compromised

#266

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

I'm one of the people that replied yesterday. I haven't used LastPass since, at the latest, 2017. I had actually deleted all my passwords from my LastPass vault, but originally kept the account because of LastPass's password sharing feature, though I stopped using that as well. I believe I had the LastPass extension installed on both Chrome and Firefox, on both Mac and Ubuntu. I primarily used Chrome on Mac. I did ha…

Almost identical case except I think I last used my account in 2018. No matches in haveibeenpwned. Password not saved anywhere (written only) and hasn't been typed in years.

Re: LastPass users warned their master passwords are compromised

#267
post #238

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

It still seems that the most likely answer might be that lastpass are incorrectly alerting that someone's correct passphrase had been used, and that the email is being triggered by a bug, or something like a login attempt using the wrong password from a suspicious IP. The fact that lastpass support says that it means that the correct password was used doesn't mean it's true, the support staff might just be mistaken.

Agree here.

Re: LastPass users warned their master passwords are compromised

#268

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

My money is on compromised hardware, someone has bought the stealer logs and tried to scrape the whole lot at once. If you got it, assume you have malware and all your passwords you have entered have been captured.

Best way to confirm this?

Re: LastPass users warned their master passwords are compromised

#269
post #162

Earlier quoted context omitted.

To be fair to LastPass/LogMeIn, they're a company handling a lot of valuable information (passwords/form-fill data/card numbers/notes etc.) - and they're one of the biggest out there. You'd expect them to be one of the more targeted companies just because of the 'treasure' they hold - hence the more security breaches.

An “Ask HN” was just trending about this yesterday ( https://news.ycombinator.com/item?id=29705957 ). Sounds like a good reason not to trust any third party service with my password database to me. I’ve always taken the route of managing my own local Keepass DB & key files. Sure it’s more cumbersome, but it prevents me from having to decide whether or not to trust some third party vendor or not. I know 100% that I’m…

For a personal password manager, that works ok, although syncing between multiple devices can be complicated and is sort of what I do, but it is much more difficult when you need to manage shared password for a team. At the very least you need some sort of locking mechanism to prevent accidentally overwriting someone else's change. And you also probably want an audit log, admin override capabilities, ability to grant different levels of access to different groups, etc.

Pass with a git repo satisfies some of those requirements, but it isn't very user friendly for non-technical users, and fine grained access controls and groups is tricky.

Re: LastPass users warned their master passwords are compromised

#270
post #254
post #162

Earlier quoted context omitted.

An “Ask HN” was just trending about this yesterday ( https://news.ycombinator.com/item?id=29705957 ). Sounds like a good reason not to trust any third party service with my password database to me. I’ve always taken the route of managing my own local Keepass DB & key files. Sure it’s more cumbersome, but it prevents me from having to decide whether or not to trust some third party vendor or not. I know 100% that I’m…

>I know 100% that I’m in full control and I’ve never put my DB or key file in the cloud. I can sleep sound knowing that whatever password service, or file sharing service, somehow getting compromised, cannot endanger one of my most valuable assets What's the risk of keeping the keyfile/password on your device(s) but uploading the database to the cloud? Assuming your keyfile has enough entropy (eg. 256 bits), your dat…

Because something like this break will happen, and the fewer suspects the better. Maybe the code to upload the encrypted version is buggy, maybe the code hits a bug that uploads the private key to Dropbox... there are all sorts of "maybes", no matter how remote. If the file never touches, eg, Dropbox's servers, then there's zero possibility the break happened because of something related to Dropbox. Maybe the keys used are weak in some manner that is later discovered.

Do you own assessment of all of the "maybes", and come up with your own conclusion and practices. Someone else's hard drive is not to be trusted, but it is convenient.

Post reply on HN