Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

291–300 of 326 posts

Re: LastPass users warned their master passwords are compromised

#291
post #162

Earlier quoted context omitted.

An “Ask HN” was just trending about this yesterday ( https://news.ycombinator.com/item?id=29705957 ). Sounds like a good reason not to trust any third party service with my password database to me. I’ve always taken the route of managing my own local Keepass DB & key files. Sure it’s more cumbersome, but it prevents me from having to decide whether or not to trust some third party vendor or not. I know 100% that I’m…

I recommend this every time a similar news item gets posted. Password Safe (designed by Bruce Schneier). I use the iOS and Linux apps and keep them synced via DropBox. Been around for years (I've been using it almost as long). Still getting updates. Still works. https://pwsafe.org

I've been doing this for years too. I recently bought two yubi keys and now don't rely on a master password for it. However now I'm scared I could lose my yubi keys.

Not sure what I can do about that.

Re: LastPass users warned their master passwords are compromised

#292
post #275

Earlier quoted context omitted.

For FIDO (and thus WebAuthn, and thus to make this actually practical beyond a toy that only works for some particular Yubico product) the keys are random per enrollment. This is intentional because it means that you can't be tracked, since "your" key on Facebook and "your" key on GitHub are no more related to each other than "my" key on Facebook is to "your" key on GitHub. Google have apparently some plans to addres…

>This is intentional because it means that you can't be tracked, since "your" key on Facebook and "your" key on GitHub are no more related to each other than "my" key on Facebook is to "your" key on GitHub. I get the motivation behind it, but the mechanism I proposed in the last comment still preserves those properties? Each site would still get its own derived ECDSA public key. The master ECDSA public key would only…

To complete enrollment you need to know the corresponding private key, live.

The relying party says "I am some.example and I want to enroll a Security Key, but, not ones which recognise these huge random-looking IDs that are already enrolled: 12345678, 34561234. I also picked this random nonsense XYZXYZXYZ. Go for it" and your browser talks to your Security Keys until it finds one that isn't already enrolled, gets that one to sign the appropriate message and sends back, "I am a web browser, I checked that you are some.example. I picked my own random nonsense XXXZZZ, and a Security Key picked public key ABCDEF, then to prove it knows the private key it signed this message for some.example mentioning XYZXYZXYZ and XXXZZZ and with bitflags it understands enough to know what it's signing. It says the resulting credentials have random-looking ID 98765431. Thanks". /s/Security Key

If the Security Key cost less than a low-end Yubikey, it has no storage. That random-looking ID is in some sense your private key for the site, but suitably encrypted, e.g. with AES in Galois/Counter Mode, so that the device needn't remember it, when a site asks keys to authenticate, it must provide the ID they're authenticating against, and so they can do AES GCM, figure out if they minted this ID, and if so recover the private key and authenticate. This is fiendishly clever, but so far as I can see renders your idea impossible.

Re: LastPass users warned their master passwords are compromised

#293

Confession: I store all my passwords in a plaintext file on my local desktop. I'm sure some people will look at me very funny for doing this, but it seems to me that I have both fewer hassles logging in and fewer breaches than people using more "secure" methods (like handing your passwords over to LastPass's mystery Chrome extension). Think about today's threat landscape and tell me I'm wrong. I may not be more secur…

I use Vim's built in symmetric encryption with :X

One of the reasons I haven't moved over to NeoVim is because they removed this feature, because supposedly it's not perfect or something. So sure, the NSA may be able to still be able to extract my passwords if they arrest me and take my computer, but the point is that random people won't be able to.

Re: LastPass users warned their master passwords are compromised

#294
post #52
post #5

Earlier quoted context omitted.

all the speculation in that thread about how the password could have been leaked reminded me of a post earlier this year that drastically changed my view on password managers. (also generated a lot of discussion here) https://news.ycombinator.com/item?id=27407603

Seems like the lesson there is to use a standalone password manager, rather than one that's a browser extension?

Some guy did an long analysis and figured for most purposes you are as well to use the built in ones in Chrome or Firefox. Personally I kind of like Bitwarden.

Re: LastPass users warned their master passwords are compromised

#295

Earlier quoted context omitted.

My money is on compromised hardware, someone has bought the stealer logs and tried to scrape the whole lot at once. If you got it, assume you have malware and all your passwords you have entered have been captured.

Best way to confirm this?

10's of GB of credential data is being harvested daily, and personally I think these stealer logs are the greatest security threat at the moment .

To confirm, you would have to basically get access to all the stuff that has been sold, as the malware is pretty widely sold and distributed it is effectively ad infinite data set, and constantly growing.

A previous responder checked with a security researcher who has a Redline Dataset and was not in there. Some of the annecdotes suggest it is from an old breech likely before 2020. Given the age and how these things get bought / sold / compiled into bigger datasets, there is a fair chance that researchers have the data and hopefully lastpass can dig into it to find the source.

Re: LastPass users warned their master passwords are compromised

#296

Lots of people here recommending to switch to Keepass. I have both Keepass and Lastpass, but the reason I didn't do away with Lastpass yet is basically that it seems to me that Keepass can't do proper form-filling like Lastpass can? I'm talking about: auto filling custom configurable fields, addresses, credit cards, etc. Am I missing something, some addon/extension? My current Keepass setup: Keepass 2 with Keeweb for…

I use KeePass on multiple devices, all sync'd via SFTP to/from a database on a cheap VPS, and I'm really happy with my setup.

KeePass lets me fill in the username and password fields, and I can configure the names of the fields if KeePass can't figure it out itself. My browser remembers not-so-secret stuff such as my address, and it's very rare I'd want additional form fields managed by KeePass, beyond username and password. That said, I wouldn't be surprised if there was a plugin that does that.

Re: LastPass users warned their master passwords are compromised

#297
post #31

LastPass has had a history of security incidents (no company can completely avoid incidents, but if security is literally a primary part of your value, you shouldn’t be having so many). Even worse, they have a history of doing hand-wavy corporate non-explanations for what actually happened in these incidents. The antithesis of being responsible and respecting users in the modern day.

To be fair to LastPass/LogMeIn, they're a company handling a lot of valuable information (passwords/form-fill data/card numbers/notes etc.) - and they're one of the biggest out there. You'd expect them to be one of the more targeted companies just because of the 'treasure' they hold - hence the more security breaches.

That doesn’t prevent them from being open & honest about what caused a security incident and what they’ve since done to ensure they’re highly secure.

Furthermore, I’d argue that Firefox & chrome password managers probably have several orders of magnitude more passwords stored (and therefore much more highly targeted), yet they don’t seem to have annual security incidents. And you can’t even pay for those products.

People stealing passwords are probably doing it to eventually make money. Criminals could save themselves a ton of work by just directly hacking the banks, yet we don’t hear about highly regular complete compromises there.

Furthermore, if operating a password manager service puts a huge kick-me sign on your service, why don’t the other password managers have plenty of incidents?

Re: LastPass users warned their master passwords are compromised

#298
post #250
post #162

Earlier quoted context omitted.

An “Ask HN” was just trending about this yesterday ( https://news.ycombinator.com/item?id=29705957 ). Sounds like a good reason not to trust any third party service with my password database to me. I’ve always taken the route of managing my own local Keepass DB & key files. Sure it’s more cumbersome, but it prevents me from having to decide whether or not to trust some third party vendor or not. I know 100% that I’m…

I use KeePass with Syncthing, which works across all my PCs + Android. It's a good option if you don't want to use Dropbox or similar.

I wish there was an integrated solution for this approach. Both programs are relatively hard to use in isolation, for "civilians"; combining them is pretty hard.

Password management, afaik, still needs a zero-knowledge cloud-agnostic solution that is easy to set up and run. There are the big boys (1password, bitwarden, LastPass) and then there are local-only solutions; in between, where the sweet spot should be, there is only a bunch of hacks. The issue is monetization - the incentives for that side are towards centralizing.

Re: LastPass users warned their master passwords are compromised

#300

Earlier quoted context omitted.

To be fair to LastPass/LogMeIn, they're a company handling a lot of valuable information (passwords/form-fill data/card numbers/notes etc.) - and they're one of the biggest out there. You'd expect them to be one of the more targeted companies just because of the 'treasure' they hold - hence the more security breaches.

once again, maybe security through obscurity is not the worst idea...

As long as it's not the only idea..
Post reply on HN