Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

31–40 of 326 posts

Re: LastPass users warned their master passwords are compromised

#31
LastPass has had a history of security incidents (no company can completely avoid incidents, but if security is literally a primary part of your value, you shouldn’t be having so many).

Even worse, they have a history of doing hand-wavy corporate non-explanations for what actually happened in these incidents. The antithesis of being responsible and respecting users in the modern day.

Re: LastPass users warned their master passwords are compromised

#32

Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

You can do this with LastPass.

Re: LastPass users warned their master passwords are compromised

#34
post #10
post #7

> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after c…

Ones which say "something went wrong" with a "funny" gif of someone scratching his head?

Add a recaptcha that barrely solves in the mix before being able to click on continue, or after logging in.

Re: LastPass users warned their master passwords are compromised

#35
This is framed so negatively toward LastPass, which is unfortunate. They stopped all usage of correct passwords they believed were compromised, which is exactly what I'd want them to do in this situation. Them warning users their master passwords are compromised is a good thing! Yet it's framed as though they're admitting to something.

"However, users receiving these warnings have stated that their passwords are unique to LastPass and not used elsewhere." That's really hard to verify. I think most users would say that rather than admit they re-used passwords (or used similar passwords that were easy to reverse engineer). Since there only seems to be 2-3 reports of this, and they're self-reported and not cited, it doesn't seem like LastPass was compromised.

I'm not saying I like LastPass (I use 1Password and find LastPass to be much worse), but I haven't seen any indication at this point that LastPass has been compromised at all.

(To be clear, it's very possible I'm wrong and this message won't age well. But so far, it seems like LastPass is doing its job, and I'd want to see more than this before jumping on the blame-LastPass bandwagon.)

Re: LastPass users warned their master passwords are compromised

#37

LastPass's statement via HowToGeek: https://www.howtogeek.com/776450/lastpass-says-it-didnt-leak...

So original article is down, but this sounds like people who used the same password as their master and in some _other_ service that has been leaked. ie a user who's lastpass master pass is same as their facebook. Very different from having LastPass leak master pass. Is this the same issue or a case of LastPass not getting the situation?

This article mentions that there were users with unique LastPass passwords who had this occur. Also, I guess they have no incentive to admit a breach

Re: LastPass users warned their master passwords are compromised

#38

Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

Ah yes, the $5 wrench method.

A simple rubber hose would do. https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis

Re: LastPass users warned their master passwords are compromised

#39
post #6

obligatory: I use passwordstore.org by Jason A. Donenfeld and its local, relatively easy to use, works with git, and free. Too niche for hackers to take interest I hope.

I used to use pass, and while it’s fine if you’re primarily a terminal user, it’s much less convenient if you’re dealing with Windows or mobile devices. Instead of fiddling with git and gpg (which is super painful on Android), I just use KeePassXC on desktop (Windows/Linux/Mac), Keepass2Android on Android, and sync my database via OneDrive. KeePass gives me search, storage of metadata and even attachments, simple copying, and auto-type. Much friendlier than pass ever could be.

Re: LastPass users warned their master passwords are compromised

#40

Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

You can do this with LastPass.

I'm the OP from yesterday's story.

I had 2fa enabled on my LastPass account, but didn't have access to the phone anymore. I clicked a link, LP sent me an email, and I was able (through that email) to remove 2fa.

It doesn't make their 2fa completely useless, but it's not great.

Post reply on HN