Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…
+1 on uBlock Origin, but I think that's just a too common of an extension rather than the cause.
LastPass users warned their master passwords are compromised
301–310 of 326 posts
Re: LastPass users warned their master passwords are compromised
#302Re: LastPass users warned their master passwords are compromised
#303Re: LastPass users warned their master passwords are compromised
#304Earlier quoted context omitted.
> Your master passwords aren't stored on their servers. Neither is your key information. ...and, those are the only things that really matter for an attacker. Encrypted data (assuming reasonably strong encryption) is useless without the key.
Some encrypted data is worthless. Some isn't. Depends on what value it has when down the road the encryption is broken.
Re: LastPass users warned their master passwords are compromised
#305A user posted this comment then deleted it. Is this true? If so. JFC. >>> Take this with a grain of salt. LogMeIn, the owners of LastPass, had a Chinese APT group in their servers for years. They only found out because the attackers started launching unoptimised SQL queries that started killing their database cluster. They didn’t have to report this breach, despite being based in Germany where it’s a legal requiremen…
Not saying you're lying, but could you provide a source?
[0] https://www.pcworld.com/article/491164/lastpass_ceo_exclusiv...
Re: LastPass users warned their master passwords are compromised
#306Earlier quoted context omitted.
I'm not here to defend LastPass, but there are some rational answers to the questions you're asking, a lot of them having to do with human psychology. First thing's first, and yes I am "victim blaming" when I say this: 60% of users reuse their passwords. [0,1] It's a widespread problem. Maybe that number is lower for a technical site like HN, but I have encountered technical people who do not practice what they preac…
Like the accidental VPN possibility: did anyone consider the recently released Apple iCloud private relay feature as a potential reason for receiving these notification? It may present a different IP/country to LastPass when actual users log in. https://support.apple.com/en-us/HT212614
Re: LastPass users warned their master passwords are compromised
#307> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after c…
Re: LastPass users warned their master passwords are compromised
#308Earlier quoted context omitted.
>This is intentional because it means that you can't be tracked, since "your" key on Facebook and "your" key on GitHub are no more related to each other than "my" key on Facebook is to "your" key on GitHub. I get the motivation behind it, but the mechanism I proposed in the last comment still preserves those properties? Each site would still get its own derived ECDSA public key. The master ECDSA public key would only…
To complete enrollment you need to know the corresponding private key, live. The relying party says "I am some.example and I want to enroll a Security Key, but, not ones which recognise these huge random-looking IDs that are already enrolled: 12345678, 34561234. I also picked this random nonsense XYZXYZXYZ. Go for it" and your browser talks to your Security Keys until it finds one that isn't already enrolled, gets th…
This seems like the main blocker. Why is that required? In theory all the site needs is a public key to verify against.
Re: LastPass users warned their master passwords are compromised
#309Earlier quoted context omitted.
Same here. It appears(?) that my account got deleted.
Confirmed. I deleted my account, received the error above. Then when attempting to login again, I was told my email was mistyped. I stopped using LastPass a long time ago, but this has definitely put them on thin ice for me, I won't be recommending them going forward.
Re: LastPass users warned their master passwords are compromised
#310Earlier quoted context omitted.
all the speculation in that thread about how the password could have been leaked reminded me of a post earlier this year that drastically changed my view on password managers. (also generated a lot of discussion here) https://news.ycombinator.com/item?id=27407603
Seems like the lesson there is to use a standalone password manager, rather than one that's a browser extension?
For high-value logins, I use Passwordsafe. It's annoying; the scroll behaviour is annoying, and it's Windows-only, which is sad. But it's resolutely local and un-networked, and I'm confident that my secrets are well-protected by my (complex, long, memorized) master password.