Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

301–310 of 326 posts

Re: LastPass users warned their master passwords are compromised

#301

Hey, I'm the OP from yesterday's story. A few people and I are trying to chase down which software in common could have resulted in our passwords being stolen. The most egregious and hard-to-understand related cases (now 3!): https://twitter.com/Valcristerra/status/1475734357805572098 "Someone tried my @LastPass master password earlier yesterday [Dec 27] and then someone just tried it again a few hours ago after I ch…

+1 on uBlock Origin, but I think that's just a too common of an extension rather than the cause.

Agreed that it's quite common. Also, at least 2 users who were compromised (or at least, received the email from LastPass) have confirmed not using it. So it's a wrong trail.

Re: LastPass users warned their master passwords are compromised

#304

Earlier quoted context omitted.

> Your master passwords aren't stored on their servers. Neither is your key information. ...and, those are the only things that really matter for an attacker. Encrypted data (assuming reasonably strong encryption) is useless without the key.

Some encrypted data is worthless. Some isn't. Depends on what value it has when down the road the encryption is broken.

Properly encrypted data is worthless unless you intend to get the keys somehow. Breaking industry standard encryption schemes shouldn't be in your threat model.

Re: LastPass users warned their master passwords are compromised

#305
post #257

A user posted this comment then deleted it. Is this true? If so. JFC. >>> Take this with a grain of salt. LogMeIn, the owners of LastPass, had a Chinese APT group in their servers for years. They only found out because the attackers started launching unoptimised SQL queries that started killing their database cluster. They didn’t have to report this breach, despite being based in Germany where it’s a legal requiremen…

Not saying you're lying, but could you provide a source?

They _may_ be referring to the 2011 incident [0], which was "unusual network activity".

[0] https://www.pcworld.com/article/491164/lastpass_ceo_exclusiv...

Re: LastPass users warned their master passwords are compromised

#306
post #207

Earlier quoted context omitted.

I'm not here to defend LastPass, but there are some rational answers to the questions you're asking, a lot of them having to do with human psychology. First thing's first, and yes I am "victim blaming" when I say this: 60% of users reuse their passwords. [0,1] It's a widespread problem. Maybe that number is lower for a technical site like HN, but I have encountered technical people who do not practice what they preac…

Like the accidental VPN possibility: did anyone consider the recently released Apple iCloud private relay feature as a potential reason for receiving these notification? It may present a different IP/country to LastPass when actual users log in. https://support.apple.com/en-us/HT212614

Not a credible explanation given all those users who haven't logged in in years.

Re: LastPass users warned their master passwords are compromised

#307
post #7

> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after c…

I did not get any email about login attempt, but deleted my old Lastpass account as a precaution anyways, and also received this error. No confirmation of deletion via email. However, I'm not able to log in anymore, and attempts to get master pwd hint via email don't work either, so I believe it's more or less deleted.

Re: LastPass users warned their master passwords are compromised

#308
post #275

Earlier quoted context omitted.

>This is intentional because it means that you can't be tracked, since "your" key on Facebook and "your" key on GitHub are no more related to each other than "my" key on Facebook is to "your" key on GitHub. I get the motivation behind it, but the mechanism I proposed in the last comment still preserves those properties? Each site would still get its own derived ECDSA public key. The master ECDSA public key would only…

To complete enrollment you need to know the corresponding private key, live. The relying party says "I am some.example and I want to enroll a Security Key, but, not ones which recognise these huge random-looking IDs that are already enrolled: 12345678, 34561234. I also picked this random nonsense XYZXYZXYZ. Go for it" and your browser talks to your Security Keys until it finds one that isn't already enrolled, gets th…

>you need to know the corresponding private key, live.

This seems like the main blocker. Why is that required? In theory all the site needs is a public key to verify against.

Re: LastPass users warned their master passwords are compromised

#309

Earlier quoted context omitted.

Same here. It appears(?) that my account got deleted.

Confirmed. I deleted my account, received the error above. Then when attempting to login again, I was told my email was mistyped. I stopped using LastPass a long time ago, but this has definitely put them on thin ice for me, I won't be recommending them going forward.

Ditto - I recently switched to BitWarden and kind of forgot that I was still giving it a self determined "trail period." This certainly kicked that trail period into my new current password manager.

Re: LastPass users warned their master passwords are compromised

#310
post #52
post #5

Earlier quoted context omitted.

all the speculation in that thread about how the password could have been leaked reminded me of a post earlier this year that drastically changed my view on password managers. (also generated a lot of discussion here) https://news.ycombinator.com/item?id=27407603

Seems like the lesson there is to use a standalone password manager, rather than one that's a browser extension?

I'm not inclined to run anything that's remotely related to password security in a browser extension (I do use the Firefox built-in password manager to simplify logging in to sites like this one, where I have no money at stake and nothing much to lose but my pride).

For high-value logins, I use Passwordsafe. It's annoying; the scroll behaviour is annoying, and it's Windows-only, which is sad. But it's resolutely local and un-networked, and I'm confident that my secrets are well-protected by my (complex, long, memorized) master password.

Post reply on HN