Live data from Hacker News

Ask HN: How did my LastPass master password get leaked?

news.ycombinator.com

371–380 of 529 posts

Re: Ask HN: How did my LastPass master password get leaked?

#372
post #27

Earlier quoted context omitted.

Personally I just stick to local Keepass database files. I’ve never ventured into the cloud based services. If you are really worried about it, do you really need to use a cloud based password service? Sure, managing the KeePass files by hand is certainly more cumbersome, but to me it’s worth it for the security/ peace of mind gains. I have never put my DB or key files in the cloud. And when I need to sync them up ov…

TIL about the merge functionality! You can also use Syncthing to synchronise the databases between your devices; if you don't have public IPs for your devices, this essentially means that you can only synchronise when two devices are on the same network -- but this might not be a problem for you.

You can also use Syncthing and the merge function! It comes in very handy when two devices have made changes to the password database file and you end up with merge conflicts :D

Re: Ask HN: How did my LastPass master password get leaked?

#373

Earlier quoted context omitted.

That's really bad, and possibly invalidates the theory that this is a breach dating back from 2017... Would you mind sharing the ip address that attempted to login? Also, you created the account this year, in 2021? Thanks

Yep I created the account just last month, here are the 'Was this you?' details from the email: Time Wednesday, November 10, 2021 at 2:57 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.92.198

Thanks for confirming.

This is what's really, extremely troubling: some of the accounts (which had almost successful login attempts from the 160.116 range) here were created years ago. Mine was from 2017, others were too.

But a few reports, like yours, talk about recently created accounts.

In my personal case, I've never logged into that LastPass account since 2017.

So... was there a vulnerability back in 2017 and very recently? Or was this a recent vulnerability? Do the attackers have our master passwords, or did they discover some ability to counteract the master password verification, which is triggering those emails to be sent?

Re: Ask HN: How did my LastPass master password get leaked?

#374

Earlier quoted context omitted.

Fascinating, we must be at about 20 independent reports here. When was your account created?

My account was created 13 years ago.

Thanks a lot for confirming. Many accounts such as yours and mine were from years ago, but there are a few reports here in this thread about accounts created this year.

It's becoming harder to find a common thread between all of us.

Re: Ask HN: How did my LastPass master password get leaked?

#375

Earlier quoted context omitted.

Yeah, that's not impossible. Surprising that they sat on the passwords for so long, but this is quite possible. Thanks for the reference/link!

You don't necessarily know they sat on it. You only just got a notification of the failed login now. That doesn't mean they didn't try stuffing it elsewhere previously, or have login attempts you weren't notified of. Nor do you know if the entity responsible for the failed login is the one who originally captured the credentials. If you'll forgive the wild speculation, your credentials could have been sold recently a…

Yeah, totally agreed and all great points.

I also generally am more suspicious of the idea that they sat on the credentials for years. Although that is not impossible.

One disproving fact (of sitting on the password for years) is that a few people here in this thread confirm having a login attempt from the exact same ip range, but with an account that was created this year -- in one case, in November 2021:

https://news.ycombinator.com/item?id=29710262

So... it might turn out to be a much more recent vulnerability after all.

Re: Ask HN: How did my LastPass master password get leaked?

#376

Earlier quoted context omitted.

There are multiple independent reports here of that error happening as well! See: https://news.ycombinator.com/item?id=29708961 One commenter noted that it wasn't possible to login again (after that error happened), so presumably the account was deleted...?

Have you actually contacted lastpass about this?

I contacted LastPass support twice over the phone about the suspicious login attempts. I was shrugged off twice.

I contacted them again by email yesterday, adding the link to this thread, and mentioning the number of similar ip addresses that all attempted to login, presumably with the knowledge of the master password (or a workaround around it? or the password's hashes?). I'm hoping it gets escalated.

Also, I have not contacted LastPass about the error that shows up when deleting an account. I'm keeping my account around since I want to have access to the entry logs related to all of this for now.

Re: Ask HN: How did my LastPass master password get leaked?

#377

Earlier quoted context omitted.

Yep I created the account just last month, here are the 'Was this you?' details from the email: Time Wednesday, November 10, 2021 at 2:57 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.92.198

Thanks for confirming. This is what's really, extremely troubling: some of the accounts (which had almost successful login attempts from the 160.116 range) here were created years ago. Mine was from 2017, others were too. But a few reports, like yours, talk about recently created accounts. In my personal case, I've never logged into that LastPass account since 2017. So... was there a vulnerability back in 2017 and ve…

Could it be that some malware were run on your machines recently (say a few weeks ago) which extracted the master passwords and then used it now? If your LastPass master password was stored on your computer then malware could have collected it and sent it off to some attacker.

Or could it be that all of you guys are using the same router, same ISP, same anything-else, which has snooped on traffic and collected the credential?

Re: Ask HN: How did my LastPass master password get leaked?

#378

Earlier quoted context omitted.

Thanks for confirming. This is what's really, extremely troubling: some of the accounts (which had almost successful login attempts from the 160.116 range) here were created years ago. Mine was from 2017, others were too. But a few reports, like yours, talk about recently created accounts. In my personal case, I've never logged into that LastPass account since 2017. So... was there a vulnerability back in 2017 and ve…

Could it be that some malware were run on your machines recently (say a few weeks ago) which extracted the master passwords and then used it now? If your LastPass master password was stored on your computer then malware could have collected it and sent it off to some attacker. Or could it be that all of you guys are using the same router, same ISP, same anything-else, which has snooped on traffic and collected the cr…

Malware is not impossible, but in my case, the password is stored in an encrypted keepass file. Did the malware wait for me to open my keepass vault and snoop the password then? Possibly. But it presumably could/would have done much worse things.

Other people in this thread are also confirming that their password was unused anywhere else.

And as more independent people are reporting the same story happening to them, the less probable it is that we were all hit with the same malware. It's looking more and more like this is something happening on the LastPass side.

A router/ISP should not be able to snoop the traffic between us and LastPass as presumably it's encrypted.

Re: Ask HN: How did my LastPass master password get leaked?

#379

I am surprised that LastPass have not yet addressed this. Even if it isn't a widespread incident, the fact that this is being reported by multiple people seems worrying enough for a password manager to respond promptly.

I agree. I contacted the support agent I talked to again with a link to this thread and all of the similar IP addresses that tried to login, presumably with the knowledge of our master passwords.

I also sent off a random email to the Verge, and tried tagging LastPass on Twitter.

Does anyone have tech media connections who could try to squeeze a word out of LastPass?

Re: Ask HN: How did my LastPass master password get leaked?

#380

> Either the 3 of us had the same malware/Chrome extension Is stealing the master password this way possible in practice? As far as I know, Chrome extensions cannot inject e.g. JavaScript into tabs and toolbar popups that are owned by Chrome extensions. Random pages and extensions are able to send string/JSON messages to an extension but message sources usually have to be on an allow list + JavaScript `eval` should b…

[deleted]
Post reply on HN