Earlier quoted context omitted.
You probably don't have to worry. The main concern is whether LastPass has also faced a supply chain attack that will expose you to a malicious client that will leak your passwords post-decryption.
I'm surprised this isn't being discussed more.
Cracking encrypted LastPass vaults
51–60 of 118 posts
Re: Cracking encrypted LastPass vaults
#52So, if my lastpass master password is actually secure (~30 characters and contains capital, lowercase, symbols, and a long string of randomly-generated numbers that I memorized as part of it, and no part of this is reused anywhere else), do I have to worry? It does seem like a good idea to switch, but do I have to switch urgently ?
You probably don't have to worry. The main concern is whether LastPass has also faced a supply chain attack that will expose you to a malicious client that will leak your passwords post-decryption.
Re: Cracking encrypted LastPass vaults
#53Earlier quoted context omitted.
>It's a demonstration that a laptop can reach `2,000,000+ H/s`. No, the author says their laptop only reaches ~1kH/s. That 2 million number is a pure guess for a multi-gpu setup and that is still pretty weak, unless you have a very good dictionary for a specific target. Brute forcing remotely long alphanumeric passwords is out of the question. So if you have a 8+ character password with upper+lowercase characters and…
With 8 characters, which is way below all recommendations and using only alphanumeric + the simple special chars on the keyboard you're looking at over 7 * 10^14 possibilities. If you could do 100 million hashes per second (that seems to be possible with hardware looking at crypto stuff), the way I understand the setup you're still up against the 100100 iterations in the key derivation algorithm. So that's 7 * 10^19…
1) Find all vaults with the lowest iterations
2) Order by some criteria (known money sources: URLs for banks and crypto, known URLs that would have PII information: utilities, telcos, governmental URLs)
3) Start cracking...
Or they could skip all that for some quick money. There's no need to crack anything if the URLs can get you money. How much would a dictatorship pay for the identities of everyone with an account at a URL that posts negative information on the regime? A domain.com/wp-admin account could certainly get you killed.
Re: Cracking encrypted LastPass vaults
#54Earlier quoted context omitted.
> LastPass prioritized ease of onboarding (=increased profits) or (=increase number of users actually using a password manager)
1Password has a solution that is quite usable: it generates a secret key and provides facilities to transfer it between hardware devices as needed, e.g. from your phone to desktop. 1Password does not cloud store it and urges users to print a backup copy. There is a marginal usability benefit to LastPass’s lack of such facilities, but I think this breach shows that the security reduction was too high a price to pay fo…
> urges users to print a backup copy
I read it a few times in this thread already, but with the general lack of printers for most people, I find it kind of funny. I personally guess that more people put it unsecured in their dropbox than people actually printing it.
> I think this breach shows that the security reduction was too high a price to pay for it.
I think this breach shows that operational security for lastpass is lacking, something distinctly different from the password storage system security. Although it might be linked as in teams building less secure systems might have worse security themselves.
Re: Cracking encrypted LastPass vaults
#55Earlier quoted context omitted.
I think the other problem is that when people are thinking up “random” words on their own, they aren’t pulling from the English dictionary. Common vocabulary is a much smaller set.
About 20 000 active words is my understanding. And then the words people pick from is likely from fraction of that.
Most people know at least 3 languages well enough. I often make passphrases out of 5 to 6 languages.
Re: Cracking encrypted LastPass vaults
#56Good tutorial. This is why I prefer 1Password, as it requires the secret key to be compromised in addition to the Master Password, thus providing protection against a weak master password. I've always thought it foolish to recommend solutions like LastPass and BitWarden, which don't require a secret key. It is dangerous design, prioritizing ease of onboarding over actual security. The average consumer needs an autoge…
> Good tutorial. This is why I prefer 1Password, as it requires the secret key to be compromised in addition to the Master Password, thus providing protection against a weak master password. Do you know that or do you just hope they do what you think they do?
Re: Cracking encrypted LastPass vaults
#57Earlier quoted context omitted.
>It's a demonstration that a laptop can reach `2,000,000+ H/s`. No, the author says their laptop only reaches ~1kH/s. That 2 million number is a pure guess for a multi-gpu setup and that is still pretty weak, unless you have a very good dictionary for a specific target. Brute forcing remotely long alphanumeric passwords is out of the question. So if you have a 8+ character password with upper+lowercase characters and…
With 8 characters, which is way below all recommendations and using only alphanumeric + the simple special chars on the keyboard you're looking at over 7 * 10^14 possibilities. If you could do 100 million hashes per second (that seems to be possible with hardware looking at crypto stuff), the way I understand the setup you're still up against the 100100 iterations in the key derivation algorithm. So that's 7 * 10^19…
Speed.#1.........: 38789 H/s (11.17ms) @ Accel:128 Loops:64 Thr:64 Vec:1
Speed.#2.........: 39017 H/s (11.17ms) @ Accel:128 Loops:64 Thr:64 Vec:1
Speed.#3.........: 38894 H/s (11.16ms) @ Accel:128 Loops:64 Thr:64 Vec:1
Speed.#4.........: 39254 H/s (11.02ms) @ Accel:128 Loops:64 Thr:64 Vec:1
Speed.#5.........: 38626 H/s (11.17ms) @ Accel:128 Loops:64 Thr:64 Vec:1
Speed.#6.........: 39448 H/s (10.94ms) @ Accel:128 Loops:64 Thr:64 Vec:1
Speed.#7.........: 39256 H/s (11.06ms) @ Accel:128 Loops:64 Thr:64 Vec:1
Speed.#8.........: 38966 H/s (11.14ms) @ Accel:128 Loops:64 Thr:64 Vec:1
Speed.#9.........: 38870 H/s (11.17ms) @ Accel:128 Loops:64 Thr:64 Vec:1
Speed.#10.........: 39259 H/s (11.01ms) @ Accel:128 Loops:64 Thr:64 Vec:1
Speed.#\*.........: 390.0 kH/s
Used the same example as the author with 100500 iterations. I think with some good wordlists, I'd wager a ton of low hanging fruits will be wiped within a reasonable time. If we're talking a threat actor with $$, they'd do some serious damage on this dump.*edit: just wanted to clarify that I think bruteforcing this dump wouldn't be as useful. It would still take a crapload of resources to be effective or useful in that scenario.
Re: Cracking encrypted LastPass vaults
#58Earlier quoted context omitted.
1Password has a solution that is quite usable: it generates a secret key and provides facilities to transfer it between hardware devices as needed, e.g. from your phone to desktop. 1Password does not cloud store it and urges users to print a backup copy. There is a marginal usability benefit to LastPass’s lack of such facilities, but I think this breach shows that the security reduction was too high a price to pay fo…
My comment was only targeted against the claim that prefering easier onboarding (made by the parent comment) only means increasing profits (which probably is also true). Don't get me wrong, I am not making any "lastpass is better" point or anything, I currently think of switching to 1password, because it seems like the better solution overall. > urges users to print a backup copy I read it a few times in this thread…
Re: Cracking encrypted LastPass vaults
#59Good tutorial. This is why I prefer 1Password, as it requires the secret key to be compromised in addition to the Master Password, thus providing protection against a weak master password. I've always thought it foolish to recommend solutions like LastPass and BitWarden, which don't require a secret key. It is dangerous design, prioritizing ease of onboarding over actual security. The average consumer needs an autoge…
So your more secure solution involves using... another, stronger, password? How would your mother use 1Password if she now has to remember _two_ passwords? Both LastPass and Bitwarden (and 1Password) support 2FA. This isn't a solution that will have mass adoption, but the UX is much better and more secure than using a secret key. It could even be used by non technical users, depending on the device. But password mana…
AFAIK it doesn't help if your vault is in the hand of someone who obtained it from a security breach on lastpass/bitwarden side.
Re: Cracking encrypted LastPass vaults
#60Earlier quoted context omitted.
> if you tell the cracking tool your password it can indeed crack it... It's called "dictionary attack", but author wasn't bothered doing full brute-force attack or masked attack. It's a demonstration that a laptop can reach `2,000,000+ H/s`.
Actually, he said his laptop maxed out at 1110 H/s. He then said that using multiple GPUs one could likely achieve 2 MH/s and higher.