Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

71–80 of 326 posts

Re: LastPass users warned their master passwords are compromised

#71
post #51

Earlier quoted context omitted.

Nope. Keeping my secrets store on someone else's computer is simply not compatible with my threat model. Yes, they say it is encrypted, and I believe them and believe they're competent. But competent people write vulnerable code all the time, disastrously bad hires happen (see Unifi), and companies go bad. You can't un-disclose information stored with them, only laboriously invalidate it.

What's your personal threat model? I'm always trying to balance the risk of a party focused on security vs the minimal effort I'm likely to put into it. I don't want to be a story about the guy that lost their password to a wallet or anything else important. I used to be able to reliably remember complex passwords reliably but finding that's no longer the case, now only shorter intermittently used ones based on how o…

I’ve decided that besides a password manager, all of my passwords will also have a number at the end, like 8 (simple, easy to append manually in a password field. Now the password manager has to get defeated AND my own small personal salt value will have to be known.

Re: LastPass users warned their master passwords are compromised

#72
post #7

> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after c…

>Must be a compromised browser extension at this point

Just for fun, I downloaded the official LastPass chrome extension. The zip file is 32MB before unzipping, and it has 426 separate *.js files, total of 25MB of javascript. That should be a fun audit.

Edit: To be clear, nobody has said the LastPass extension is compromised, though that is one possibility.

Edit #2: Some of the larger js files do have a fair amount of the size as arrays of localized text, error messages, lists of numbers, etc. But it is still a lot of JS.

Re: LastPass users warned their master passwords are compromised

#73
post #51

Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

Nope. Keeping my secrets store on someone else's computer is simply not compatible with my threat model. Yes, they say it is encrypted, and I believe them and believe they're competent. But competent people write vulnerable code all the time, disastrously bad hires happen (see Unifi), and companies go bad. You can't un-disclose information stored with them, only laboriously invalidate it.

Your personal infrastructure is likely much more volatile than some Expert company. Unless of course you happen to be an industry expert ...

Re: LastPass users warned their master passwords are compromised

#74
post #72
post #7

> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after c…

>Must be a compromised browser extension at this point Just for fun, I downloaded the official LastPass chrome extension. The zip file is 32MB before unzipping, and it has 426 separate *.js files, total of 25MB of javascript. That should be a fun audit. Edit: To be clear, nobody has said the LastPass extension is compromised, though that is one possibility. Edit #2: Some of the larger js files do have a fair amount o…

Wow, how can this amount of files be justified?

And how did this breached exactly happen?

Re: LastPass users warned their master passwords are compromised

#75

Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

Ever since 1password removed local vaults I am looking / waiting for a decent alternative. I also wonder what the impact of that move was on enterprise users, as they don‘t have hosted version.

Re: LastPass users warned their master passwords are compromised

#76

Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

Ah yes, the $5 wrench method.

Are you aiming for perfect or have you stopped at good enough?

Re: LastPass users warned their master passwords are compromised

#77
post #7

> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after c…

"Something went wrong"

> Is there anything more infuriating than this type of error message?

Well the other classic move by webshits is to have you stare at a spinner indefinitely.

Re: LastPass users warned their master passwords are compromised

#78
post #54
post #7

> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after c…

>Must be a compromised browser extension at this point. The previous thread had password never typed, copied or used for years. Unless we are talking about multiple vector, otherwise browser extension doesn't fit most of the reported scenario.

Maybe hashes got snarfed somehow, possibly multiple times, and some passwords shook out of a rainbow table?

Impending company changes also raises the possibility of an insider attack.

Re: LastPass users warned their master passwords are compromised

#79

Is there anything like lastpass that has TOTP + password remote backup that has a chrome plugin and an android application? I'm getting to the point where I'd love to switch off.

I use KeepassXC on my desktop OS's, storing my database on a NextCloud instance. Android can R/W that same file using the KeePassDX app (available on either the Play store or F-Droid). I can store TOTP keys in my Keepass database as well. My browser has an extension that lets me autotype the username, password, and TOTP codes.

I know storing my TOTP passphrase along with my un:pw combo isn't as secure as keeping them in separate locations, but my threat model is just to stop someone with only my un:pw.

YMMV

Re: LastPass users warned their master passwords are compromised

#80
post #3

Let this be your Last non-selfhosted Pass solution.

No no. Everything has to be hosted on the cloud with a monthly subscription.

Exactly, otherwise how will you ever get updates or product support?
Post reply on HN