Live data from Hacker News

Cracking encrypted LastPass vaults

markuta.com

71–80 of 118 posts

Re: Cracking encrypted LastPass vaults

#71
post #19

Earlier quoted context omitted.

> Good tutorial. This is why I prefer 1Password, as it requires the secret key to be compromised in addition to the Master Password, thus providing protection against a weak master password. Do you know that or do you just hope they do what you think they do?

Ultimately I trust that they do as they say, which is necessary to any modern computer use. The same way that I have to trust that my OS vendor is not stealing everything I have.

Yes true, attack surface is already big enough, lets upload our passwords into the cloud...cant be much worse...oh wait...

Re: Cracking encrypted LastPass vaults

#72
post #64
post #47

Earlier quoted context omitted.

So your more secure solution involves using... another, stronger, password? How would your mother use 1Password if she now has to remember _two_ passwords? Both LastPass and Bitwarden (and 1Password) support 2FA. This isn't a solution that will have mass adoption, but the UX is much better and more secure than using a secret key. It could even be used by non technical users, depending on the device. But password mana…

> How would your mother use 1Password if she now has to remember _two_ passwords? She doesn't have to remember the secret key. She prints out copies and puts them somewhere safe. > Both LastPass and Bitwarden (and 1Password) support 2FA [...] the UX is much better and more secure than using a secret key No. Please don't make statements like this if you're not certain. 2FA confers zero benefit in a breach like this on…

[dead]

Re: Cracking encrypted LastPass vaults

#73
post #61
post #57

Earlier quoted context omitted.

Just out of curiosity I booted up a box with 10x RTX A6000 @ 451.6 TFLOPS Speed.#1.........: 38789 H/s (11.17ms) @ Accel:128 Loops:64 Thr:64 Vec:1 Speed.#2.........: 39017 H/s (11.17ms) @ Accel:128 Loops:64 Thr:64 Vec:1 Speed.#3.........: 38894 H/s (11.16ms) @ Accel:128 Loops:64 Thr:64 Vec:1 Speed.#4.........: 39254 H/s (11.02ms) @ Accel:128 Loops:64 Thr:64 Vec:1 Speed.#5.........: 38626 H/s (11.17ms) @ Accel:128 Loo…

So you're doing 4e10 hashes per second or 390k password guesses per second. At what price per hour?

Used vast.ai for this setup: $5.875/hr. Using their API you can likely find better deals and launch a series of different setups and optimize your spending. Hope that helps.

Re: Cracking encrypted LastPass vaults

#74
post #66
post #62

Earlier quoted context omitted.

I used the wrong word apparently. My security vocab got worse over the years, sorry. What I meant by it: Securing the system against breaches of, even encrypted, data. I was trying to differentiate the security of access to the encrypted database from the security of the data inside the encrypted database, i.e., how hard is it to get it, instead of how hard it is to break once you have it. Because I think that the se…

The whole point of a password manager is that "access security" will fail at some point. That's the reason they are E2EE. Every password manager is built with the idea that one day, the server will be hacked and the vaults will be free to download. The same goes for E2EE in general. With this in mind, LastPass and Bitwarden's solutions are very poor and can result in most customers vaults being breached, whereas 1Pas…

> The whole point of a password manager is that "access security" will fail at some point. That's the reason they are E2EE.

Maybe that's a better way of restating my point that access security is not identical to the security of the password store.

> With this in mind, LastPass and Bitwarden's solutions are very poor and can result in most customers vaults being breached, whereas 1Password's secret key model stays strong.

While believable that most peoples passwords are weak enough to be broken, I wonder how many people actually have bad enough passwords to be reasonably decrypted.

I have no doubt about the security of 1passwords secret-key model being stronger - and I haven't seen anyone claim any different. At most I have seen anyone claim it is cumbersome and will get people to use no password manager instead (resulting in weak, reused passwords).

Re: Cracking encrypted LastPass vaults

#75
post #33
post #23

Earlier quoted context omitted.

With 1Password you also have a randomly generated secret key. As I recall it’s a 128-bits, but could be wrong. To access your vault an attacker will need both your master password and the secret key. These are effectively combined to generate your keys for decryption. This protects against an attacker gaining access to 1Password servers. They can’t control whether you chose an awful password or not. So to protect the…

Sorry, I don't get it. The secret key has to be stored somewhere, right? If it's on the server, the attacker gets it together with the vault. If it's on the client, then you lose your phone → you lose your passwords, which is, while secure, very risky and I wouldn't expect it from a company focused on regular customers.

It’s generated locally when you create your account and not shared with 1Password. Various keys are derived from your master password and secret key.

The secret key is never sent to 1Password and is only used locally.

This is why it’s so much more secure than LastPass, and Bitwarden, and any other cloud hosted solution. I know, I just pissed off all the Bitwarden fans, but it is true.

You must save your Secret Key, but it’s also saved in Apple’s Keychain so there’s a copy there as well.

Finally, if you do lose your secret key, your account can be recovered using the Account Recovery process as long as there is someone else on your account with the appropriate permissions. If you want to know how that works, ask, but it’s sort of lengthy so I’ll skip it for now.

Re: Cracking encrypted LastPass vaults

#76
> I downloaded the popular rockyou.txt wordlist and put my actual vault master plaintext password inside (using a quarter of the wordlist), otherwise it would take 6 hours+ to crack.

I don't believe the 6 hours+ claim. (Or rather, the "+" is doing some serious lifting in that sentence.)

Looking at the password, it's of the correct-horse-battery-staple variety, which could be conservatively estimated at 44 bits of entropy (this is even ignoring the additional number appended to a random word) - which would take even the described "multi-gpu" setup with 2 million hashes a second just about 100 days to exhaust (or 50 days to have a 50% chance of getting it), let alone the 1000 hashes a second macbook the author was using.

Re: Cracking encrypted LastPass vaults

#77
post #2

Good tutorial. This is why I prefer 1Password, as it requires the secret key to be compromised in addition to the Master Password, thus providing protection against a weak master password. I've always thought it foolish to recommend solutions like LastPass and BitWarden, which don't require a secret key. It is dangerous design, prioritizing ease of onboarding over actual security. The average consumer needs an autoge…

I thought 1Password and LastPass were equal. Then I was asked to use LastPass still can’t believe how crude & crap it is compared to 1Password (even before breaches.)

I just logged in to delete my dormant free account – turns out I'm in a "Premium Trial" that I definitely never signed up for and never received any communication on. What happens when that runs out? No way to find out. And their UI hasn't improved a bit, they really try hard to be as unattractive as possible. Good riddance.

Re: Cracking encrypted LastPass vaults

#78

> otherwise it would take 6 hours+ to crack Ok, can you run it for 7 hours without your password in the list and let us know?

Given that a four word password should have around 44 bits of entropy (according to the correct horse battery staple XKCD), that should take 2^44 hashes to exhaust, or 2^43 hashes to have a 50% chance of getting the password. 2^43 hashes / (1000 hashes per second) are about ~280 years. That's a big "+".

Re: Cracking encrypted LastPass vaults

#79
post #47

Earlier quoted context omitted.

So your more secure solution involves using... another, stronger, password? How would your mother use 1Password if she now has to remember _two_ passwords? Both LastPass and Bitwarden (and 1Password) support 2FA. This isn't a solution that will have mass adoption, but the UX is much better and more secure than using a secret key. It could even be used by non technical users, depending on the device. But password mana…

> Both LastPass and Bitwarden (and 1Password) support 2FA. AFAIK it doesn't help if your vault is in the hand of someone who obtained it from a security breach on lastpass/bitwarden side.

That's where 1password's security key helps because you need that for decryption. Apps will store it so you really only need it once when setting up a new phone/computer and you can transfer it from another via qr code, but if all you have is a vault dump, you're out of luck even if you phish the password (which should be easier than phishing the security key since it's used a lot and in muscle memory)

Re: Cracking encrypted LastPass vaults

#80

> I downloaded the popular rockyou.txt wordlist and put my actual vault master plaintext password inside (using a quarter of the wordlist), otherwise it would take 6 hours+ to crack. I don't believe the 6 hours+ claim. (Or rather, the "+" is doing some serious lifting in that sentence.) Looking at the password, it's of the correct-horse-battery-staple variety, which could be conservatively estimated at 44 bits of ent…

Your quote includes the most significant part of the article "and put my actual vault master plaintext password inside".

He took a word list which did not include his password and put his actual password in the word list. He didn't crack his password, he showed that a brute force password guesser can find passwords that are in its word list. If he wanted to save six hours, he could have put it first in the password list. No news here.

Post reply on HN