12 ms·
LastPass requesting password reset after facing unknown anomaly
- twodayslate 15y agoI am perfectly fine with them being paranoid. They should be. They are being paranoid for me. They are doing a good job protecting the user.
- frio 15y agoI completely agree, but I'm not particularly happy about the apparent lack of detail in their logs/IDS system.
- jonursenbach 15y agoNot happy that I'm finding this out via a blog post and not an email.
- sathyabhat 15y agoI found this out when trying to login to LastPass, was redirected to "re-enable your LastPass account" page https://lastpass.com/activate.php https://lastpass.com/activate.php
- 3dFlatLander 15y agoI just tried logging out and back in a few times, nothing. Very weird.
- willwagner 15y agoSame here. I changed my master password but I was never prompted to do so.
- Jencha 15y ago"Joe Siegrist said... @SEV We're only forcing the issue right now you when we see you come from an IP you haven't used in the past few weeks (if you disable logging logins this might mean immediately)." http://blog.lastpass.com/2011/05/lastpass-security-notification.html?showComment=1304568208559#c6006851993433158567 http://blog.lastpass.com/2011/05/lastpass-security-notificat...
- mbreese 15y agoI'm curious about why they have an Asterix server on the same network as their database... is there a voice authentication feature, or are we just talking about their office phones? Either way, they seem to be taking this seriously, even if they are just being overly paranoid, I find it comforting.
- maguay 15y agoSuddenly, I'm glad I switched to 1Password.
- RyanKearney 15y agoYeah 1Password is pretty awful when you consider the amount of features you get with LastPass like multi-factor authentication. 1Password relies on Dropbox. Your passwords are all stored on your computer. Granted they're in an encrypted format, but if you have a jerk for a room mate they could copy your encrypted files, key log your vault password, and have access to all your passwords. On the other hand, if you get my LastPass password you better have my grid too (I keep it online so I can access it wherever, password protected). Additionally LastPass is working on SMS codes for login.
- tomjen3 15y agoThat's not very smart considering that a lot of people won't be able to lockin to their email to verify their emails because they don't have access to the login details of their email because they haven't verified it. And why the hell didn't they use scrybt in the first place? For a company so paranoid, that seems to border on neglect.
- incongruity 15y agoAnd that, right there, highlights why all of my passwords aren't kept with their (or any) service - for many, it just introduced a single point of failure. Imagine being locked out of every website you have an account on, just like that. Nope. I'll make strong passwords on my own and encrypt my own copies, thanks.
- VMG 15y agojust separately save your email password, all other services restore the password via email
- bruceboughton 15y agoMaking your email password the weakest link...
- crocowhile 15y agoMy gmail account is actually more secure than lastpass since I have OTP enabled with two factors identification.
- rakkhi 15y agoWell done, hopefully more will do following this type of incident. You can also use Yubikey to add two factor authentication to your Lastpass account if you want keep using LP
- latortuga 15y ago
- kjetil 15y agoNice to see a company so transparent about situations which could easily have been hushed down.
- nikcub 15y agoI didn't think it was transparent at all. More like the minimum corpspeak required to inform their users that they should change their passwords Transparent would have been describing exactly what they saw
- pilif 15y agoThe blog post said that they detected traffic patterns in their network that they couldn't account for. They also said that they checked logs and checksums and found no intrusion yet. So the post basically means: "we have no idea what's going on/went on, but here we are, informing you early. Here's the steps we have taken and here's the steps we are going to take" You can't have everything: On one hand, everyone wants to be notified early (see playstation network breach), on the other hand, people want to know everything when they get the information. I think that's asking a bit much. Either we get informed early ("we've seen something strange, but we have no idea what's going on") or you want all information ("we've discovered and researched a breach. here is what's happened", followed by a story that spans two weeks). As lastpass contains potentially sensitive data, I'm happy they chose to inform early, even before they had a complete picture. (disclaimer: I'm not using LastPass nor any other password manager as the risk of losing access to that and to all the services I used them with is too high for me)
- urbanjunkie 15y agoWhat kind of additional information are you looking for that would be useful to you? Would be good to understand precisely what you're after. Can you point out some examples of "corpspeak" in their notification?
- jessedhillon 15y agoNo, you're totally right. This sounds exactly like the release we got from Sony a few weeks ago, detailing the points of entry, the volumes of data released from their servers, and estimates about who is and isn't affected. And who can forget when Sony told us all exactly what steps they were taking to make sure this wouldn't happen again? /dumb
- alanh 15y agoResult of me trying to log in to delete my account, just in case (having switched to 1Password): http://cl.ly/3T0B2W09262N3k2j2U3k http://cl.ly/3T0B2W09262N3k2j2U3k
- pstack 15y agoInteresting, it isn't prompting me to do any such thing. Anyway, since many are mentioning 1Password - I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows. Also, since I use two-factor authentication, I wonder if that's the reason they have not asked me to change my password?
- mike-cardwell 15y agoIn the comments it states: "We're only forcing the issue right now you when we see you come from an IP you haven't used in the past few weeks (if you disable logging logins this might mean immediately)." It hit me straight away even though I'm using a static IP, because I disabled the logging of logins after this happened: https://grepular.com/LastPass_Vulnerability_Exposes_Account_Details https://grepular.com/LastPass_Vulnerability_Exposes_Account_...
- pstack 15y agoThanks. I had seen someone else asking in the comments on that page about two form authentication with regard to this, but hadn't seen any further comments about who this may or may not affect at the time I read it. Of course, I went ahead and changed it anyway, since it was getting to be about time.
- brown9-2 15y agoI used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows. I find that Keepass, with the database saved on my Dropbox folder, works well. No browser integration needed - Keepass registers an OS hotkey (at least on Windows) for ctrl+shift+A which will autotype ${USER}TAB${PASS} in the currently focused field, using the title of the browser window as the entry to look for in the pw database. Great for a free solution.
- crocowhile 15y agoDoes anyone know if there is a way to encrypt my lastpass db using both a password and an RSA private key?
- kmfrk 15y agoLet this be a reminder to LastPass to include a password expiration date by default.
- beaumartinez 15y ago...So you then have to replace a safe, well-thought-out password for a less safe one?
- kitcar 15y agoWow, Lastpass won't let me login to my account now, and doesn't throw any error message whatsoever. When I try to change my password it says I can't because I don't have their browser plugin. Wacky, this is quite frustrating
- ukdm 15y agoSomeone brought up the same issue in the comments on that post. Here's the solution given, two options: 1) Login in 'offline mode' then reconnect your cable/wireless connection and go to gmail... This is the preferred method. 2) Download Pocket, and have it find your local offline copy from the drop down of files and login there.
- mike-cardwell 15y agoPeople using two factor authentication, eg with a Yubikey, can not log in, in offline mode. Some people will also have turned this feature off. No idea what Pocket is.
- dkl 15y agoWhat if there are no files in the drop down? Where are the files located?
- mike-cardwell 15y agoThat's the final straw for me. Just exported my login details, emptied out my lastpass vault and uninstalled the addon. Will stick to storing my login details in a Dropbox distributed GnuPG protected flat file. Less convenient, but at least I'm not reliant on a third party.
- y0ghur7_xxx 15y agoYou still rely on Dropbox.
- eitland 15y agoAs for not getting his passwords compromised: no, not more than a vpn user relies on internet to keep his data secret. As for getting access to his data anytime: Yes, except if he has a backup.
- mike-cardwell 15y agoI don't understand why you think I wont be able to access my data anytime? Dropbox synchronises the files so you have a local copy on each of your Dropbox hosts. So if Dropbox is offline, or you get disconnected from the Internet, you can still access them... Worse case scenario is something causes the file to get deleted and that propagates to all of the other hosts and deletes their local copies. But yes, I have backups so that isn't a problem.
- mike-cardwell 15y agoIn what way do I rely on Dropbox for securing or accessing my login details? My passwords are encrypted and accessible at all times, even if Dropbox is down or I lack Internet access...
- derobert 15y agoSo is LastPass, you just click the 'log in locally' checkbox.
- dfischer 15y agoSo I just started using 1password and was thinking of lastpass. I'm still trying to figure out which is better. Anyone have any comments?
- 16s 15y agoI would say use SHA1_Pass and never store, synchronize or forget a password again. I'm biased though, I wrote it and use it daily. It's entirely free, cross-platform (GPL licensed) and you can get the source code from github. Edit: Also, SHA1_Pass does not rely on websites or anything remote from your device to operate. It just requires you (the user) and your brain ;) That's the biggest reason I wrote it.
- mc32 15y agoI use Passpack. Uses a password and a packing key -you have the option to use a yubikey as well. You can read up http://www.passpack.com/en/faq/ http://www.passpack.com/en/faq/
- andrewcooke 15y agoi'm surprised by the reactions here. maybe i am misunderstanding the blog post, or maybe others are? as far as i can see they are being extremely paranoid. they seem to be monitoring (and following up on!) traffic flow, which is itself pretty impressive, are flagging this even though they have no other error signs, and have done a good enough job in their implementation that can say, without any more details, that the only risk is via brute force cracking. i use keepassx locally, but my take on this is that they are way better than average. this kind of report would make me use a company, not switch from them.
- jojo1 15y agoIMHO everyone who is using such a service is a moron.
- latortuga 15y agoThis is an irresponsible position to take and akin to telling people to "make stronger passwords." It simply isn't realistic. LastPass allows creation of randomly generated passwords very easily and encrypts and stores them so you can use them anywhere. The alternative for most normal users is to create one or two passwords and use them everywhere, compromising the security of all of their accounts. Obviously your response to this would be that they shouldn't do that but the fact is, without something like LastPass, they have little other choice. This freakout reminds me of the radiation poison bullshit from a few months back. Bananas have radiation therefore bananas are dangerous. Practicality dictates that you are plain wrong.