13 ms·
How did LastPass master passwords get compromised?
- mizzao 5y agoI've found LastPass to be increasingly buggy and less reliable as time goes on. Do they have security problems as well? Should I switch to a different service as a paying customer (for me and my family?) If so, any recommendations?
- palant 5y agoI’ve written about their security story a while ago here, not much has changed since AFAIK: https://security.stackexchange.com/questions/45170/how-safe-are-password-managers-like-lastpass/137307#137307 https://security.stackexchange.com/questions/45170/how-safe-... The trouble is that the majority of their competitors isn’t great either. I used to recommend 1Password, but another knowledgeable security researcher isn’t really fond of them.
- mattwad 5y agoBeen using Bitwarden and it works great, at least for personal use. And Authy for 2-factor
- lycalopex 5y agoJust curious if you had any information on the security concerns of 1Password from that researcher?
- palant 5y agoIt’s rarely actual security concerns, mostly how they deal with security issues when they are reported to them. I’ve never had to deal with 1Password in this way, the code I’ve seen was pretty solid. This researcher made some rather bad experiences however.
- goldcd 5y agoI'm suddenly very grateful for Lastpass wanting to charge me, and me leaving
- joenathanone 5y agoI moved when they raise their prices, I just wish I had deleted may account....
- dang 5y agoOngoing related thread: Unusual login activity was due to bug - https://news.ycombinator.com/item?id=29737973 https://news.ycombinator.com/item?id=29737973 Recent and related: LastPass Login Attempted Activity Blocked – More Information - https://news.ycombinator.com/item?id=29731317 https://news.ycombinator.com/item?id=29731317 - Dec 2021 (12 comments) LastPass says no passwords were compromised following breach scare - https://news.ycombinator.com/item?id=29723319 https://news.ycombinator.com/item?id=29723319 - Dec 2021 (68 comments) LastPass users warned their master passwords are compromised - https://news.ycombinator.com/item?id=29716715 https://news.ycombinator.com/item?id=29716715 - Dec 2021 (313 comments) Ask HN: How did my LastPass master password get leaked? - https://news.ycombinator.com/item?id=29705957 https://news.ycombinator.com/item?id=29705957 - Dec 2021 (508 comments)
- Dedime 5y agoThis whole LastPass kerfuffle has solidified my choice to continue using FOSS + self hosted password managers only. If my passwords get stolen, I'd rather be responsible for the loss than wait for a company to put out a squirrely statement.
- yonixw 5y agoI was self-hosted enthusiast myself, until I found out that self-updating is not fun, not always compatible and thus not secure*. And therefore, I take the hard pill of SaaS even if security wise, it is hard to swallow. *Not secure: It will always catch you off guard, and will require a lot of work, so you will postpone it which is, not secure.
- t0astbread 5y agoWhat about an offline password manager? Like pass[1] or one that supports the KeePass format. Then you could use your regular file synchronization tool to synchronize the database files. You could also use a P2P sync tool like Syncthing. (Of course this makes more sense if you already have some kind of file sync setup.) [1] https://www.passwordstore.org/ https://www.passwordstore.org/
- jimmydorry 5y agoThat would be roughly equivalent to lastpass then.
- t0astbread 5y agoHow so? The password database is still encrypted with a master password which is completely independent of the file sync mechanism. So the master password is not involved in anything network-facing.
- jimmydorry 5y agoLastpass simply downloads your password database as an encrypted blob which you unlock locally with your master password. The fact that this unlocking is somewhat automated does not change the fact that it acts identically to your proposed solution.
- jumperabg 5y agoWere there any breached sub-accounts/credentials?
- bth 5y agoI've received the email about login attempt from replies@m.lastpass.com even though I've removed my account 24h before that. When I try to login, I'm getting an error that my account doesn't exist. Maybe this is a phishing attack after all.
- ptmvp 5y agoSame thing happened to me. I contacted support and they confirmed my account had been deleted, but I'm still uneasy..
- helloworld11 5y agoI never trusted or used LastPass and others of this type for this very reason. Powerful passwords created by a single central expert source? Sounds great, very secure, except for the little tiny detail of that source being broken wide open despite its claims of excellent security. It's impressive how many supposedly tech-oriented people on this very site and its comments I've frequently seen recommending such an obviously insecure way of keeping you private stuff protected. This not to mention the possibility of collusion with certain alphabet agencies. It's like data management in general: If you don't uniquely, personally control it, you don't really control it.
- jeremyjh 5y agoFor the majority of people it is still better than the only alternative they would actually use: using the same password in a lot of different websites. This way there is only one company that can completely compromise you, instead of dozens.
- ritmatter 5y agoUsing 2FA with LastPass (Google Authenticator) makes me feel a lot better about the security. Even if my password were compromised, it would still be hard for an attacker to get access to my LastPass account. Note that 2FA with SMS is much less safe than a code generator app, since it is much easier for someone to get access to your phone number than to get access to the code generator.
- askvictor 5y agoWhile trying to delete my lastpass account (which repeatedly comes up with an error, though may have actually deleted it, but now I'm no longer sure and can't verify), I've just discovered that, when trying to log in to Lastpass, it tells you if you have the username incorrect, not "either username or password" is incorrect; I thought standard security practice of the last decade was the latter :-/
- chikfilley 5y agoHaving intimate knowledge of this event, they are not being honest.
- gregsadetsky 5y agoCan you tell more?
- chikfilley 5y agoThe actual security event and the email bug are two separate problems they are combining to obscure one with the other. Accounts were compromised by credential stuffing and password reuse, a bug did break some of the security controls that would normally protect accounts when a specially crafted request was sent to authentication services (allowing some of the stuffing to occur). Weak securoty controls design allowed attacks to continue in other scenarioa. What probably stopped this from being a bigger story the MONTHS ago that it took place was the fact so many lastpass accounts are abondoned accounts that don’t get run through a garbage process, or primary email account was also compromised, or users with weak passwords that are low tech IQ and not aware of the activity in their account or unsure how to handle it. Check Twitter, it started with a user complaining about account takeover and losing their coin wallet (and thousands of dollars) (stored password in LP). There were thousands of accounts compromised this way.
- gregsadetsky 5y agoCan you talk more about the specially crafted request? Were those requests the ones that triggered the emails that many of us received, and were those requests made with the correct or incorrect passwords? Do you have an explanation why some people changed their LP passwords, and then received another login attempt alert email after that? Is that a coincidence (i.e. it was just more incorrect credentials still being tried on the same accounts) or was the attacker aware of the password change? Did the attacker have access to the new password or not? Many of us received the alert email that our passwords had been used (i.e. an attempted login with the correct password from a new IP), but swear that those were unique passwords (in my case, it was computer generated, locally stored in KeePass and never re-used -- many other cases like that). Did the attackers have our passwords in their possession, or no?
- palant 5y agoI am the author of this article. I’ve kept it short, some points made there could have been expanded considerably. So if there are questions, feel free to ask here.
- buck4roo 5y agoI haven't seen any mentions discussing HTTP request smuggling try. This could cause LP's internal or external load balancers to misdirect requests/responses. Thoughts on this as a possible root cause?
- palant 5y agoI’ve given this some thought, but I think that this scenario still requires someone to attempt a login with correct credentials. It cannot be the legitimate owner however if the account hasn’t been touched for a year.
- overlordalex 5y agoWhat is your opinion of the analysis from LastPass themselves?[0] It seems to have been some internal alerting that went wrong, which does happen from time to time. > Our initial findings led us to believe that these alerts were triggered in response to attempted “credential stuffing” activity [...] We quickly worked to investigate this activity and, at this time, have no indication that any LastPass accounts were compromised by an unauthorized third-party as a result of these credential stuffing attempts, nor have we found any indication that user’s LastPass credentials were harvested by malware, rogue browser extensions, or phishing campaigns. > Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. [0] https://blog.lastpass.com/2021/12/unusual-attempted-login-activity-how-lastpass-protects-you/ https://blog.lastpass.com/2021/12/unusual-attempted-login-ac...
- WarOnPrivacy 5y ago>Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. As a result, we have adjusted our security alert systems and this issue has since been resolved. This added bit hints that these emails were erroneously sent in response to the wrong password being attempted against the master account (which normally doesn't rate an email). It isn't fully spelled out tho. LP spends most of the blogpost going on about bad user practices - which feels a lot like gaslighting in this context. edit: I'm leaning toward accepting LP's incomplete, forced explanation and that hackery isn't in play here.
- jmull 5y ago> "First of all, malware provides a level of access that makes hacking LastPass accounts unnecessary. If it can intercept or extract the LastPass master password, it can do the same for all other passwords as well." That logic doesn't really make sense. Malware might make hacking LastPass accounts unnecessary, but it would still be highly desirable (one target gives you everything else). Frankly, it feels like OP decided on the conclusion before any analysis was done.
- ViViDboarder 5y agoThe additional justification there seems to ring true to me at least. If you had machine access, why not download the database from the “trusted” (compromised) machine? Why not extract the plain text passwords when they unlock their vault? How would it impact users who hadn’t logged into their accounts in years? Malware doesn’t seem to fit to me.
- jmull 5y agoConsider if you have key logger logs you’d like to profit from. What do you look for? Login credentials is a good idea… which login credentials should you target? Password manager credentials seem like a good idea, since that gives you full login details for anything else else you might want.
- gruez 5y agoBut if that were true you'd expect a bunch of other account compromises?
- smorgusofborg 5y agoIf it is a group accumulating passwords via extensions it would make a lot of sense to me if they planned to sell them like credit card data on bulletin boards. I don't think individual financial accounts would sell that well without really knowing if you have the necessary associated email accounts, etc to delay detection of a fraud. I also don't think such groups are necessarily sophisticated enough not to have someone slip up at stage 2 of their plan, give away a few accounts to boast, etc, etc.
- SloopJon 5y agoThe article suggests that hashing (PBKDF2) is done client-side only, and that LastPass stores this hash directly. If true, this is very bad. However, LastPass claims that PBKDF2 is also used server side: > We then take that value, and use a salt (a random string per user) and do another 100,000 rounds of hashing, and compare that to what is in our database. https://blog.lastpass.com/2015/06/lastpass-security-notice/ https://blog.lastpass.com/2015/06/lastpass-security-notice/ While it's true that the client-side hashing means that LastPass never sees your plaintext password, the first hash effectively becomes the password. Then it's on LastPass to treat it as such, which they claim to do by hashing it again. Edit: another link describing the use of PBKDF2: https://support.logmeininc.com/lastpass/help/about-password-iterations-lp030027 https://support.logmeininc.com/lastpass/help/about-password-...
- 42jd 5y agoWhen I was doing some research into building an app that encrypted data similar to these cloud password managers, I encountered OPAQUE[1] which seems to be the ideal way to perform authentication and securing a master encryption key. It is an asymmetric PAKE that also has a step for providing a salt. This removes the need to do what LastPass does with treating the first hash as a password. There is a great article from Cloudflare on how it works[2], and a working implementation of the spec in rust[3]. [1]: https://github.com/cfrg/draft-irtf-cfrg-opaque https://github.com/cfrg/draft-irtf-cfrg-opaque [2]: https://blog.cloudflare.com/opaque-oblivious-passwords/ https://blog.cloudflare.com/opaque-oblivious-passwords/ [3]: https://github.com/novifinancial/opaque-ke https://github.com/novifinancial/opaque-ke
- 8organicbits 5y agoI wish there was a good way to implement this sort of double hashing in web apps. Doing the extra salted hash client side ensures that the value the server sees is globally unique, even when the user is reusing passwords across sites. Unfortunately the only way I know how to implement that is to have the server send JS down to the browser that instructs it to perform the hashing. For certain types of compromises server side, the attacker would just modify the JS to get the unhashed password. I'd also need to fall back to pure JS hashing for old browsers (5% users?), so there's a UX concern if I perform lots of rounds. I kind of wish there was a different password HTML field that could run the client side hashing without JS, so the browser would manage that. Ideally using different UX so the user understands they are using a "safe" password field. The end result would be to deny access to the raw password, which is likely reused on multiple sites.
- deleted 5y ago[deleted]
- wubbert 5y agoThis is exactly why I have never used LastPass, and have always stuck with KeePass (and KeePassXC). It is much more secure to keep all of my passwords locally than in the cloud.
- afiori 5y agoThe main feature that cloud solutions provide is the ability to share passwords to specific teams and users within an organization.
- ryanjkirk 5y agoPassBolt comes to mind.
- AnIdiotOnTheNet 5y agoEven then there are locally hosted solutions like VaultWarden.
- SavantIdiot 5y agoThis argument has never made sense to me. Keeping an encrypted password file in the cloud or locally makes no difference. There exists no computer system than can crack an AES256 encrypted document. The weaknesses are in the protocol. Storing the encrypted database in the cloud and downloading it is the same as storing it locally if the decryption protocol is performed locally. If the decryption was done in the cloud I would agree with you, but that is not the case, so the two are the equivalent.
- Sebb767 5y ago> Storing the encrypted database in the cloud and downloading it is the same as storing it locally if the decryption protocol is performed locally. The problem is that, with web-based password managers, you are not only downloading the database, but also the code to decrypt it. A locally installed Keypass requires your PC to be compromised, whereas for LastPass it is sufficient for their servers to be compromised (while not avoiding the problem if you are compromised, either).
- syvanen 5y agoSo this blog seems to completely ignores LastPass statement from 2021-12-28: > Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. As a result, we have adjusted our security alert systems and this issue has since been resolved. Source: https://blog.lastpass.com/2021/12/unusual-attempted-login-activity-how-lastpass-protects-you/ https://blog.lastpass.com/2021/12/unusual-attempted-login-ac... Source2: https://twitter.com/troyhunt/status/1476296988001849345?s=21 https://twitter.com/troyhunt/status/1476296988001849345?s=21
- ohyeshedid 5y agoI'm curious how that balances with everyone sharing random IP's from attempted account access. Where did those addresses come from? Why are users seeing them? Did the bug they're talking about cause bad data to be pushed to users dashboards?
- tuwtuwtuwtuw 5y agoSeveral people have reported that if you tried to log on from a new IP with incorrect master password, then you got an email saying that someone tried to log on using your master password even though that was not the case.
- ohyeshedid 5y agoI was referring to the IP's being shown to users.[1] So then; Is the bug also responsible for pushing bad data to the users dashboards? If this is really a bug, it's a complicated one. I'd be curious if those IP's are still being shown on the users end. [1]: https://news.ycombinator.com/item?id=29705957 https://news.ycombinator.com/item?id=29705957
- tuwtuwtuwtuw 5y agoWhat "dashboards" are you referring to? I have not seen any dashboards in LastPass. Why would it need to be a complicated bug? It could be as simple as: If UnkownIP OR InvalidMasterPassword Then LogAndSendNotication Instead of: If UnkownIP AND InvalidMasterPassword Then LogAndSendNotication Please tell me why it needs to be a complicated bug.
- skarz 5y agoPasswords were NOT compromised. It is hackers using existing compromised email/password combinations on brute force attempts at Lastpass. That is why your Lastpass password should be a password that you have not nor will ever use on any other site.
- roozbeh18 5y agoOP blog suggests users receiving similar email even after changing their master password. two possibilities for LP. either their servers were hacked and hashed master passwords were dumped somewhere or as LP said, system error due to a bug.
- jerf 5y agoI'm not sure we can concretely say there was no compromise. However, at the moment I'm not satisfied that a compromise has been demonstrated, either. As near as I can tell, nobody has reported a compromise, just suspicious emails. That's not enough evidence to prove a compromise. LastPass' response, so far, adequately covers what we've actually seen.
- latortuga 5y agoPlenty of folks who reported getting this email from LP, including myself, reported that they used a strong unique passphrase for LP only.
- tuwtuwtuwtuw 5y agoLastPass wrote that there was a bug causing these emails to be sent. That may be correct, because several persons have reported reproducing that issue before the LastPass fix - they have written that they logged on with incorrect password while using an IP from another country and still got the email that their master password was used.
- latortuga 5y agoVery interesting and would set my mind a bit more at ease.
- sunshinekitty 5y agoI stopped using lastpass a couple years ago now due to ill-communicated master password leaks, ever-rising fees, and buggy UX. This seems par for the course, I can’t imagine any credible company or keen user actually using lastpass at this point.
- herodotus 5y agoUpdate: https://blog.lastpass.com/2021/12/unusual-attempted-login-activity-how-lastpass-protects-you/ https://blog.lastpass.com/2021/12/unusual-attempted-login-ac...
- NickBusey 5y agoJust one of the many reasons I self host my password manager. Bitwarden hosted via HomelabOS.
- 40four 5y agoWhat are the chances these emails were actually sent out in error, like Lastpass claims? It’s not in-plausible, but I also take it with a grain of salt. To be fair to them, I don’t think we’ve seen any reports of folks password DBs actually being compromised. Just a lot of presumed failed attempts. If the e-mails were sent in error, then it’s all much to do about nothing. If the master passwords were actually compromised, then the system still successfully protected the clients password assets.
- unicornfinder 5y agoSums up my feelings really. I genuinely think that what they're saying is probably true, that these emails were sent in error (and I have to say I don't envy their teams at all in having to deal with the fallout from this), but it's also entirely understandable that many people will have been justifiably spooked to the point where they probably won't continue to use their services now.
- joenathanone 5y agoFor whatever it is worth, the same day people started getting the emails someone attempted to login to both my outlook.com account and Steam account using the correct passwords and I got a 2FA alert, that has never happened before and then the next day I also got an alert from Lastpass. Could be some crazy coincidence but what Lastpass is saying isn't adding up.
- SavantIdiot 5y agoI use a YubiKey with LastPass. But it seems that still wouldn't help with "pass the hash", correct?
- rexreed 5y agoOut of curiosity the meaning of "credential stuffing" doesn't jibe with what I would assume the term would mean. Why isn't the more obvious "password reuse" term not preferred? I would assume credential stuffing would mean something to do with pushing a bunch of credentials into a system and overloading the credential system somehow, rather than simply being "reusing a password that was found on a third party site".
- yellowstuff 5y ago"Credential theft occurs when attackers breach a system and steal users' access credentials -- usually ID and password. The ID is most commonly the user's email address. Credential spilling is when those credentials are made available to other criminals. Credential stuffing is the large scale use of automated means to test stolen passwords against other unrelated websites." https://www.securityweek.com/credential-stuffing-successful-and-growing-attack-methodology https://www.securityweek.com/credential-stuffing-successful-... The term "credential stuffing" is a bit counterintuitive for me as well, but I guess it fits the pattern of credential attacks. "Password reuse" has other meanings, so would be less precise as a technical term.
- rexreed 5y agoThe use of obscure and unintuitive terms would seem to hurt the objectives of security proponents to explain how systems have been compromised. If you tell me my credentials were "stuffed", I'm going to assume it was some technically sophisticated attack using some exploit or system vulnerability. If you tell me my password was simply stolen and posted on a website, and they're just brute force trying the password on all the systems, I'm going to know that my password has been compromised and some cybercriminals are out there using bots to try them everywhere. In the first, case, I'd feel less empowered to do something about it. In the second case I'd be more aware of all the databases with old passwords in it and never reuse a password twice. (if that's what's happening).
- jcrawfordor 5y agoI agree that the security industry has a problem with inventing new terms when they don't contribute to understanding. I do think there is some nuance here though to "credential stuffing" vs "password reuse" - credential stuffing is a description of the exploit while password reuse is the vulnerability. In other words, password reuse is a user behavior that doesn't directly cause unauthorized access. "Credential stuffing" is described from the perspective of the service provider, which sees an attacker "stuffing" many thousands (often hundreds of thousands over time) of credentials into their product to see if any of them work. Of course only a tiny fraction do, but that's enough to create a big problem. It's usually not clear where the stuffed credentials came from, it may be a check to see if compromised passwords from other websites were reused, but more often credential stuffers just try a "top 100" password list against every user they can enumerate---so password reuse per se or a compromised credential list may not even be involved, just use of common passwords. Researchers will sometimes modify services to log password attempts in plaintext in order to try to determine where stuffed credentials are coming from, but for obvious reasons it's not advisable to do this on a "real" service, so it's usually hard to know exactly what's going on---although the set of attempted usernames can sometimes give you a good hint, for example it's not at all unusual to see credential stuffing attacks where the attacker hasn't even enumerated users and is just trying common usernames. Some of these common username lists are kind of eccentric and you can recognize which one an attacker is using by some of the odder entries on it. I've had instances where googling a particularly weird username out of authentication logs just turned up exactly the perl script the attacker was using, uploaded to some compromised webserver where Google got wind of it somehow. I assume the username list it was using was originally from some real system but had been copypastad until it no longer had any relation to the original source. A lot of common password lists are like this as well. The term "credential stuffing" should be viewed as a term of art and not used in communications to the public, but I do think it's useful because it describes a phenomenon which is different from, and may or may not involve, password reuse by users. As a semi-related but amusing anecdote, there was for a time a fairly large-scale SSH credential stuffing effort by a botnet whose operator had made a mistake and mixed up the "username" and "password" fields in their credential list. Many SSH servers saw thousands of attempts with various usernames like "letmein123" and password "root" or "admin". I suspect the actual root of the problem was that they'd concatenated credential lists, not realizing they were in different formats. They may have even gotten the credential list that way, these things get passed around in really haphazard ways.