7 ms·
So this blog seems to completely ignores LastPass statement from 2021-12-28: > Our investigation has since found that some of these security alerts, which were
by syvanen 5y ago
So this blog seems to completely ignores LastPass statement from 2021-12-28:
> Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. As a result, we have adjusted our security alert systems and this issue has since been resolved.
Source: https://blog.lastpass.com/2021/12/unusual-attempted-login-activity-how-lastpass-protects-you/ https://blog.lastpass.com/2021/12/unusual-attempted-login-ac...
Source2: https://twitter.com/troyhunt/status/1476296988001849345?s=21 https://twitter.com/troyhunt/status/1476296988001849345?s=21
- ohyeshedid 5y agoI'm curious how that balances with everyone sharing random IP's from attempted account access. Where did those addresses come from? Why are users seeing them? Did the bug they're talking about cause bad data to be pushed to users dashboards?
- tuwtuwtuwtuw 5y agoSeveral people have reported that if you tried to log on from a new IP with incorrect master password, then you got an email saying that someone tried to log on using your master password even though that was not the case.
- ohyeshedid 5y agoI was referring to the IP's being shown to users.[1] So then; Is the bug also responsible for pushing bad data to the users dashboards? If this is really a bug, it's a complicated one. I'd be curious if those IP's are still being shown on the users end. [1]: https://news.ycombinator.com/item?id=29705957 https://news.ycombinator.com/item?id=29705957
- tuwtuwtuwtuw 5y agoWhat "dashboards" are you referring to? I have not seen any dashboards in LastPass. Why would it need to be a complicated bug? It could be as simple as: If UnkownIP OR InvalidMasterPassword Then LogAndSendNotication Instead of: If UnkownIP AND InvalidMasterPassword Then LogAndSendNotication Please tell me why it needs to be a complicated bug.
- ohyeshedid 5y agoI don't have a link handy, nor currently familiar with LP's site or extensions: The part of the site that shows the recent connections to your account, with IP's. People were sharing those IP's and thoughts in the linked thread. That data came from somewhere; if it's related to this bug then this bug is also pushing incorrect data into other parts of the service. It's also entirely possible that it wasn't a bug, and instead a security issue, and that data is correct, and they're bending words to play it off as just a bug. I can understand a bug triggering a warning system, but when it's also presenting related data in the account security logs; it's either a complicated bug or there's more to the story.
- tuwtuwtuwtuw 5y ago> it's either a complicated bug or there's more to the story. I showed you pseudo-code which could trigger this issue. It was trivial code which could cause it in practice. Yet you claim it must be complicated or more to the story. I have no idea why you feel that classifying a request in a certain way must be caused by a complicated bug - very strange. I think you're into FUD-mode now because even after being shown wrong, you continue to spread misinformation. Also, you are referring to LP functionality which to my knowledge doesn't even exist, and when asked you say you don't know the software being discussed. Very strange behavior by you.
- ohyeshedid 5y agoYour example would've caused a much larger response, no? By most accounts, it didn't trigger for most users, so a simple flub like that should've triggered on more accounts. I'm viewing this through the lens of multiple days of differing social groups poking at this, and the crowdsourced information that's yielded. > ...shown wrong, you continue to spread misinformation. You haven't shown anything wrong: neither of us know what actually happened. nor am I spreading misinformation, nor making statements as to what happened; I'm questioning it. Is there some reason you're so accusatory? > Also, you are referring to LP functionality which to my knowledge doesn't even exist, and when asked you say you don't know the software being discussed. [1]. I haven't touched LP in, ehhh, 10ish years, and it was a feature even back then. [1]: https://support.logmeininc.com/lastpass/help/lastpass-account-history-lp010014 https://support.logmeininc.com/lastpass/help/lastpass-accoun...
- palant 5y agoI haven’t seen it when I wrote the article. However, the formulation is vague enough that it could mean anything. Maybe the alerts were sent out by mistake which would be good news. But they don’t quite say that. Their statement might also mean that they rather disabled legitimate alerts so that people don’t get concerned. So they might have “cured” the symptoms without addressing the actual issue. It certainly isn’t reassuring that they keep talking about credential stuffing, even though it’s quite unlikely to be the culprit here.
- tuwtuwtuwtuw 5y agoWhat's the difference between "triggered in error" and "sent out by mistake" then? In this context they seem like the same..
- palant 5y agoThe difference is the word “likely” which means as much as “we have no idea.”
- deleted 5y ago[deleted]
- softwarebeware 5y agoWell...the word "likely" is a weasel word and not very comforting.
- Ansil849 5y agoLastPass's statement is extremely vague. _Why_ were these alerts triggered in error? What error triggered them?
- tuwtuwtuwtuw 5y agoThe lack of that specific information doesn't make it vague in my view. If I tell to that the world appears to be shaped as a globe then that statement isn't vague just because I don't explain _why_ it appears shaped as a globe.
- aflag 5y agoIt's vague because we don't know why you consider it to appear to be a globe. Did you fly in a rocket and saw it or do you just think that round is the perfect shape and God wouldn't create the world in any other way?
- tuwtuwtuwtuw 5y agoThat's not what the word vague mean though. If you make up your own definitions of words then it's not worth discussing with you.
- Ansil849 5y agoThis isn't some abstract argument about your view of the world. This is a blogpost about a potentially very serious system fault. Customers want to know what the root cause of the fault was, so that they can evaluate whether to continue to do business with the company or not. It's very cut and dry.
- _aavaa_ 5y agoThat statement is too squirrelly for me to trust if my passwords were stored with them. “SOME of these security alerts” “were LIKELY triggered” “HAS BEEN solved” (Emphasis mine) How can the issue be definitely solved if you aren’t sure that they were actually triggered in error, if they were in error then it’s only some of them.
- deleted 5y ago[deleted]
- cortesoft 5y agoThat is the wording they have to use, right? They can't be certain that ALL the people who have seen these emails are caused by the buggy email notification code... I am sure some legitimate notifications were also sent out during the time, so how would they know if any of those were caused by something else?
- dwattttt 5y agoIt's not the wording they could use if they were sure that at least one alert was sent in error; then they wouldn't say it was likely, they'd say they know there were erroneous alerts. As it is, they're just speculating the alerts were wrong, which bodes very poorly.
- singlow 5y agoI think they are sure they triggered some of the errors. However they may not be able to identify which ones were caused by their bug and which ones were legitimate attacks, which probably happen at some rate each day. If you are a customer, and you received this message, you should definitely change your master password and probably rotate your stored passwords. You don't know if your email was real or not. However, it explains why so many users were getting this message recently in a plausible way, that is not too hand-wavy except for their dodgy track record. Its not the level of transparency I would expect from Mozilla or even Reddit, but its par for the course. You should probably migrate to another password store. I moved away a while ago for other trust reasons, but this particular incident on its own is not that concerning to me.
- willis936 5y agoWhich is exactly what you say when facing an existential crisis. If you have a master password leak you either: 1. lie about it and the truth never comes to light 2. lie about it and get caught and the consequences are the same as if you came clean If LP suffered a master password leak then there is no benefit to telling the truth.
- imwillofficial 5y agoExcept earning trust with the customer, in a line of business that is built entirely on the customer trusting you to manage things properly.
- mgraczyk 5y agoOne advantage of telling the truth is that you don't go to prison for fraud. When evaluating this kind of conspiracy theory, it's important to consider the number of people who would have to remain silent for the conspiracy to survive, and to consider how much it would cost to keep that many people silent. In this case, it's at least a few dozen so I think it's fair to assume that such a lie would not survive very long.
- imwillofficial 5y agoThis is broken thinking built on faulty assumptions. There are countless examples of massive conspiracies and secrets never leaking.
- dreae 5y agoThen how do we have the examples?
- imwillofficial 5y agoI’m not sure I understand your question. Can you state it in a different way?
- nmca 5y ago
- abarringer 5y ago"likely" "some", weasel words. Corporate marketing speak for we have no idea what happened so dream up some scenario that sounds plausible and do a press release.
- dehrmann 5y agoSome of the emails were probably real, and they just happened to have been when there was supposedly a issue. That can't part be definitive.