64 ms·
Lastpass Security Incident
- cwkoss 4y agoIf you're a lastpass user, might be wise to avoid logging into lastpass until they update with a resolution - if the attackers got into the build server they could craft attacks that would exfiltrate passwords after user decrypts
- aussieguy1234 4y agoLastPass is architectured so that your master password is never sent to their servers. Decryption of your vault happens locally on your device. Maybe such an attacker might get your email address (username).
- joenathanone 4y agoWell, it should go without saying but their architecture cannot be trusted at this point.
- sciurus 4y agoUnless the attacker is able to modify the LastPass client to upload your masters password.
- waynesonfire 4y agothe architecture that was just hacked? Maybe in the next version of the update you'll find the architecture has mysteriously changed as well.
- the_svd_doctor 4y agoIs there a web UI ? If yes - I guess an attacker can just send "bad" JS to the client and steal the master password no? Or inject a malicious update. Most people probably have auto updates?
- darkhelmet 4y agoYes, this is one of the concerns. In theory a browser addon should take a while for the bad guys to update and publish, but are the existing addons downloading and using server-provided JS? One would hope not, but that's hardly a safe assumption these days. I know Mozilla takes a pretty hard stance against this sort of thing, but it's not all caught in review. And then there's the electron style apps - those should be static too, right? right?? Also not a safe assumption. And yes, there is a pure-web UI where the code is downloaded from their servers. Anyway - it's not a good position to be in.
- philsnow 4y ago> are the existing addons downloading and using server-provided JS? One would hope not, but that's hardly a safe assumption these days This reminds me of a very brief security review I did of a 3rd-party browser extension that was being installed on everybody's laptop at a previous job. The extension itself had very little code, it was just something that bootstrapped with code from the company's servers. There was no real way to review it or freeze a reviewed version. The kicker was that the server-provided JS was being loaded over plain http (and no, nothing was checking signatures or anything like that).
- aussieguy1234 4y agoI think I misread the initial comment. Yes, if the build server is compromised code could be injected into the next build/release cycle to pilfer your master password. Not only that, but also anything else in the vault since it is decrypted locally and visible to the extension. Still, local decryption is more secure than sending the master password to the server (so, just compromising the server holding your vault wouldn't be enough to steal your password). I think I will switch to BitWarden which uses the same approach, LastPass seems to be getting hacked alot nowdays.
- greyhair 4y agoAre you certain bitwarden has not? I read a thread here some time ago where 1password was bragging that they have never been breached, and someone basically commented back "they have never been breached that they are aware of". I am concerned at some level on the lastpass breaches, but I am less affected so far than I have been by the equifax, target, and t-mobile breaches. I have had years of free credit monitoring since each one of those handed out enough data to compromise my identity several times over.
- Springtime 4y agoAs a workaround one can log in offline via the browser extension to export one's database (by default at least). Edit: hadn't considered that addons also autoupdate by default when back online.
- meow_mix 4y agoWouldn't the devs know if a malicious LoC had been built into the client and distributed to take master passwords from the browser? Idk much about browser extensions, but I think they would have been able to figure out if something malicious went out to last pass clients, no?
- pcthrowaway 4y agoFuck. If you're a lastpass user, you kind of don't have a choice. I can't log into accounts I use for socializing, work, banking, etc. without lastpass
- Tijdreiziger 4y agoI just spent a couple of hours resetting my most important passwords and writing them down on paper. Won’t be touching LastPass again except offline, while I figure out where to go from here. I had been putting off finding a better password manager, but this is the last straw.
- frankhoward 4y ago
- frankhoward 4y ago
- frankhoward 4y ago
- frankhoward 4y ago
- frankhoward 4y ago
- celestialcheese 4y ago> was able to gain access to certain elements of our customers’ information This is frustratingly vague. This incident started 4 months ago, and you can't provide any details? If it wasn't such a PITA to move off LastPass, I would do so. They got me.
- deleted 4y ago[deleted]
- snailmailman 4y agoHow is it a PITA to move off lastpass? I switched to Bitwarden and it was a piece of cake. Exported all passwords. Imported all passwords. Pretty much all password managers can import/export as a CSV or similar.
- celestialcheese 4y agoIt's easy if you don't share passwords with others. I have my whole family and business using it, and there's lots of shared folders. Convincing my wife and colleagues to all switch simultaneously isn't feasible unless this data fiasco gets worse.
- neurostimulant 4y agoIt'll only going to get worse. Better move now before it's too late.
- ragingroosevelt 4y agoI tried migrating from LP to BW and got import errors. Bitwarden's error message was very vague (along the lines of "sorry, something went wrong") and I haven't been able to track down what entries were causing the issue. I've tried 3 or 4 times including trying to reproduce with subsets of the full collection but it's too much of a pain with hundreds of accounts and I so far haven't been motivated enough to manually transfer them or to write a selenium script to do it automatically.
- 4y ago
- reiichiroh 4y agoRuh Roh
- teg4n_ 4y agoLastpass has had so many security incidents I have no idea why anyone uses it anymore when the whole product is supposed to be Security.
- bnmathm 4y ago> We have determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information. Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture. Sure sounds like they found passwords or keys in the development environment breach back in August, and nobody bothered to change those after knowing they were hacked.
- EugeneOZ 4y agoThe most shocking thing for me. The real stopper for anyone who is still trying to keep their trust in LastPass.
- ocdtrekkie 4y agoPassword managers are a huge security antipattern and this will probably have to happen a couple dozen more times before infosec bloggers with affiliate marketing deals stop promoting them.
- KyleBerezin 4y agoNo one who uses unique passwords can remember them forever. It's a compromise of post-it notes vs managers. Either that or do account recovery every time you need to do your taxes (SOL for encrypted files though). I sadly write passwords down, but dream of a better option.
- ocdtrekkie 4y agoPost-It notes are a safer option than password managers. And it's absolutely outrageous to say this: But not every single account you have needs a unique password. Just ones which can actually allow someone to impersonate you meaningfully, cost you money, or gather sensitive data about you. Response to @palata because of rate-limiting: The problem is people tend not to only put unimportant accounts in their password managers. They also put their bank and email passwords in there, and to my true horror: People have started storing their TOTP tokens in their password managers, which effectively reimplements single-factor authentication!
- KyleBerezin 4y agoI do post-it notes and a couple of master passwords for things I don't care about, so I don't disagree. I need to make 2 points though. 1, enough 'non-sensitive' data can eventually become sensitive when taken as a whole, and 2 post-it notes are less secure if they are at a place of employment, think teachers. Maybe the best option is one of those physical access password managers like KeePass
- ocdtrekkie 4y agoKeePass on something normally-offline like a thumb drive is probably a decent compromise where needed, but I'd still encourage people to keep their most sensitive passwords either undocumented or partially/incorrectly documented.
- bombcar 4y agoSomeday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.
- Gigachad 4y agoSure it’ll result in a lot of issues for minor sites, but most critical services mandate 2FA. So just don’t keep your password and 2FA in these services.
- sidewndr46 4y agoI don't use them, but my conclusion is that at least one major cloud password manager has been hacked already without any disclosure. If they disclose it, the company should logically be dead. Thus, the incentive would just be to cover it up.
- amerine 4y agoCan you elaborate more? Which? Why do you think this? I also agree with you and I think it’s one that rhymes with shome paus werd. But I think it happened early in their “cloud” journey
- arjvik 4y agoAre you talking about 1Password? What makes you think that?
- yeeeloit 4y agoNo idea what they are talking about, or why they feel the need to withhold information, but a quick search turned up this interesting comment: https://www.reddit.com/r/1Password/comments/lkfg5p/what_happens_if_1password_is_hacked/h6r872w/ https://www.reddit.com/r/1Password/comments/lkfg5p/what_happ...
- alar44 4y ago
- geocrasher 4y agoGreat, now I'm going to have to rename my dog.
- LudwigNagasena 4y agoI never pick a real answer to my security questions. It just seems pointlessly dangerous.
- LegitShady 4y agothey never know that i secretly use the name of my imaginary pet from grade 1 rather than my actual first pets name.
- 4ec0755f5522 4y agoI use random strings and store them in a Passwordsafe db. Ever since the Sony PSN hack which IIRC did include secret questions and answers. (I may be mistaken, but I do know it was absolutely the last time I gave a company true information for security questions).
- mokanfar 4y agoHow do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.
- _zer0 4y agoI generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.
- bergenty 4y agoI hate password managers. They sign you out way too often and god forbid you’re on another PC.
- kome 4y agoit's so baffling to me that people give ALL their password to a third party, commercial, organization...
- blurri 4y agoCome on now. How is that baffling?
- serf 4y agoin what other tech stack is it a good idea to have all your eggs in one basket? that's why it's baffling. The convenience is outweighed by the possible loss.
- rtpg 4y agoWhat is the alternative strategy? I think for most people before password managers the strategy would be "have one egg".
- 542458 4y agoThere are lots of enterprise tech stacks where you have a single (or single-as-possible) centralized secret store… it’s far from uncommon, I.e., Hashicorp Vault, AWS Secrets Manager, Google Cloud KMS.
- noirbot 4y agoWhat percentage of the population even thinks about "tech stacks"? That's the group of people who probably already is using something else. Everyone else is still catching up to not having a password that's just "password1234" People get their credential compromised via shared passwords way more than compromises of Lastpass or Chrome or 1Password. Sure, it's a bigger risk if your manager is compromised, but for most people it's as much "eggs in one basket" as people only having one bank account which is probably true of nearly everyone.
- theonething 4y ago
- mushufasa 4y agoCan someone in the know comment here on the succinct and honest scope of breach of passwords stored by LastPass users?
- mankyd 4y agoThey're encrypted/decrypted by the user's password locally in the app or extension.
- aeyes 4y agoHow does it work for passwords which you shared with your team on their enterprise plan?
- 656565656565 4y agoExactly what I thought too but there appears to be a lot of dislike for LastPass on HN and I’m not seeing any evidence to back it up, perhaps it’s just a dislike for cloud based solutions
- deleted 4y ago[deleted]
- birdyrooster 4y agoGuess what, they will keep getting hacked and it doesn't even matter
- jph 4y agoKudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.
- jeffbee 4y agoRidiculous take. Absolutely zero kudos because it was obvious to everyone that this was the most likely outcome way back in August. Back in August the company issued a bullshit statement that they'd ruled out that the intruder accessed customer data. Now they are saying they did lose customer data.
- CaliforniaKarl 4y agoIs this the same incident as the August incident (https://blog.lastpass.com/2022/11/notice-of-recent-security-incident/ https://blog.lastpass.com/2022/11/notice-of-recent-security-...)? From this blog post, it’s not clear to me that they are. EDIT to correct: Thanks to the link posted by u/voganmother42, this is indeed related!
- deleted 4y ago[deleted]
- bigmattystyles 4y agoNot to mention, this is mentioned nowhere on the LastPass page itself - only on that of the corporate owners.
- dang 4y ago(this subthread was originally part of https://news.ycombinator.com/item?id=33809508 https://news.ycombinator.com/item?id=33809508, but we merged the comments hither)
- cramjabsyn 4y agoHacking is why we’re here. It’s criminal and exploitative behavior that sucks.
- clumsysmurf 4y agoJust a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!
- danmur 4y agoIt also didn't export attachments when I used it (long while ago now though)
- r1cka 4y agoThis is years ago now, but every ampersand in my passwords came across wrong. I can't recall if it was missing or url encoded, but even passwords weren't safe.
- xd1936 4y agoI'm still finding passwords in Bitwarden to old accounts that have `&` in them. Thanks, LastPass!
- userbinator 4y agoThat is especially surprising, considering that passwords are more than likely going to contain special characters.
- eru 4y agoLastPass's own generator puts them in there.
- mattacular 4y agoThe conspicuous lack of detail in this statement doesn't bode well...
- sp332 4y agoIt's not unusual when the investigation has just started.
- chris_wot 4y agoThey known enough to say "We have determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information." I'd want to know what information they have gained access to.
- SpaghettiX 4y agoI used to be a lastpass customer a few years ago, until I switched to Bitwarden. Can you tell me that you actually delete users data when they delete their account? Or do you keep backups which were also hacked? i.e. are your ex-customers also affected?
- gbala 4y agoWhat does the hacker news community think about Google Chrome's internal password manager?
- idiotsecant 4y agoThe one where you can just launch chrome and click the eyeball icon to see what the password is? Or does chrome have something fancier I am not aware of?
- xen2xen1 4y agoUsually requires a system password to actually see them.
- ab_io 4y agoI’m disappointed, but I can’t say I’m surprised. I once tried to contact their support team after getting effectively locked out of my account, only to have the support form return a 5XX error upon submission. I dropped them right then and there.
- gbala 4y agoWhat does HN community feel about Google chrome's internal password manager compared to third party ones?
- ocdtrekkie 4y agoI'm not sure if they fixed it, but in the past any process that was running in your user account or admin on your PC could dump the plaintext of this trivially, for many years. Reply to @jeffbee: You basically have to have that threat model, because ordinary users are running dozens of untrustworthy processes on their machines. Real world security has to assume the user is not a security expert.
- jeffbee 4y agoA process running as my user or admin on my PC can also just inject input events to transfer money out of my bank account. You cannot have a useful threat model that models yourself as a threat.
- sureglymop 4y agoWill never understand why people use managed password management services when things like the KeePass KDBX format exist.
- ocdtrekkie 4y agoBasically the entire password manager space is the result of "security fatigue". Telling everyone that every single unimportant website they log into requires a unique high security password makes people use bad solutions that make their security worse, like storing all their passwords in a cloud-based single point of failure.
- winphone1974 4y agoMultiple devices? Central management? I use KeePass so I don't know, but I assume there are valid reasons
- system2 4y agoYou can use KeePassium for mobile, store your kdbx file on ftp or google drive. Not difficult. Takes only one time setup then all good for life.
- hprotagonist 4y agowhen you have an employee leave your company can you reroll or disable all their work account passwords in keepass? (no; this is good for the user and not useful for the org, but that’s the use case.)
- olyjohn 4y agoIf I were going to steal passwords for my company, I'd steal them before I quit / got fired or did something illegal.
- xboxnolifes 4y agoYes. Because their passwords should be linked only to their own work accounts and not be shared passwords. Even if you used lastpass at work, nothing stops an employee from storing it again somewhere else.
- sys32768 4y agoTime for hardware tokens based on DNA, so that nobody gets online unless they are exactly and uniquely who they are, and fully trackable from all points of contact. To get in, you must have the token. Bad actors lose access similar to jail time. Unless they can hack their DNA to be unique again, they don't get back in except on parole or after punishment. My guess is this way of solving old problems may create new ones due to that pesky problem called human nature.
- Rebelgecko 4y agoIsn't DNA more of a "username" than a password?
- darth_avocado 4y agoDNA is easier to lift from unsuspecting victims than it is to hack your alphanumeric code. Thought theft at scale with DNA based systems would be hard. Unless, you’re the government, in which case, good luck.
- deleted 4y ago[deleted]
- n4bz0r 4y agoWouldn't this be easily bypassed by, say, picking up a hair on a street and fabricating the token? If so, at least bad actors won't have the incentive to cut off your finger or pull an eye out as with the other biometric authentication options :')
- nottorp 4y agoThat's how the voodoo doll myth was created. And to the OP, any shared secret that you cannot change in case of compromise is kind of a bad idea.
- avrionov 4y agoThe Verge has more information [1] "This comes just months after LastPass confirmed that hackers had stolen some of its source code in August and had access to LastPass’ internal systems for four days before getting detected. It looks like this new attack is connected, as Loubba says it determined that hackers gained access to user data “using information obtained in the August 2022 incident.”" https://www.theverge.com/2022/11/30/23486902/lastpass-hackers-customer-information-breach https://www.theverge.com/2022/11/30/23486902/lastpass-hacker...
- Sakos 4y agoFar better than the blog post, which leaves out crucial info.
- zzzeek 4y agoJust read it looking for that extra info and not seeing it? the blog post and this article seem to have the identical information in them. The blog post is in a series, so for background on the "four days in august" you can scroll down. it's certainly not acceptable that all they are saying is "certain elements of our customers’ information." very unacceptable, if it's credit card numbers or home addresses, they have to reveal that. the current language makes it look like they want to hide some kind of very bad news which is worse. Also their August post indicated that the developer account that was compromised had no access to customer data, so why exactly was that wrong.
- crumpled 4y agoPerhaps the attacker determined how the software interacts with customer information, by reading the source code, and was able to exploit the information somehow.
- rtepopbe 4y agoThey may have missed it, as I did. The current update fits pretty well exactly on my screen, so I saw no hints that it was a series. After seeing the usual corporate speak and signoff, I assumed that was it. I went looking in their history of posts for more information on the August incident but couldn't find anything, as the older installments do not show up individually.
- destitude 4y agoJust the usual semi-annual LastPass related compromise.. nothing to see here..
- gcanyon 4y agoJust in time to give a boost to passkeys. https://fidoalliance.org/passkeys/ https://fidoalliance.org/passkeys/
- ghosts_ 4y agoThese probably won't replace password managers, just result in passkey managers... Dashlane already supports passkeys & 1password just announced intent to support soon.
- gcanyon 4y agoHow do they "manage" passkeys? There's nothing to manage except your fingerprint/face authentication.
- greenicon 4y agoYou get some form of cross-platform sync. Apple, Google, and so on each have syncing, but in their ecosystem only. You can break out with the QR codes, but this might not be the preferred solution to some.
- gcanyon 4y agoGiven that Apple and Google (at least) are collaborating on a shared standard, shouldn't cross-platform sync be possible?
- ghosts_ 4y agoThey're essentially certificates, so most implementations will only store them on-device, and most implementations I've seen seem to favor the phone as the device you use. It really depends on the platform - but in short you'll either need a phone, or be locked into an ecosystem (browser, OS, etc) making using them on multiple devices & browsers difficult or impossible. A password manager supporting passkeys makes this easy as you can 1-click generate a passkey, and 1-click sign-in to services from any device or browser.
- babypuncher 4y agoAnd here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across devices.
- wheels 4y ago> You just have to deal with the very mild inconvenience of keeping your database synchronized across devices. Which is pretty easy with SyncThing. Other services like Dropbox are also fine if you have a sufficiently high entropy password. The danger isn't in the "online", but a third party being able to decrypt your passwords.
- tux 4y agoNever using online password manager is a good start. Only use encrypted local password manager preferably on encrypted file system and never use same passwords and emails. Best have seperate emails at least for the most important data. Also generating random 50+ alpha-numeric-symbols.
- slondr 4y agoEasier said than done, sadly.
- NateEag 4y agoThe pass command makes this significantly easier: https://www.passwordstore.org/ https://www.passwordstore.org/ There's even a decent Android client: https://github.com/android-password-store/Android-Password-Store https://github.com/android-password-store/Android-Password-S...
- bmitc 4y agoIs that safer than 1Password? According to their documentation, passwords inside 1Password are fully encrypted and only ever decrypted locally on the user's devices. So, it seems identical to the local use case you describe except that it's much more difficult to lose your passwords on 1Password. With passwords only locally on a single machine, if you lose the machine, you lose your passwords. Plus, there's no easy way to share the passwords across multiple machines and especially operating systems. It seems to me that everyone stating that systems like this are terrible simply propose an alternative that is a hand-built version of the same solution.
- rubysash 4y agoI am by no means skilled as a programmer when compared to skilled programmers/scripters, but I did cobble this together a few days ago. Python version of a password keeper using sqlite. My motivation was precisely because I do not trust other password keepers. MIT license: https://github.com/rubysash/PythonPassKeep https://github.com/rubysash/PythonPassKeep
- rubysash 4y agohttps://github.com/rubysash/PythonPassKeep https://github.com/rubysash/PythonPassKeep MIT license. Python version of a password vault using sqlite I cobbled together from chunks of other, greater coder/scripter's work. I know I'm not any type of pro coder so be gentle with the attacks. Feel free to use it too though, I do.
- nde 4y agoIs there a better cloud-based alternative to LastPass? I see KeePass being mentioned but I’m not interested in the keeping devices in sync myself.
- SparkyMcUnicorn 4y agoI can never recommend 1Password enough. When it comes to hosted options, they are hands down the best. Worth pointing out that they also have integrated 2FA, if you're satisfied with first and second factor living in the same spot. https://1password.com https://1password.com
- symlinkk 4y ago> if you're satisfied with first and second factor living in the same spot It’s no longer “2FA” then.
- robbintt 4y agoIt is still 2 factor, breaching the password manager is a corner case that you can decide to cover or not. It seems like for critical accounts you should NOT. For derived accounts, it should be better than just a password.
- next_xibalba 4y ago> Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture. https://blog.lastpass.com/2022/11/notice-of-recent-security-incident/ https://blog.lastpass.com/2022/11/notice-of-recent-security-...
- foobiekr 4y agoZero knowledge, 100% authority on downloaded JavaScript.
- Zamicol 4y agoI wish there was a bigger push for integrity checking in the browser. It would be foundational to any solution that fixes that problem. There is already integrity checking for subresources: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres... Newcastle University had a proposal for website wide integrity checking: https://github.com/toreini/DOMtegrity https://github.com/toreini/DOMtegrity Note that only 7 people have starred it on Github.
- roywiggins 4y agoI don't think either of those help if the website itself is pwned? SRI is fine if your website is secure but the CDN is pwned, the other one seems to be a defense a website can use against a malicious extension, but the risk with LastPass is if the LastPass website is pwned it can just read your password. You'd need some way to transfer essentially signed app bundles to the browser for the browser to verify, which seems like a different sort of project.
- bigDinosaur 4y agoI assume ultimately something like signed releases will become a thing on the web, with the signing process being separate from the other processes so that a hack has to compromise two entirely different systems, not just the build pipeline, to allow new JS to run. Currently the only thing that is signed is the SSL certificate which of course guarantees precisely nothing about the actual website content served from the server other than that someone didn't tamper with it after it was sent.
- fredgrott 4y agoFor those that do not know Yubico hardware stuff does work with both Bitwarden and BitLocker It's the solution I will be transitioning to at some point. Note, GitHub requires 2-auth fall of 2023 in case anyone forgot.
- aborsy 4y agoIf the software is compromised, Yubikey won’t help.
- graiz 4y agoPassKeys can't come fast enough.
- aborsy 4y agoThe best is to use something like Keepassxc, synced peer to peer by Synchting or Resilio. Nobody will be involved with your passwords. Keepassxc supports Yubikey, so you can lock it down strongly!
- lxgr 4y agoYubikeys (and more generally CTAP) do not really help with locking down local password managers. The KeePassXC FAQ even explicitly explains that.
- rexreed 4y agoFrom the KeePassXC FAQ: "Additionally, you can use a key file filled with an arbitrary number of random bytes or a YubiKey to further enhance your master key" https://keepassxc.org/docs/#faq-keepassx https://keepassxc.org/docs/#faq-keepassx
- lxgr 4y agoFrom the same FAQ: > So in a sense, it makes your password stronger, but technically it doesn't qualify as a separate second factor, since this is not an authentication scheme and also because the expected response doesn't change every time you try to decrypt your database. I'd argue that the biggest threat against a (non-cloud-synced) password manager is a local database compromise, and the Yubikey does not meaningfully help here. To be fair, I don't think anything can help in this threat model – a password manager is ultimately a key/value storage for bearer tokens, and if an attacker can exfiltrate those key/value pairs, it's game over. So the Yubikey certainly helps against an otherwise too short/reused password manager unlock password, or against somebody shoulder-surfing your password and able to steal your database, but not otherwise tamper with the device you're decrypting it on. But other than that – if somebody can steal your local database and sniff your password (e.g. via a key logger), they can probably also sniff your Yubikey challenge/response, which is returned via the USB HID protocol as well.
- aborsy 4y ago
- grogenaut 4y agoYears before these systems came out I thought of building a similar zero trust style system and I realized the level of attack that I would be putting myself under and the insecurity of JavaScript due to extensions, mitm, and client side malware made it ridiculously unpalatable. You would have nation state attackers coming after you as well as your nation state demanding you grant access to them. It felt pretty brazen to me that these companies came out but they did well. I still think it's an incredibly juicy target and a bad idea. I at least know if someone broke into my physical safe.
- bawolff 4y ago> I realized the level of attack that I would be putting myself under and the insecurity of JavaScript due to extensions, mitm, and client side malware made it ridiculously unpalatable This doesn't really make sense. These threats apply equally to people just memorizing and typing in their passwords into web forums. If the user's browser is compromised there is literally nothing to be done.
- quickthrower2 4y agoLastpass is an extension. Your as secure as the JS running in that extension.
- grogenaut 4y agoIt doesn't compromise ALL of your passwords in one go, it only gets the ones you type. I don't do my bank or my broker except on my low risk machines with 2fa. But logging into a motorcycle web forum shouldn't leak that password. Having them all in the browser local storage with one master password does.
- Beaver117 4y agoI know people will deny it but don't underestimate security by obscurity. Why use the most well known password manager which is a huge target for nation states everywhere? Nobody is attacking my provider (which I won't say)
- hk1337 4y agoI have never really liked the idea of a password manager synched to a central server. Everyone always made excuses for it because each one is encrypted for each user and whatnot but it just means an attacker only needs to hit one spot to get a slew of vaults. I liked 1Password for a long time because it gave you an option to sync with iCloud, Dropbox, FTP, etc. Then they started their own service like LastPass and started trying to push people to that. They got backlash initially and turned the other abilities back on but I'm sure they're trying to make it as difficult as possible to continue to use anything but synching to their server. I've since moved to Keepass and sync it with my NAS
- Johnny555 4y agoNobody is attacking my provider Would you know if they did? Would your provider know?
- k_roy 4y agonation states? lol. I would rather use the most popular password manager that's been audited, and never had a hack (1Password). Then we have your "less well known" provider. They have probably outsourced their dev work to cheapest Indian firm they could find. So I guess congrats on your data being public?
- mfcl 4y agoI once started an interview process as a senior developer at Goto, the company behind LastPass. The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open source? "How many years of experience do you have in open source?" (Probably because the recruiter had a list of tech and skills required and simply went through it.) Anyway, I went with it and eventually got a coding assessment. The docx document told me to implement a little deck of cards in Java using classes and inheritance. This was for a senior position. I did not do that and withdrew my application.
- matthewwolfe 4y agoYou laugh at that coding assignment for a senior position but you'd be surprised how many "senior" people interview that would struggle with that and be unable to complete it.
- caminante 4y agoFizzBuzz interview questions are fair game[0] , especially if you're not networking in via referrals and are 1/5000 online applicants like the parent. [0] https://www.joelonsoftware.com/2006/10/25/the-guerrilla-guide-to-interviewing-version-30/ https://www.joelonsoftware.com/2006/10/25/the-guerrilla-guid...
- rjbwork 4y agoPretty much. I hold the record for our coding question in my company - 3 minutes and 54 seconds. Granted, I'm one of the two people that put the question together, but still. We've had candidates with "20 years of experience" completely unable to do what amounts to "call a web service, deserialize some json, write a couple for loops and if statements, and post back some json to a web service" in over an hour, or in a take home scenario. It will never cease to amaze me that there are people employed in this field that just. can. not. program.
- zelon88 4y ago> We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security firm, and alerted law enforcement. EXACTLY why so many companies opt to stay on-prem, to the amazement and bewilderment of every vendor sales rep that calls on the phone. Go ahead and ask them which Cloud providers their company uses. Ask them which open-source libraries their SaaS uses. Ask them to show you the audits they've performed on THEIR supply chain this year. You won't get any answers. So sick and tired of everyone jumping on the "more links in the chain is better" bandwagon.
- deleted 4y ago[deleted]
- hn_throwaway_99 4y agoLastPass blog post on Sept 15 said the hack was accomplished with a compromised developer machine: > Our investigation determined that the threat actor gained access to the Development environment using a developer’s compromised endpoint. While the method used for the initial endpoint compromise is inconclusive, the threat actor utilized their persistent access to impersonate the developer once the developer had successfully authenticated using multi-factor authentication. This is similar to other recent hacks, e.g. where a crypto company was hacked when a developer opened a malicious PDF he thought was a job offer. So, in other words, being on cloud vs. on prem, and potential supply chain hacks, had nothing to do with it. So sick and tired of everyone jumping to conclusions to fit their preconceived notions of what is good/bad when it comes to security.
- zelon88 4y agoYou're missing the point entirely. When you're on prem you only have to worry about your own employees opening sketchy PDFs. When you're not, you have to worry about everyone in your supply chain opening sketchy PDFs. Nevermind the fact that the next time a major world conflict occurs, the big 4 cloud providers will probably be destroyed, taking about 90% of the western economy with it.
- MetaWhirledPeas 4y agoProduct idea! A little e-ink display (let's call it a Password Storage Device or PSD) with a tiny processor and enough memory to store all your passwords. Make them cheap enough that you can have a few redundant copies in various places. - OS sees the device as a keyboard - Two versions. One with bluetooth, and one with only USB for a little more security. - Open source software package to sync your collection of PSDs - Open source browser extension to autofill passwords - Tiny keyboard on the device (detachable to share between your collection?) Usage: 1. Install browser extension 2. Navigate to a password field 3. Follow prompt to populate password Alternate usage: 1. Manually search for password using the device keyboard 2. Click into password field in browser 3. Press button on device to have it type the password Or of course you could just view the password on the device if you prefer.
- VoidWhisperer 4y agoYou would also likely need a way to get this to work on a mobile phone too. I know from personal experience that there is plenty of times nowadays that I end up logging in to various places using my password manager (not lastpass) on mobile.
- Steltek 4y agoThe phone would still see the device as a Bluetooth or USB keyboard and the "alternate usage" should work.
- vel0city 4y agoAndroid and iOS work with Bluetooth keyboards.
- dotancohen 4y agoBut not _as_ bluetooth keyboards, which is what the proposed feature requires.
- tcoff91 4y agoYou can use the Trezor as a password manager. Passwords are not stored on the device, but the key and all encryption/decryption happens on the device.
- k7sune 4y agoHow does LastPass implement their security challenge, where they rate your passwords and compare them to known mass password leak incidents? Does that require an upload of plaintext passwords to the server?
- andirk 4y agoOh like 1st interview question is: "What's your password?". A few jobs ago I needed some IT help and the guy asked me that. I told him my very vulgar password loudly. Then went back to my desk and changed it.
- wizofaus 4y agoNot sure why you would think that was necessary or at all likely. We have these things called hashes...
- 8n4vidtmkvmk 4y agothat doesn't explain anything. they shouldn't be uploading unsalted hashes either. and if it's salted, it won't match with any database
- marklyon 4y agoDoesn't it run zxcvbn to calculate the score on the logged-in client?
- ThunderSizzle 4y agoMy wife's Instagram was hacked and then banned. It was using a Lastpass generated and managed password. I've since redid all her credentials in the password keeper I personally use. I suspected Lastpass was lieing about how significant their security leak was back in August, considering my wife's account getting hacked and banned was pretty soon after the news hit.
- bnmathm 4y agoI have to believe that if hackers hit the treasure trove of Lastpass customer passwords, Instagram is not going to be their first target. We'd be seeing financial fraud first and foremost, likely sparingly at first, to not alert everyone to the fact that all of our passwords are compromised.
- ThunderSizzle 4y agoYour probably right, but I'd assume financial attacks would be highly targeted after verifying they have the proper passwords via using places like FB that will just ignore you endlessly if your account is hacked.
- Operyl 4y agoThere’s something hilarious about reading their blog to understand what has happened from their side, to getting this wonderfully annoying pop up urging me to sign up to their newsletter multiple times: > JOIN OUR NEWSLETTER > Enter your email for updates from the LastPass Blog.
- huxflux 4y agoAnd people still ask me why I don't use password managers..
- system2 4y agoThank you LastPass. You make me look better in front of our clients for using local KeePass.
- moron4hire 4y agoMy company uses LastPass, but I found it too much of a hassle compared to the browsers own, built-in password management, so I don't use it. But I do keep it installed, because their poorly developed browser extension hijacks way too much on any page with any <input> elements on it. I need to keep it around to be able to test my own work to make sure LastPass isn't fucking things up for my coworkers. It's something to do with how they inject their UI into the page. It's particularly bad if you're trying to make a responsive grid layout. I've seen several incidences of the LastPass extension completely obliterating an otherwise very well-behaved page, on both my project and other websites. And because it's happening in extension code, it's not immediately obvious what is going on. All you see is a blank page, or a page with the intended UI all smashed into the bottom rows of the grid layout. It's also a bit of a Heisenbug, as the LassPass code races your own to inject the UI.
- tims33 4y agoAnyone know which cloud storage provider this was?
- davnn 4y agoA couple of days ago some of my sensitive information (stored in LastPass) was used trying to access different services. I‘m still trying to identify how the data got breached.
- harriet1 4y ago[dead]
- roydivision 4y agoRelated general question - does anyone do a regular export of their password database? I'm thinking this would be a good idea, but I'm wondering what the best practice is, obs the export needs to be secured.
- donkeyd 4y agoI have an encrypted USB stick for things like this. It has a keyboard, so encryption is built into the device and it wipes after 10 tries (not ideal for back-up).
- rationalfaith 4y ago
- amelius 4y agoGlad I'm using Firefox Sync.
- phyzome 4y ago"Third-party cloud storage service" -- left an S3 bucket open?
- femboy 4y agoOh, that time of year.
- cfontes 4y agomigrated to Bitwarden last time LP had a security breach, never been happier it's a lot better with a better app.
- rubslopes 4y agoMe too, but I'm wondering if I went through the trouble of deleting my LP account...
- Yuyudo_Comiketo 4y agoOh come on guys, what's the problem? Just keep delegating all your sensitive stuff to the cloud instead of the unbearable chore of storing it locally! They'll definitely fix their shit together and everything will be okay, until someone hacks them again.
- deleted 4y ago[deleted]
- tasuki 4y agoI've been looking to migrate off LastPass to Bitwarden or KeePassXC, but can't decide: 1. First off, who's to say LastPass will actually delete my data when I delete my account? Could I in practice be increasing my exposure by starting to use something different? 2. Bitwarden: They look cool but "In September 2022, the company announced $100M series B financing". In my experience, usually, financing = bad. 3. KeePassXC: I'm afraid the UX will be worse. But hey it's in my operating system repos, so perhaps I should just give it a try?
- tornato7 4y agoWhy no 1Password on your list?
- lepetitchef 4y ago+1 for 1Password and Bitwarden. One is good at UI, one is simply yet more affordable.
- tasuki 4y agoI just looked at the two that seemed to be the most mentioned in my circles (that'd be HN, I'm afraid...)
- cmsj 4y ago1Password has the same fundamental flaw that LastPass does - they insist on hosting your vault on their servers. That is a bad idea and you shouldn't use a service with that requirement. Use something you can self host, or have the choice of DropBox/iCloud/etc for syncing.
- sillyapple 4y agoI've been very happy with Bitwarden. If things go south because of getting funding there are some good forks of the server you can self-host (vaultwarden).
- CheBuzz 4y agoAnother happy vaultwarden self-hoster here. It requires almost not maintenance from me once I got everything setup.
- prego_xo 4y ago"Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture." A security breach memo is not the place to advertise how great your security is.
- frankhoward 4y agoFinding your partner cheating isn’t easy. People who cheat are generally smart enough to hide it. Therefore, their partners often spend nights awake wondering if their suspicions are true or not. Luckily today you are going to read about a way through which you can know for sure if your partner is cheating on you. This happens by sending a mail to Jeffreyethicalhacker Don’t worry, you aren’t going to need your partner’s phone in order to see what your partner had been up to. The way I told you worked for me, and it was remotely. contact him via email; Jeffreyethicalhacker@gmail.com whatsapp or Text on : +1 (747)345-9036 umyu
- frankhoward 4y agoFinding your partner cheating isn’t easy. People who cheat are generally smart enough to hide it. Therefore, their partners often spend nights awake wondering if their suspicions are true or not. Luckily today you are going to read about a way through which you can know for sure if your partner is cheating on you. This happens by sending a mail to Jeffreyethicalhacker Don’t worry, you aren’t going to need your partner’s phone in order to see what your partner had been up to. The way I told you worked for me, and it was remotely. contact him via email; Jeffreyethicalhacker@gmail.com whatsapp or Text on : +1 (747)345-9036 ymjh
- sghosh2 4y agoThey gave no information on what was hacked. Although they're saying no passwords were compromised because of their encryption and architecture. For a layperson, what's the best tips for what to do. Are passwords in Lastpass still safe or should we change all the passwords? Or simply change the master? Or should we migrate to something else? I've thought about migrating before but frankly any password manager will have breaches...