6 ms·
This is not the worst case scenario. This is literally the best case hack scenario. Why? Because we already know that encrypting something using their strateg
by FatActor 4y ago
This is not the worst case scenario.
This is literally the best case hack scenario.
Why? Because we already know that encrypting something using their strategy is essentially uncrackable.
AES256 is quantum resistant.
The worst case would be silent exfiltration from the LastPass application via malware to steal user master passwords.
In the security game, the crypto is the strongest part, the crypto-system is the weakest part.
- CookieCrisp 4y agoWhile I agree with your main point, I think confirmation that the URLs weren't encrypted and that they can all be tied to your Lastpass signup information is far from "best case"
- FatActor 4y agoI missed that part. What is the problem about URL exposure? EDIT: all three replies to this comment are about sex-shaming people via their email address, ip, home address. hardly pearl clutching. go to DefCon some day, you'll see how that information is basically for sale legally, let alone on the darkweb. i don't have a horse in this race because i use my own password storage software but the amount of FUD in this thread is cray cray.
- deleted 4y ago[deleted]
- phillipseamore 4y agoWith a list of names, billing addresses, email addresses, telephone numbers, IP addresses (sounds like it's a list since the user first started to use LP) along with URLs having a 99.9% probability of the individual having an account at the URL... that can be pretty much catastrophic. Create a list of OnlyFans subscribers, or if there is a subdomain used for OF creators you can compile a list of them. Any service that uses unique subdomains (like the users username) means you can connect usernames with individuals and so on.
- sockaddr 4y agoProbably that now it is known that people with a lastpass account of email address X also have an account at login.furriesindiapers.com or something really insane like dailywire.com
- phillipseamore 4y agoOr worse... find everyone that has a "WePostDamningInformationAboutOurDictator.com/wp-admin" URL
- sockaddr 4y agoYeah, yikes.
- g_p 4y agoSince they're tied to people's account details, address and similar, I'd imagine quite aggressive blackmail opportunities going forward if the data gets to the hands of criminals. Think postal letter named and addressed, giving your email, and the adult (or other embarrassing) sites you were a member of listed on the letter, along with details of a bank account to make immediate payment to... Also, you may be able to identify people working for certain high profile orgs (defence contractors, etc) and target them further if you can gleam from URLs they have access to internal systems by specific URL.
- poglet 4y ago> that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.
- hunter2_ 4y agoI wonder why URLs would be unencrypted given that all the other things are encrypted. I guess browser integration relies on it?
- micahcc 4y agoright, they need to know whether to offer you a password or not regardless of whether you have re-locked
- phillipseamore 4y agoThat doesn't require it to be stored in the clear on the server. Extensions/apps could keep a domain list (don't see why they need full URLs) in memory after lock.
- hunter2_ 4y agoAre domains truly the only scope that matters? What if a platform site allowed hosting user web apps (which could themselves offer authentication) all on the same domain, each in their own directory/path. As long as the app was careful to set the path attribute of the session cookie appropriately, the app could be pretty well-contained. Then a password manager just decides that a password field anywhere on the whole domain is a good place to autofill your password for one of the apps on that domain? That's pretty scary!
- phillipseamore 4y agoThe context here is with a locked vault so no data to auto-fill with. It's most likely purpose was to indicate "LP has the login info for this site but the vault is locked". An indicator like that can be coarse and simply use a root domain and ignore subdomains and paths, better to have some false positives than leak data in the clear. [We might be wrong about the locked-vault but might have data scenario, but that kind of seems the only legit reason to store that stuff in the clear, so if that wasn't the reason, LP's negligence is even worse]
- alexhjones 4y agoI might be misunderstanding, but if the url was adobe.com, then it would be possible to find the corresponding password from that adobe breach for the same email address (not trivial, but if someone moves in the right circles I assume they could get a whole host of the big breaches in a searchable format). A subset of users might have reused the breached password(s) for their lastpass master password. Not sure if you could also feed the breached passwords into the brute force tool to give it a headstart, in case they did a slight variation on a breached password for the lastpass master password.
- randerson 4y agoAny information that helps an attacker craft a more targeted attack is useful to the attacker. With URL exposure the attackers now have a comprehensive list of services that a person depends on and where further data about them is stored.
- thaumaturgy 4y agoSome URLs will be for internal corporate networks, things that should be protected by VPN but aren't, or publicly-accessible projects with poor security. It would be really interesting to crawl through this data and filter out all the boring usual stuff, and see what else shakes out. It's also somewhat helpful for spear-phishing or other social engineering. If you know which services a particular person is using, it's easier to fool them into giving up access to one or more of them.
- jjulius 4y ago>go to DefCon some day, you'll see how that information is basically for sale legally, let alone on the darkweb. "It's already out there so we shouldn't bother preventing it from spreading further," is a terrible argument.
- g_p 4y agoAgreed. Also what's being overlooked by others is the inability (using dumps of "users of site X") is the ability to globally intersect that with another site. The ability to quickly find users who have an account in (list of embarrassing sites) intersected with (list of internal gov and mil sites, and large defence companies) is hugely powerful to some adversaries, and data leaks/dumps only give half of this equation.
- panarky 4y agoLastpass called storing URLs in plaintext their "Zero Knowledge Architecture". "Zero Knowledge" should join "Full Self Driving" in the malicious marketing hall of fame.
- Dykam 4y agoWhich is a shame, because zero-knowledge actually can mean something. But it's yet another term with actual value hijacked for marketing.
- intelVISA 4y agoSounds like it technically was Zero Knowledge Architecture in the non-cryptographic sense.
- mace01 4y ago"Zero knowledge means that no one has access to your master password or the data stored in your vault, except you. Not even LastPass." That definitely cannot be true since they were storing URLs in vaults unencrypted. Seems like a class action lawsuit waiting to happen. https://www.lastpass.com/security/zero-knowledge-security https://www.lastpass.com/security/zero-knowledge-security
- zacharycohn 4y ago> The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that *contains both unencrypted data, such as website URLs,* as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data That's real bad - think blackmail material for important people.
- lowapm 4y agoI agree this isn’t the worst-case as you mentioned above. However, it is far from the best case scenario which is closer to “only fake testing vault data was exposed”. The vault leak is acceptable in terms of Lastpass’s formal threat model but could still result in real user pain e.g. targeted spear phishing using plaintext fields like URLs, or compromise for users with weak passwords.
- sliken 4y agoUmm, not sure you understand. Yes AES256 is good, if you have a great password. However if you take 1M users, as them to set a 12 character password with A-Z, a-z, and at least one digit you'll find an astounding lack of entropy. I believe this is pretty close to LastPass's master password requirements. If you take the most popular 1M passwords and attack the master password you'll find that you've cracked them. With a 2 generation old GPU and the default iterations of 5000 (like several people mention on this post) you can try 300,000 passwords a second. So 3+ seconds per vault and you'd crack a decent fraction of them.
- jart 4y ago(26+10)**12 is 4738381338321616896 combinations. 300,000 attempts per second isn't going to have an easy time cracking that, so I don't see what the problem is with LastPass' requirements.
- mint2 4y ago“(26+10)*12” is irrelevant Please Refer back to “If you take the most popular 1M passwords and attack the master password…”
- jart 4y agoIt is relevant, because it's where LastPass' responsibility ends. It's not their job to prevent people from being stupid and choosing a password like `lovelovel0ve` but rather to define a requirement that allows for sufficient complexity.
- rsj_hn 4y agoI think a reasonable feature for a password manager would be to do NIST recommended checks, such as comparing passwords to databases of known compromised passwords and alerting/recommending rotation or rejection of the password if a match is found (depending on password entry UI). Obviously you're not going to get a complete db of known hacks, but a db of most common X million passwords, updated every 6 months or so, is pretty good, and is what I would expect a good password manager to do. LastPass is in the bad situation of needing to provide excellent security in a product that people really aren't willing to pay a lot of money for. Some of the websites that ask for passwords are in a better position to do this, but then you don't get the benefits of a password manager. Same issue for the the other password managers out there.
- bawolff 4y agoThe relavent part is what KDF they use on the master password. Afaict They use pbkdf-sha256, with 100k rounds. which is not bad, but i think a memory hard function like argon2 would be much much better. So its not terrible, but its not amazing either