45 ms·
The situation at LastPass may be worse than they are letting on
- jeffparsons 4y agoLastPass-the-company doesn't need to die over this incident, but I can't help but wonder if a kind of corporate panic will stop them from doing what they need to survive it.
- fanso99 4y agoThey are owned by LogMeIn, which is a pretty shady company in my book (not malicious necessarily, but not transparent).
- dang 4y agoThese appear to be the main previous threads: See what is unencrypted in your LastPass vault - https://news.ycombinator.com/item?id=34105368 https://news.ycombinator.com/item?id=34105368 - Dec 2022 (9 comments) LastPass breach is worse than you think because URLs were unencrypted - https://news.ycombinator.com/item?id=34102982 https://news.ycombinator.com/item?id=34102982 - Dec 2022 (81 comments) LastPass users: Your info and vault data is now in hackers’ hands - https://news.ycombinator.com/item?id=34100087 https://news.ycombinator.com/item?id=34100087 - Dec 2022 (19 comments) LastPass says hackers stole customers' password vaults - https://news.ycombinator.com/item?id=34099647 https://news.ycombinator.com/item?id=34099647 - Dec 2022 (15 comments) LastPass user vaults stolen in recent hack - https://news.ycombinator.com/item?id=34097142 https://news.ycombinator.com/item?id=34097142 - Dec 2022 (276 comments) Lastpass Security Incident - https://news.ycombinator.com/item?id=33806803 https://news.ycombinator.com/item?id=33806803 - Nov 2022 (560 comments) LastPass confirms hackers had access to internal systems for several days - https://news.ycombinator.com/item?id=32912350 https://news.ycombinator.com/item?id=32912350 - Sept 2022 (21 comments) LastPass says hackers had internal access for four days - https://news.ycombinator.com/item?id=32871051 https://news.ycombinator.com/item?id=32871051 - Sept 2022 (7 comments) Last Pass Hacked - https://news.ycombinator.com/item?id=32612645 https://news.ycombinator.com/item?id=32612645 - Aug 2022 (35 comments) LastPass: Notice of Security Incident - https://news.ycombinator.com/item?id=32598587 https://news.ycombinator.com/item?id=32598587 - Aug 2022 (130 comments)
- deleted 4y ago[deleted]
- poszlem 4y agoIt is difficult for me to believe that this could be true unless their web application has also been hacked. And if that were the case then this is really getting into criminal negligence territory (especially the way they've been disclosing it).
- christoph 4y agoWhen I read their most recent email updating about the situation today or yesterday, I did get a definite chill down my spine. I've not used LP for a year or so, but my data (much of it now old) is still stored there, mainly left as a backup as I'd heard some people had some weird issues migrating to other password managers. I had made a mental note some months back when this first happened I should really go through everything important in my vault and update all passwords to sleep more peacefully at night. I had also made a mental note at the time that if this situation were going erupt into something much worse, it would almost certainly be over the Christmas period when many people are not at work or their computers and it would be the perfect moment for causing maximum chaos and destruction. Looks like I now really need to prioritise that tomorrow. Really not what I wanted to be doing on Christmas Eve...
- Sakos 4y agoI'm not too worried because anything important that I have in LP is protected by 2fa. It's notable that the author says his accounts are protected by 2fa, but I don't understand how LP being hacked would allow an attacker to defeat that.
- ddejohn 4y agoFor anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwarden was handling URLs. [1] https://bitwarden.com/resources/zero-knowledge-encryption-white-paper/ https://bitwarden.com/resources/zero-knowledge-encryption-wh...
- dreamyfigment 4y agoI wonder what 1password does
- vermilingua 4y ago1password’s security design whitepaper can be found here: https://1passwordstatic.com/files/security/1password-white-paper.pdf https://1passwordstatic.com/files/security/1password-white-p... It’s quite good.
- dreamyfigment 4y agoThanks! They seem to encrypt everything too. Items contain overviews and details which are encrypted separately by the vault key. We encrypt these separate so that we can quickly decrypt the information needed to list, sort, and find items without having to first decrypt everything in the vault. Item overviews include the item fields needed to list items and to quickly match items to websites, such as Title, URLs, password strength indicator, and tags.
- _-____-_ 4y agoAdditionally, 1Password makes the extra effort to never even send the URLs of your accounts to their servers. Even with their Watchtower service, which notifies you of breached accounts and websites that support 2-factor authentication, your passwords and website URLs are never sent to 1Password servers. https://support.1password.com/watchtower-privacy/ https://support.1password.com/watchtower-privacy/
- eigenvalue 4y agoI’m skeptical of this. Seems like if it were true, we would be hearing the same thing from several other independent and credible sources.
- phphphphp 4y agoI agree: LastPass has been hot garbage for many years but it still has a significant presence, some guy’s low-value crypto wallets would not be the first we hear about a compromise of LastPass vaults. There are entire companies using LastPass for critical systems. I absolutely believe it’s possible that LastPass has been compromised more than they’ve let on and I won’t be surprised if we eventually find out vaults are vulnerable, but I don’t believe this is how it would play out. Sunday the 18th is conveniently around the time of the latest announcement, but not the time of the actual hack. Feels like someone is over fitting.
- P5fRxh5kUvp2th 4y agoThis attitude is why a poor person will effectively be put in debtors prison and no one bats an eye. It requires "someone important" before people think maybe it actually happens.
- MBCook 4y agoBut if you had a ton of credentials from people, scanning for crypto credentials and trying to use those may be easier/faster/safer to turn into money than system credentials to some random company network.
- phphphphp 4y agoIf the hack of LastPass happened yesterday, sure, but it happened months ago. There are a variety of different attacks that could be executed in that time, and the sooner the attacks are executed, the better — because less time for credentials to be rotated. I find it implausible that the first hint of vault compromise comes 4 months after the hack and is against a low value cryptocurrency wallet. Especially considering that when LastPass first had issues, there were dozens of people reporting personal experiences of it here on HN — if LastPass vaults are compromised, the internet would be flooded with reports.
- DethNinja 4y agoIs there any reason to use these cloud based solutions when open source alternatives like KeepassXC is available?
- n0tth3dro1ds 4y agoYeah: they’re cloud based. Your passwords get synced to all your devices automatically. That’s kinda the entire draw.
- acheron 4y agoExactly. I used Keepass for years but it became too much of a pain. (Though I suppose changing a bunch of passwords that I had in LastPass is also kind of a pain.)
- npc12345 4y ago[dead]
- dividedbyzero 4y agoThat and you get to centrally admin this for others (employees, family members), fine grained access controls for business use, you don't have to host and secure anything yourself (e.g. Bitwarden), pretty good UX on all your devices. I had to use a shared KeepassX file in git for a project and it was a frequent source of problems.
- MattGaiser 4y agoSame problem with many other open source alternatives. Lousy user experience, in this case across devices.
- klooney 4y agoAlthough LastPass had a pretty lousy UX for years and years.
- usefulcat 4y ago
- DSingularity 4y agoIf this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?
- deleted 4y ago[deleted]
- luisschwab 4y agoSelf-custody of keys. What's the point of trustless money if you trust someone with it?
- armada651 4y agoThere's a step in between LP and an air-gapped setup, it's called "not uploading your keys to the internet".
- TedDoesntTalk 4y agoPrint out the seed phrase
- Sakos 4y agoI handwrite them, stuff them in with a bunch of other handwritten notes and make it a bit less obvious that the words belong together as a phrase.
- dan-robertson 4y agoI think lastpass is reputed to be bad compared to competitors like 1password. If you can’t secure your bike with a flimsy Kevlar belt, what’s left? A team of two armed guards?
- loopdoend 4y agoWhy would you store your private key on a cloud storage service? This is what hard wallets are for.
- 4y ago
- idontwantthis 4y agoWe’ll find out if they actually deleted deleted data or not.
- endisneigh 4y agothis sort of thing is why I append the name of the website + a unique identifier + password, so that I don't have to bother changing my password during such nonsense, ugh.
- TedDoesntTalk 4y agoAppend it where?
- endisneigh 4y agoe.g. password to facebook would be: facebook.com$293MyPasswordYouKnowIt!!123 password to gmail would be mail.google.com$113MyPasswordYouKnowIt!!123 only annoying thing is that the passwords are long. I guess it's secure, though. edit: see child post for clarification. I do something above for spammy sites, but for something like gmail I probably wouldn't do that.
- kangalioo 4y agoHow do you remember the unique identifier?
- endisneigh 4y agoit's deterministic, but obviously I can't tell you the secret ;) that being said there are a lot of things you could use. you could use information in the whois, you could use the birthdate of the founder of the site, etc. personally I believe people should use the same password for all sites and then something similar to what I described. though I use a password manager, I do always feel nervous about the implementation leaking out details
- zenexer 4y agoThat’s not secure at all. Eventually, some website you use is going to get hacked. They’ll have stored passwords as plaintext. From there, anyone who wants to hack any of your accounts knows your password format. It’s going to be obvious to them that they just need to replace the domain.
- gjsman-1000 4y agoReminder that in 2015 LastPass was acquired by LogMeIn, who then in 2021 announced it was spinning off back into its own thing, though whether that has happened yet is unclear. If you look into what LogMeIn (now renamed to “GoTo”) makes… this doesn’t make me feel good about GoToMeetings, GoToMyPC, or join.me.
- puffoflogic 4y agoThat's an interesting take, because for many of us, prior knowledge about the insecurity of GoTo products (not so branded then) were evidence that the security of LastPass was at risk.
- user3939382 4y agoI saw a class action filed. If the class is admitted I may opt out, I want compensation for each of the many hours I now have to spend rotating my hundreds of passwords. This is totally unacceptable.
- peter422 4y agoYou want compensation for rotating your passwords even though there is no evidence other than this random twitter thread that any of them are comprised?
- organsnyder 4y agoGiven the extent of the breach, it's prudent at this point to assume all passwords have been compromised.
- gsk22 4y agoWhy is that so? Aren't the passwords encrypted?
- user3939382 4y agoYes however https://en.wikipedia.org/wiki/Rainbow_table https://en.wikipedia.org/wiki/Rainbow_table
- michaelmrose 4y agoYou wouldn't normally be compensated for your own time lost in a matter that didn't actually cost you money eg actual time not hypothetical time lost from work.
- jackmott 4y ago[dead]
- bawolff 4y agoIf this was true, i feel like it would be a little strange for the attacker to use it to steal a small amount of crypto. Once its revealed how bad this is, there would probably be a small window before people change their passwords, i would assume attackers would either go for a big score before revealing this capability, or they would try to hit everything very quickly. Just hitting a tiny amount of crypto seems odd.
- philistine 4y agoPerhaps the crypto passwords were stored in the unencrypted URL field, or could be understood from data in there. https://twitter.com/SwiftOnSecurity/status/1606071798667173888 https://twitter.com/SwiftOnSecurity/status/16060717986671738...
- LilBytes 4y agoSeems very likely, it's now known (maybe always was) that metadata fields aren't encrypted. If Twitter poster added those keys to a 'metadata field's then they were clear text. LastPass has a LOT to answer for.
- idlewords 4y agoThat tiny amount of crypto is going to be worth a fortune someday!
- nequo 4y agoUnfortunately or fortunately, that day is in the past.
- paulpauper 4y agoin a 3rd world country, a tiny bit of crypto is a nice sum
- xwowsersx 4y agoI've been using LastPass for years. Looks like I'm going to have to export everything from my LP vault and import it into Bitwarden. Any downsides to Bitwarden that anyone knows of? I'm asking more about convenience, i.e. how well the browser extensions and Android app work and less about security.
- rtp4me 4y agoSwitched from LastPass to Bitwarden some time ago. The only issue I had thus far was exporting the contents out of LastPass. Some of the special characters in some passwords did not export properly. I had to add those items by hand. As for Bitwarden, I like the UI (iPad, Mac, iPhone) but routinely forget how to generate a new password - the function is buried inside one of the menu options. Other than that, I really like it. And, there is option to host your own vault.
- xwowsersx 4y agoThanks very much. I wanted to hear from others who've made the same switch, so this is really helpful. LP has been pretty seamless for across devices so I wanted to know what to expect with BW.
- faitswulff 4y agoQuick tip: if you have Bitwarden's browser extension installed, you can use Cmd + Shift + 9 (I'm assuming it's Ctrl + Shift + 9 for Windows) to load your clipboard with a randomly generated password: h4!E49vFcGEE%c#$HZ%z*3^5B
- chank 4y agoHaving all your keys/passwords on a 3rd party server is something that I've never been willing to accept from a security standpoint. That's what always kept me from using a `hosted` solution. I do get the allure from a multi-user management aspect though.
- smt88 4y agoI used to use KeePass and synced the database (but not the keys or password) with Dropbox. Very secure and mostly convenient.
- bigiain 4y agoI loved a similar setup when 1Password used to make that easy. I am very grumpy about them bait and switching me to a cloud/subscription model. (But not quite grumpy enough to have done anything about it yet.)
- chank 4y agoVersion 7 is still available on their website to download (if you have a key for it). Oddly enough they still do update it. It's what I use and likely will use until it no-longer works or there is some issue with it.
- lolinder 4y agoIs the added security just that Dropbox is a lower value target (possible) and that attackers won't think to look for password databases in Dropbox accounts if they do compromise Dropbox (less likely)? Or is there something more to it? EDIT: Given the replies below, I should be clear that I'm not interested in comparing to LastPass, I'm comparing to Bitwarden. LastPass had an obviously bad security model that failed to encrypt everything, but Bitwarden does not have that flaw.
- aborsy 4y agoNo. When you login to LastPass, your password can be taken if LastPass is compromised. You have to trust that LastPass will not do it. If you login to Dropbox, the master password to your keepass database cannot be stolen. You don’t need to trust Dropbox. But what you said is also an additional benefit.
- ern 4y agoThis is quite interesting. A couple of weeks ago, I received an extortion phishing email, but it was directed to a secondary email address that hasn’t been previously compromised. It made it past Gmail’s spam and phishing filters into my inbox. Maybe a coincidence, but I guess every weird thing that happens is going to raise alarm bells. I was suspicious of the LastPass concept (storing passwords in a cloud app) when a former employer introduced it some years ago, but they had a strong IT and security culture so I trusted them to make the right choices and adopted it for my personal use. A few months ago I hsd an issue with my LastPass 2FA device and a policy set by my former employer blocked me from resetting it for my personal account. It was resolved by LastPass, but that was the first strike, and I had spent most of the night extracting my personal account passwords manually from the mobile app, which remained logged in. That was strike 1. This is strike 2.
- bigiain 4y agoI’d love to hear the story about bypassing/resetting that 2FA setting? Sounds suspiciously like something that could be social engineered around by a sufficiently skilled attacker? I am very much of the opinion that if I fuck up my side of 2FA protection, the resources/accounts they’re protecting should be lost forever. (Or at the very least, a co-account holder might be able to reset some things, like my AWS IAM creds or GSuite admin account). If I can ring up and whine at enough support people to get them to hand over my account, so can a sufficiently persistent skilled social engineer…
- ern 4y agoFair enough. It was a support request, and IIRC they disabled it remotely.
- bombcar 4y agoAny two factor that doesn’t require your firstborn or travelling in person to some frightening building to remove is basically a form of security theater. Most can be removed by support pretty easily just by asking.
- 4y ago
- StanislavPetrov 4y agoI feel like this is an excellent time to, once again, give out two reminders to anyone who needs reminding: "The cloud" is just someone else's computer. Sharing your password with anyone always makes you less secure.
- wruza 4y agoAnd so does sending your passwords to a phone or a home/work pc via chats or email, or using a single password everywhere, or maybe a couple of them with trivial variations. Cloud password managers wouldn’t even exist if people didn’t do much more stupid things to enter their passwords on a different device than the cloud could ever think of.
- TylerE 4y agoOr typing your password in! Keyloggers…
- StanislavPetrov 4y ago>And so does sending your passwords to a phone or a home/work pc via chats or email, or using a single password everywhere, or maybe a couple of them with trivial variations. Cloud password managers wouldn’t even exist if people didn’t do much more stupid things to enter their passwords on a different device than the cloud could ever think of. "You should do something stupid because most people do things that are even more stupid" is not a good argument in my opinion. I've been in the computer/tech space for 30+ years without every sharing a password or doing something stupid with my passwords, and it hasn't ever been any sort of burden. Why is it so controversial among the HN crowd to simply be minimally intelligent and careful with your sensitive information?
- five82 4y agoMay I ask how you accomplish this without any sort of burden? Because from my perspective, managing strong unique passwords for hundreds of accounts across desktop, mobile, servers, and other devices is a major pain and I’m tired of dealing with it. It’s human nature to take shortcuts and develop bad habits when you’re dealing with a flawed system and poor tools that puts the burden on the end user to manage everything. And if I’m struggling with four decades of experience, how is the average non tech user expected to do it properly?
- nicolas_t 4y agoAnd when I say that I will stop using 1password when the local vault no longer works, people look at me like I'm paranoid and crazy. I've looked at the white paper https://1passwordstatic.com/files/security/1password-white-paper.pdf https://1passwordstatic.com/files/security/1password-white-p..., I think 1password has a decent security posture for their cloud offering but then there's always the risk of a breach where the attacker controls the site and can intercept your master password through it. Same as what happened with British Airways or Lavabit.
- kccqzy 4y agoThere is always the risk of an attacker infiltrating the company to write vulnerabilities or a government forcing the cloud provider to write malicious code in order to degrade security. That's what the U.S. government almost succeeded at forcing Apple to do in the wake of the San Bernardino case. A local vault is better than a cloud vault, but if that local vault software is written by a commercial company there's still that risk.
- maccard 4y ago> A local vault is better than a cloud vault, but if that local vault software is written by a commercial company there's still that risk. Depending on your device and platform there's still "that risk" even if its open source. If you're compromised, you're compromised.
- salzig 4y agoI know more and more people that are unwilling. But looks like 1Password is still unable to recognize this.
- nerdawson 4y agoIs that same risk present if you use the app? My understanding is the app decrypts the vault locally. I guess they could put out a malicious update but then you’d be impacted whether there was a cloud-free option or not.
- 4y ago
- fanso99 4y agoPlease stop commenting whether you are a LastPass user or not. Some of your profiles on HN have an email address and in general all your comments are public so can be mined, plus "rich techies" could be prime targets for more direct and elaborate phishing campaigns.
- petarb 4y agoThis
- vba616 4y agoFor all you know, they are bots or shills to encourage actual users to comment. Remember this? <Cthon98> hey, if you type in your pw, it will show as stars <Cthon98> ********* see! <AzureDiamond> hunter2 <AzureDiamond> doesnt look like stars to me <Cthon98> <AzureDiamond> ******* <Cthon98> thats what I see <AzureDiamond> oh, really? <Cthon98> Absolutely <AzureDiamond> you can go hunter2 my hunter2-ing hunter2 <AzureDiamond> haha, does that look funny to you? <Cthon98> lol, yes. See, when YOU type hunter2, it shows to us as ******* <AzureDiamond> thats neat, I didnt know IRC did that <Cthon98> yep, no matter how many times you type hunter2, it will show to us as ******* <AzureDiamond> awesome! <AzureDiamond> wait, how do you know my pw? <Cthon98> er, I just copy pasted YOUR ******'s and it appears to YOU as hunter2 cause its your pw <AzureDiamond> oh, ok.
- tommieb 4y agothe ol' hunter2 ... haven't seen this irc dialogue in years, thanks for the laughs
- deleted 4y ago[deleted]
- lolinder 4y agoAren't we assuming at this point that the attackers have the complete customer list? I imagine that it would be way easier for them to have a script query that list directly and search for names and emails to find high value targets, rather than reading through HN hoping for a hit.
- deleted 4y ago[deleted]
- HitchLiveTrevor 4y ago[dead]
- drawingthesun 4y agoI've been using KeePass for years and have recently switched to Strongbox which is an incredible app/ui to interact with Keepass databases for macOS and iOS. The database is kept in sync with either Dropbox or iCloud.
- iamshs 4y agoI just wish Firefox would integrate Apple’s Keychain. I don’t know if it is even possible or not. But it is such a pain because I really am tired of all these password managers and also security breaches from multiple silos. Medibank has leaked all my data and now I have lastpass to deal with too.
- spiffytech 4y agoThis pushed me to move my Bitwarden data to a self-hosted Vaultwarden instance tonight. At this point I just don't want my data in the big, juicy hacking target.
- broknbottle 4y agoThis is why Microsoft's requirement to drink a verification can was so genius. Imagine being a hacker and have to drink multiple verification cans to be able to proceed throughout multiple transactions. "Hacker dies from overdose due to ingestion of too much Doritos and Mountain Dew" https://imgur.com/dgGvgKF https://imgur.com/dgGvgKF
- bombcar 4y agoIt’s basically what modern ddos protection does - the WASM computational calculation is a digital dew can.
- tkanarsky 4y agoWait, so you're telling me that Cloudflare interstitial is running some PoW check on my client? I always thought that was just a way to let the user know they're being rate limited on Cloudflare's end.
- bombcar 4y agoNot sure if cloudflares does it but disable WASM/JavaScript and you’ll find some that do.
- mike_d 4y agoEffectively yes. Not mining bitcoin, but modern bot detection works by asking your browser to do various tasks and comparing the results to a known good sample. It could be a complex math problem, or another common trick is to purposely trigger bugs like a javascript engine not rounding numbers correctly in edge cases.
- Vinnl 4y agoI haven't heard of Cloudflare doing that, but it's the concept behind mCaptcha: https://mcaptcha.org/ https://mcaptcha.org/
- jki275 4y agoWhile this could be what happened, I suspect otherwise. For many years, those of us in the cryptocurrency fields have said never enter your keys on a computer. Generate them offline on a hardware device and let that be it. The person making this claim clearly had to enter unencrypted keys into a computer to put them into his laspass vault. There are a number of malware variants that specifically target keys and search things like input fields in web forms and clipboards for those keys.
- aborsy 4y agoThis claim looks strange. A 16 characters password from all character types can’t be broken. How could hackers break the vault, with end to end encryption and such password?
- paulpauper 4y agofaulty implementation of encryption , such as using a weak RNG
- wlonkly 4y agoA _random_ 16-character password from all character types can't be brute-forced. A password made from common dictionary words, with numbers substituted in with l33tsp3ak, and an exclamation mark on the end, is a different story. Passwords like that would be sitting in precomputed hash lists already.
- snowwrestler 4y agoThe hash would only be sitting in precomputed lists if LastPass did not salt the passwords first. It's my understanding that they did.
- wlonkly 4y agoAh, we both went on a tangent. The password in question is to the twitterer's LastPass vault, and so a precomputed hash list would be of no use, and since it's an encryption key and not a hash, there is nothing to salt. I suppose the point was more that faced with many users' LastPass vaults there are more likely and less likely keys -- but they'll still have to try the keys.
- aborsy 4y agoRead the tweets, explaining how they generated their password.
- paulpauper 4y agoeither two possibilities: 1. password was somehow left in plain text 2. there was a problem with the encryption implementation by LastPass. likely this is the reason. this is why you always encrypt crypto stuff with offline computer using well-vetted tools like VeraCrypt or openssl, and not rely on cloud storage encryption. Only you can do your encryption. relying on others doomed to fail eventually.
- irrational 4y agoIs there a site or something where you can put in all the devices you own (e.g., iPhone, Mac laptop, tablet, chromebook, etc) and what features you want (e.g., adding a password on one device syncs it automatically to all other devices, offline useage, auto fill of browser form fields, auto saves now username/passwords, etc.) and it will tell you what password manager best meets your needs?
- eternityforest 4y agohttps://en.m.wikipedia.org/wiki/List_of_password_managers https://en.m.wikipedia.org/wiki/List_of_password_managers As far as I can tell BitWarden and Google are the two good ones. I use BitWarden. My reasoning is anything new and experimental is scary, I want something with tons of users that's well established. If the community isn't all over it, it's probably not reviewed enough. Open source makes stuff a little more trustworthy, but by itself isn't enough. I also don't want to pay a lot for it, and many are paid. The two big FOSS ones everyone knows are KeePass and BitWarden. Keepass uses some single file database last I checked. Terrible for sync as the sync engine won't be able to automatically merge conflicts and you might get hassles. That just leaves BitWarden, or just using Chrome because it's there, it's easy, and Google seems to be good at protecting you from everyone but them.
- irrational 4y agoWhat do you mean by Google? I looked at the Wikipedia article, but didn’t see Google listed.
- eternityforest 4y agoThey're not listed, but Chrome and Android can manage passwords
- irrational 4y agoOh, I see. Well, I don’t use Chrome or Android, so I’ll look at BitWarden.
- msravi 4y agoBest to just use pass (https://www.passwordstore.org/ https://www.passwordstore.org/) with your own gpg key rather than rely on any 3rd party service. Then set up a git repository on a (free) google cloud instance, (or even use github/gitlab), and you're set to sync your passwords to all your devices.
- nequo 4y agoI like this idea. Have you tried setting this up on iOS?
- b0afc375b5 4y agoYes for me. On my iPad, using the Pass - Password Store app.
- heywoodlh 4y agoI have and it's fantastic: https://apps.apple.com/us/app/pass-password-store/id1205820573 https://apps.apple.com/us/app/pass-password-store/id12058205...
- gleenn 4y agoMaybe this is terrible logic but I would never trust an app that had 120 reviews and what appears to be a single person as the app owner with all my passwords.
- heywoodlh 4y agoNo, I think that logic is completely fair. From my experience it is dead simple and works extremely well, however, I think it's definitely good to vet apps in your own way.
- definitely-not 4y ago[dead]
- user3939382 4y ago
- Scoundreller 4y agoI wonder if quadrigacx’s recent lost “cold wallet” movements are related: https://news.ycombinator.com/item?id=34074858 https://news.ycombinator.com/item?id=34074858
- anonym29 4y agoThis is ultimately a predictable outcome for any password manager that stores your credentials on someone else's server. Just like they say in crypto "not your keys, not your crypto" - it applies here too. Not your storage, not your passwords. KeePass on an airgapped box, or an encrypted hardware password manager with no network interfaces is best, though frankly, I'd even be more comfortable writing down passwords on paper (at home) than I would be storing them on someone else's server. I say all this as a big tech red teamer, or, someone who breaches other people's servers for a living.
- bombcar 4y agoThe idea of using crypto wallets as canaries is an interesting one, however. I bet you could set that up to only be tripped by a major compromise. And yes - there is basically no way to actually prove that your passwords on a server aren’t accessible to someone - especially if they can update software.
- userbinator 4y agothough frankly, I'd even be more comfortable writing down passwords on paper (at home) than I would be storing them on someone else's server. 100% agreed. Physical access is not something than an attacker, especially one likely to be in an entirely different country or even continent, can easily achieve.
- tester457 4y ago> KeePass on an airgapped box Sounds inconvenient for password retrieval when not home, how does this work in practice? How about an airgapped phone with GrapheneOS and Keepass?
- Joe_Boogz 4y agoI deleted my LastPass data a few years back, now hopefully it actually got deleted…
- heywoodlh 4y agoSo is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS password managers for everything possible but have to use LastPass for some non-personal stuff and I very much dislike it
- chx 4y agoQuite obviously there isn't anything and the handle indicating a crypto hack it's as non-credible as anything can be but some folks on HN still fall for the crypto hype. This is your regular reminder that all crypto is scam , this is a simple mathematical fact.
- wombatmoose 4y ago[flagged]
- raydiatian 4y ago> why is this tweet on HN Is a meme
- jupp0r 4y agoVerified account, blue checkmark, must be legit!
- zmmmmm 4y agoThe inference that the LastPass leak is responsible is being made purely on the basis that this particular person can't identify any other way the security of their wallet was broken. That seems a very weak basis (essentially, absence of evidence equating to evidence of absence) to make what is really a very strong assertion.
- paulnpace 4y agoIndeed, the votes on this tweet make me skeptical of HN community's basic critical thinking skillz.
- renewiltord 4y agoEvery week there's some HN post like this. Everyone loses their shit. Then nothing happens. I use Bitwarden but damn dudes. Wow.
- deleted 4y ago[deleted]
- eBombzor 4y agoSimple, use local password managers. Who would trust a single entity with all your passwords
- layman51 4y agoI'm very interested in how this breach was pulled off. Could it be some sort of state actor?
- t3pfaff 4y agoIt was phishing and or extortion of a developer that for some reason had unilateral access to production databases and keys without any higher approval.
- chx 4y agocrypto pathic Press [X] to doubt.
- _8j50 4y agoI have no conclusions on this but kind of like in court, not the best idea to investigate your own personal breach but I get there is little choice for OP. In my experience "I didn't click on any suspicious link" and similar user denials are exactly why you don't ask them that during incident response, instead you get them to give you all their browsing/download history/content so you can verify that. It could be cookie theft (physical 2fa can't stop that) or consent phishing if they use oauth for their main lastpass login. As soon as this was noticed, disk/memory images should be taken of all devices with lastpass ideally so they can be investigated. I don't know if the victim here uses laspass on their phone for example or by new apps they include new browser extensions or updates to existing apps (supply chain compromise).
- Tempest1981 4y agoCould the hack have been achieved using the leaked unencrypted URLs? Not by decrypting the user's vault?
- dzmien 4y agoI have always used Pass [1], and while it is certainly less convenient, it doesn't really take too much extra effort to self host your passwords in a PGP encrypted git repo. Self hosting has drawbacks of its own, of course. [1] https://www.passwordstore.org https://www.passwordstore.org
- pleb_nz 4y agoMost hackernews readers will have left LastPass after the amount of times LastPass has been in the news over the just 5 years wouldn't they? Genuinely interested if phone is still using it - by choice that is.
- ytygg775 4y agoI don't get why everybody is in love with cloud solutions for keeping their secrets. Encrypted as they may be. Self hosted, at home, or I don't trust it. It's really that simple.
- PradeetPatel 4y agoFor enterprise customers, the usage of SaaS solutions is often: 1) Cheaper to manage than in-house solutions, and 2) A way to outsource and manage risks.
- whatsu 4y agoA few years ago, I made the decision to delete my LastPass account. At the time, I wasn't sure if it was the right move, but in light of the recent data leak, I couldn't be happier with my decision. If you're in the market for a new password manager, I highly recommend giving Bitwarden a try. It's open-source and has a strong focus on security and privacy.
- protortyp 4y agoI am quite happy that I am only using KeePassXC + Syncthing. My default assumption for these kinds of services is that they will be breached sooner or later.
- amq 4y agoI so much wish Google would provide a password manager within Workspace. I'm yet to find a trustworthy frictionless product for my business.
- tommieb 4y agoWhat I find concerning is PKDBF was used, even https://en.wikipedia.org/wiki/PBKDF2 https://en.wikipedia.org/wiki/PBKDF2 quotes PKDBF1 and PKDBF2,and that is recommended to use PKDBF2. Is there any evidence to show that they indeed rolled their own encryption rather than use a de-facto standard AES algorithm? Or is there something that is missing.
- fear-anger-hate 4y agoPKDBF is just the password derivation function to better protect the vault against dictionary attacks. The vaults are still encrypted with AES-256.
- tigrezno 4y agoImagine storing all your sensible passwords in the cloud of a private company lol
- Fostewrs 4y ago[flagged]
- chiph 4y agoAs a suggested alternative - I've been very happy with pwSafe. www.pwsafe.info It's not nearly as convenient as LastPass, but likely more secure. It uses TwoFish with a 256 bit key length, which was one of the finalists for the AES standard.
- paulnpace 4y agoWhat if this tweet was provided as "evidence" of the opposite claim: > I think the situation at @LastPass may be better than they are letting on. > > On Sunday the 18th, four of my wallets were completely safe. There were no losses. > > Their seeds were kept, encrypted, in my lastpass vault, behind a 16 character password using all character types. IOW, the honesty and integrity of the user does not matter. What matters is some form of verification of the cause of a breach, because this single post presents no useful evidence for determining the cause of the breach, most especially ruling out over-the-shoulder attacks. What has confounded me for a long time is this question: are there no breaches of security cameras? I can spend time in a Starbucks and always see someone enter a password into some device, I do not recall reading that a security camera system has been hacked, yet I would assign an incredibly high value to security cameras in places like coffee shops, airports, hotel lobbies, etc.
- croes 4y agoBecause that's not how evidence work. There are fewer ways to get the data than reasons why the data has not (yet) been used. You can't prove there was no breach.
- paulnpace 4y agoBeing unable to prove there was not a breach is correct because you are unable to prove there was a breach, meaning there is no useful evidence in the post. As I demonstrated in what might be called talking past the sale, there are other attacks that have nothing to do with the security of the technologies used. I don't know the person who originally stated this, but as the popular refrain goes: "security is a process, not a technology."
- cdolan 4y agoDear Agile Bits: Please reaffirm my choice to pick you as our company password manager years ago before I research the ambiguity of centralized password management and make my own decision.
- Havoc 4y agoHope this isn’t true. Only going to get a chance to sort all my stuff out post Xmas
- d_burfoot 4y agoI use my own hand-rolled password management system. Everyone told me: "don't roll your own password manager!!" Here's the thing: yes, my tool is probably less secure than a professional tool, by an order of magnitude. But it's also a far less attractive target for hackers. If you spend an hour to crack my tool, you get one guy's data. If you spend 1000 hours to crack LastPass, you get millions of users' data. The cost::payoff ratio for hacking LastPass is far better.
- ltbarcly3 4y agoRight, security advice is always given as though everyone will follow it and it has to work for really useless dummies that don't understand anything about it. They also say not to roll your own encryption, but if you encrypt your data and then use ssl it does increase security. When there is some bug meaning your ssh key was easily guessable (happened with dsa keys) having that obfuscation will prevent bulk collection from doing things like keyword matching against your data. Doesn't work if everyone does it, but it does work. Most of the time you gain the most not from state-level impossible to break security, because most of the time you aren't trying to defeat a room full of geniuses all working full time with you as a target.
- cma 4y agoOn the other hand you see things like people xor'ing with the same random number stream twice, causing things to be encrypted to plaintext.
- taylodl 4y agoNot only that but there are security best practices you can follow when rolling your own that can keep your data reasonably secure. Enough so that the cost::payoff ratio is even worse and you're that much less likely to be hacked.
- pmontra 4y agoYou can use one of the several password managers of the keepass family. They are local, you can share the encrypted password database with your other devices and maybe it has more features that one's own password manager. But by going DIY you probably learned more about passwords management than the average person.
- rwmj 4y agoBeing completely ignorant about how this works, why would a LastPass compromise result in passwords being exposed? Surely they themselves don't store unencrypted passwords, but instead the passwords are encrypted by the user's key? Or is this a compromise of the locally installed software?
- g_p 4y agoThe passwords are encrypted by a per-user key. That per-user key is derived from a password through a password based key derivation function (PBKDF). In essence, an iterative hashing function. Many users don't use "good" passwords, so you use a high number of iterations on the KDF, to make it harder to brute-force an account's password. Lastpass initially used 5000 rounds of KDF for old accounts. That's not a lot, especially today. They increased it over time to 100,100 iterations (which is better). The data stored in a password vault is encrypted by a per-entry key, derived from this user password. If a user's password is weak, predictable, re-used, etc, then attackers now have an opportunity to decrypt the contents of their vault. Up until now, attackers generally have been assumed to not have access to user vaults, as that requires authentication (maybe including MFA). No local software has been compromised, but getting a hold of the server-side backups makes it possible to try to brute force user's passwords in a way that was prevented by server-side rate limiting and MFA. There is also some side information leakage from the server-side copies of users' vaults, like the URLs of websites in a given vault not being encrypted, and vaults being tied to user identities and contact info. This tweet thread suggests/implies that at least one user has had a password compromised from information held in an encrypted vault. There's no evidence yet of a compromise of the locally installed software, but it emphasises the importance of changing passwords, moving to new wallets if seeds were exposed to Lastpass etc.
- tanepiper 4y agoSeems nothing of value was lost though.
- somewhat_drunk 4y agoPassword managers should be offline. I use keepass and sync the key file across all my devices using a cloud service. Works great and is the probability that my key file will ever be compromised is very close to zero.
- aaron695 4y ago[dead]
- andrejodc 4y agoIt is highly unlikely that the attacker was able to crack the encryption. It's also highly unlikely that Lastpass had an unencrypted copy of the vault. However we know that all URLs are not encrypted which allows to identify users who have accounts for particular services e. g. cryptocurrency websites. The attacker could mount targeted attacks only on these lastpass users to reduce the risk of raising red flags. For example the attacker can send very convincing phishing mails to target these individuals with 0-day exploits. But an alternative much more scarier scenario could happen if the attacker found a way to extract the lastpass master password by injecting malicious code into the lastpass extension of targeted users. The possibility of this scenario depends if there is a way for lastpass servers to inject code into the browser extension.
- PhiLambda 4y agoI tend to stay away from centralized password managers like last pass too risky and too big a target. I use and recommend KeePassXC for local password management. This is a similar problem to keeping your crypto on a centralized exchange vs in a cold wallet. There are trade offs to doing it this way, but to me it is the best and most secure option. I rather control my passwords or keys than some company.
- helloworld11 4y agohah. For years I've been telling people I know to NEVER trust all their security to one-password services. Given so many tech companies penchant for playing stupid and loose with internal security without customers even being aware of it, this kind of thing was bound to happen. All the worse to trust a password vault service under the circumstances. Too many people who should know better on this site itself kept recommending things like Lastpass... Incredible.
- docandrew 4y agoI’m wondering if leaving the URLs in plaintext was actually a good idea, here’s my reasoning: With _random_ passwords which most LastPass users probably generated, the attacker has no way of knowing if a key resulted in a successful decryption unless they login to a particular site. If the URLs were part of the encrypted payload though, a quick string check for “http” or “www” would tell them if a key was correct or not during their brute-force attempts. Maybe a silver lining?