4 ms·
I agree: LastPass has been hot garbage for many years but it still has a significant presence, some guy’s low-value crypto wallets would not be the first we hea
by phphphphp 4y ago
I agree: LastPass has been hot garbage for many years but it still has a significant presence, some guy’s low-value crypto wallets would not be the first we hear about a compromise of LastPass vaults. There are entire companies using LastPass for critical systems.
I absolutely believe it’s possible that LastPass has been compromised more than they’ve let on and I won’t be surprised if we eventually find out vaults are vulnerable, but I don’t believe this is how it would play out.
Sunday the 18th is conveniently around the time of the latest announcement, but not the time of the actual hack. Feels like someone is over fitting.
- P5fRxh5kUvp2th 4y agoThis attitude is why a poor person will effectively be put in debtors prison and no one bats an eye. It requires "someone important" before people think maybe it actually happens.
- MBCook 4y agoBut if you had a ton of credentials from people, scanning for crypto credentials and trying to use those may be easier/faster/safer to turn into money than system credentials to some random company network.
- phphphphp 4y agoIf the hack of LastPass happened yesterday, sure, but it happened months ago. There are a variety of different attacks that could be executed in that time, and the sooner the attacks are executed, the better — because less time for credentials to be rotated. I find it implausible that the first hint of vault compromise comes 4 months after the hack and is against a low value cryptocurrency wallet. Especially considering that when LastPass first had issues, there were dozens of people reporting personal experiences of it here on HN — if LastPass vaults are compromised, the internet would be flooded with reports.
- MBCook 4y agoOh I didn’t realize the compromise was months ago. I thought it was recent. Good points.
- JimDabell 4y agoI largely agree with you, however it may also be the case that the attackers have been working on cracking vaults quietly since the hack and the announcement made them go after everything they had cracked so far instead of continuing to work quietly. They might have decided the crackable vaults don’t rotate credentials within them often, but it becomes much more likely after the announcement.
- berniedurfee 4y agoWasn’t there also source code stolen? The time might have been spent analyzing the source code for vulnerabilities in the way the vaults were being protected.
- paulpauper 4y agoyes, this. crypto is the fastest to convert to cash
- smeej 4y agoThey weren't really credentials, but keys. Pop those into any compatible wallet and you control the money now. If someone had put the key in the URL field (because there is no corresponding URL because it's not a credential), and the URL field was unencrypted, that could account for it.
- isthisthingon99 4y agoI suspect people use secure notes to store crypto keys.
- smeej 4y agoYou would hope, but I've been working in customer/technical support in the crypto industry since early 2017. People are not remotely as careful as you would expect (and hope for) them to be.