9 ms·
Cracking encrypted LastPass vaults
- EMM_386 4y agoYes, I too cracked most of my university's passwords on a UNIX system using a dictionary and a tool in 1995. There really isn't anything new here.
- lynndotpy 4y agoThis article is valuable because it demonstrates how to get the password out of Lastpass. Figuring that out is the majority of the human effort.
- xvector 4y agoGood tutorial. This is why I prefer 1Password, as it requires the secret key to be compromised in addition to the Master Password, thus providing protection against a weak master password. I've always thought it foolish to recommend solutions like LastPass and BitWarden, which don't require a secret key. It is dangerous design, prioritizing ease of onboarding over actual security. The average consumer needs an autogenerated secret key. It provides entropy where the user will refuse to. Everyone I have helped set up a LastPass or Bitwarden account have chosen simple passwords, and are extremely resistant to the point of anger if you make them choose a complex one. After a few weeks, my mother changed her complex password back to a simple one behind my back - the only time she's learnt computer functionality on her own. 1Password's whitepaper, IMO, also shows that it's ahead of the game in general. I wasn't surprised when LastPass was hacked - indeed, I've been expecting it for years - poor software quality and bad security choices were the red flags. Hopefully this forces BitWarden and LastPass to change and introduce generated secret keys in their account creation phase.
- creativenolo 4y agoI thought 1Password and LastPass were equal. Then I was asked to use LastPass still can’t believe how crude & crap it is compared to 1Password (even before breaches.)
- deleted 4y ago[deleted]
- dividedbyzero 4y agoI just logged in to delete my dormant free account – turns out I'm in a "Premium Trial" that I definitely never signed up for and never received any communication on. What happens when that runs out? No way to find out. And their UI hasn't improved a bit, they really try hard to be as unattractive as possible. Good riddance.
- CommitSyn 4y agoAs a LastPass user (that hasn't logged in since ~2015 :-/ ) can you explain the difference please? > This is why I prefer 1Password, as it requires the secret key to be compromised in addition to the Master Password, thus providing protection against a weak master password.
- selykg 4y agoWith 1Password you also have a randomly generated secret key. As I recall it’s a 128-bits, but could be wrong. To access your vault an attacker will need both your master password and the secret key. These are effectively combined to generate your keys for decryption. This protects against an attacker gaining access to 1Password servers. They can’t control whether you chose an awful password or not. So to protect them the secret key adds a ton of protection for those with weak, reused, or compromised passwords. Even in those cases an attacker needs to guess the secret key alongside the awful password. Using both the secret key and a strong master password is basically the equivalent of making a vault incredibly secure and, uncrackable using todays technology. This does not protect against local compromise of a device of yours though, as the Secret Key is stored on device and is accessible. This prevents you from having to type it every time.
- pecheny 4y agoSorry, I don't get it. The secret key has to be stored somewhere, right? If it's on the server, the attacker gets it together with the vault. If it's on the client, then you lose your phone → you lose your passwords, which is, while secure, very risky and I wouldn't expect it from a company focused on regular customers.
- poglet 4y agoIt sounds like a public and private key pair, like in asymmetric encryption or public-key cryptography. The private key is stored on the client. The private key and users password are both required to authenticate against the public key stored the server. An attacker would have no success with a dictionary attack (used in the article). Even if the password was in the dictionary, the private key is still missing.
- nix23 4y ago> Good tutorial. This is why I prefer 1Password, as it requires the secret key to be compromised in addition to the Master Password, thus providing protection against a weak master password. Do you know that or do you just hope they do what you think they do?
- massysett 4y agoUltimately I trust that they do as they say, which is necessary to any modern computer use. The same way that I have to trust that my OS vendor is not stealing everything I have.
- nix23 4y agoYes true, attack surface is already big enough, lets upload our passwords into the cloud...cant be much worse...oh wait...
- xvector 4y agoIt's literally part of the vault creation flow.
- nix23 4y agoSure you think that, but is it the reality?
- mdaniel 4y agoThey do what any reasonable security company does, and call in vendors who have negative incentive to lie: https://support.1password.com/security-assessments/ https://support.1password.com/security-assessments/ I was especially impressed by the Cure53 ones, where they were provided access to the source code: https://bucket.agilebits.com/security/Cure53-1PW18-report.pdf https://bucket.agilebits.com/security/Cure53-1PW18-report.pd...
- imiric 4y agoSo your more secure solution involves using... another, stronger, password? How would your mother use 1Password if she now has to remember _two_ passwords? Both LastPass and Bitwarden (and 1Password) support 2FA. This isn't a solution that will have mass adoption, but the UX is much better and more secure than using a secret key. It could even be used by non technical users, depending on the device. But password managers aren't a solution for digital identity. They're a hassle to use and a huge security risk, especially centralized ones. What we need is a solution that is more secure, but crucially also easier to use. The industry has been trending towards passwordless solutions for years now (OTP, FIDO, WebAuthn, etc.), and the current passkey iteration by Google might be something that could have mass adoption. Assuming you trust Google, but the technology seems sound. We still might want to use secure storage for other data, but that's a much more niche use case that can be secured with existing MFA solutions, and doesn't have to be as user friendly as identity management.
- prmoustache 4y ago> Both LastPass and Bitwarden (and 1Password) support 2FA. AFAIK it doesn't help if your vault is in the hand of someone who obtained it from a security breach on lastpass/bitwarden side.
- dividedbyzero 4y agoThat's where 1password's security key helps because you need that for decryption. Apps will store it so you really only need it once when setting up a new phone/computer and you can transfer it from another via qr code, but if all you have is a vault dump, you're out of luck even if you phish the password (which should be easier than phishing the security key since it's used a lot and in muscle memory)
- deleted 4y ago[deleted]
- xvector 4y ago> How would your mother use 1Password if she now has to remember _two_ passwords? She doesn't have to remember the secret key. She prints out copies and puts them somewhere safe. > Both LastPass and Bitwarden (and 1Password) support 2FA [...] the UX is much better and more secure than using a secret key No. Please don't make statements like this if you're not certain. 2FA confers zero benefit in a breach like this one. It is merely an access control, and doesn't provide any cryptographic benefit. Secret keys, however, make such a breach basically worthless. No amount of rainbow table usage or master password compromise will help you unless you can obtain the secret key.
- 404mm 4y agoNice break down and explanation! How does 1P compare to built in keychain (Apple devices) when it comes to security? My guess is that there’s encryption key for the vault and private key for access? I’ve been using 1P for family secrets for a while but I’m grieving more and more frustrated with frequent technical issues (unreliable sync, browser extension loses connection to 1P and has to be restarted). And I’m considering switching to OS built in keychain and maybe 1P personal for family shared secrets?
- gillesjacobs 4y agoA bit disingenuous to not discuss the strength of his master password, but a good demonstration for some who still trust LastPass's very disingenuous communication.
- xvector 4y agoThe problem is that most people will choose simple master passwords. By not requiring an autogenerated secret key, LastPass prioritized ease of onboarding (=increased profits) over user security, and now the average consumer will be facing the consequences.
- speedgoose 4y agoAn old Dilbert on this topic: https://dilbert.com/strip/2007-11-16 https://dilbert.com/strip/2007-11-16
- xvector 4y agoExcept using a secret key doesn't increase the day to day difficulty of using the tool. In fact, it makes it easier.
- speedgoose 4y agoHow do you store the secret key? In your head? In a physical device you must carry around?
- ziml77 4y agoOn a printout and even inside the vault itself. You only need the key the first time you unlock the vault on a device. After that the key can be encrypted locally with just the master password or kept in the TPM (or the platform's equivalent).
- speedgoose 4y ago
- RheingoldRiver 4y agoSo, if my lastpass master password is actually secure (~30 characters and contains capital, lowercase, symbols, and a long string of randomly-generated numbers that I memorized as part of it, and no part of this is reused anywhere else), do I have to worry? It does seem like a good idea to switch, but do I have to switch urgently?
- xvector 4y agoYou probably don't have to worry. The main concern is whether LastPass has also faced a supply chain attack that will expose you to a malicious client that will leak your passwords post-decryption.
- Proven 4y ago[dead]
- isthisthingon99 4y agoI'm surprised this isn't being discussed more.
- prettyStandard 4y agoThere was some discussion about this with the original report of the hack, less so now. I suppose because we didn't get extra details suggesting that.
- snowwrestler 4y agoSwitching to a different password manager now would do nothing to address the concern that someone has an older copy of your password database and has cracked it. The way to address that particular concern is to change the passwords of all your services themselves. If you do that, it would a good time to change password managers too—just save the new passwords in the new manager. Another approach would be to turn on MFA for your services, if you have not yet. Then even a cracked password will not be enough for a bad guy to get in. All that said, if you have been using a long and complex master password, it’s unlikely that it could be successfully decrypted in the first place.
- alin23 4y agoLooks like the XKCD way of generating passwords is not as secure. After all, it decreases entropy by a whole lot if 30 characters can be dumbed down to 5 English words with dashes/spaces/periods between. So it’s kind of like using 5 characters from a much larger alphabet (the English dictionary) instead of 30 from a 26 letter alphabet.
- ajkjk 4y agoThe XKCD method was always aware of that, the point is that it's more entropy anyway.
- xvector 4y agoThe English dictionary has about 170k-1M words, and taking the log_2 of that gives us about 16-20 bits of entropy per word. Depending on implementation, we have anywhere from 80 to 100 bits of security. Even on the low end, it should take well over a decade if LastPass chose a good cryptographic hash function with a high iteration count. The problem is that no average person is gonna use a password that long to begin with.
- nerdawson 4y agoI think the other problem is that when people are thinking up “random” words on their own, they aren’t pulling from the English dictionary. Common vocabulary is a much smaller set.
- Ekaros 4y agoAbout 20 000 active words is my understanding. And then the words people pick from is likely from fraction of that.
- prmoustache 4y agoYou don't have to pick all words in the same language. Most people know at least 3 languages well enough. I often make passphrases out of 5 to 6 languages.
- bedatadriven 4y ago> I downloaded the popular rockyou.txt wordlist and put my actual vault master plaintext password inside Note that is NOT a demonstration of being able to crack an encrypted LastPass vault. The author's exercise wouldn't be feasible without prior knowledge of the master password, or choosing a master password that is present in a list of common passwords. That is consist with what we have heard from LastPass so far.
- poglet 4y agoAgreed, it was a bit disappointing to get to the part where the password was added to the word list. The author does point out that a 2,000,000+ hashes per second could be achieved so it might give insight into how quickly all accounts will be checked against popular word lists. If I was a last pass customer I would be thinking about changing passwords on all accounts.
- agilob 4y ago2,000,000+ H/s on macbook. I heard GPU clusters built purposely for quick hashing got cheaper recently.
- II2II 4y ago> Agreed, it was a bit disappointing to get to the part where the password was added to the word list. Why is that disappointing? It is a proof of concept, rather than evidence that it has already been done. Sure, it is not novel and perhaps it is overstated, but it does point out that attacks are already possible. It would also be interesting to see the results of a dictionary attack to see if the behaviour of people who use password managers is any better than the population as a whole.
- gchadwick 4y ago>I downloaded the popular rockyou.txt wordlist and put my actual vault master plaintext password inside I was hoping for an exploration of how quickly one might crack a lastpass vault looking at different strength passwords and different iteration counts. Instead the author has simply demonstrated that if you tell the cracking tool your password it can indeed crack it... I guess you can at least follow what they did with your own vault without adding your password to the word list and see if it cracks quickly or not.
- janebrown456 4y ago[dead]
- agilob 4y ago> if you tell the cracking tool your password it can indeed crack it... It's called "dictionary attack", but author wasn't bothered doing full brute-force attack or masked attack. It's a demonstration that a laptop can reach `2,000,000+ H/s`.
- resill 4y agoActually, he said his laptop maxed out at 1110 H/s. He then said that using multiple GPUs one could likely achieve 2 MH/s and higher.
- Stagnant 4y agoThat statement sounds a bit exaggerated to me. A 4090 can do ~15000 H/s, to reach 2 MH/s would require well over 100 4090's, it definitely isn't as easy as the author claims.
- sigmoid10 4y ago>It's a demonstration that a laptop can reach `2,000,000+ H/s`. No, the author says their laptop only reaches ~1kH/s. That 2 million number is a pure guess for a multi-gpu setup and that is still pretty weak, unless you have a very good dictionary for a specific target. Brute forcing remotely long alphanumeric passwords is out of the question. So if you have a 8+ character password with upper+lowercase characters and digits that is not close to a real word and was never used anywhere else, you should be perfectly fine after this breach. Only if you have a really shitty password or if you reused it you should probably do something.
- shrx 4y agoReminder to never use pixellation to obfuscate sensitive data: https://github.com/bishopfox/unredacter https://github.com/bishopfox/unredacter
- simooooo 4y agoSomeone reversing that out of this stupid article would be more interesting
- Proven 4y ago[dead]
- IshKebab 4y agoThat would be a lot more convincing if they had a blind demonstration. As noted in the readme, getting the CSS exactly right is both critical to making it work and extremely difficult. I'd wait until someone actually uses that software successfully in anger before we declare that you should never use pixelation. Obviously black bars are better but sometimes you don't care that much about keeping the data secret.
- crazygringo 4y agoIf it's a pixel-perfect screenshot, getting the CSS right is actually extremely easy as long as there's surrounding text. It's easy to recognize a font, easy to figure out its size, and easy to figure out the coordinates. No more than a couple minutes of trial and error. It's only difficult if it's been resized+compressed lossily, if it's a photograph of a screen, etc. And since font rendering can be different between Windows and Mac, you might have to try it on each one for a perfect match.
- IshKebab 4y agoThis screenshot looks pretty pixel perfect. Maybe have a go if it's so easy!
- ziml77 4y agoI wish image editors would come with tools specifically for redaction. A solid colored box works but it's ugly or makes it hard to tell that there was anything written there at all. What could be better is adding noise that matches the dominant 2 colors of the selection and focuses near areas of contrast. Then you can apply the pixellation on top of that and get something that's tougher to reverse. Alternatively, it could try to recognize where the text and replace it with a string of random characters that are around the same size. In that case there would be absolutely no way to get back the original text since it's gone before the pixellation is even applied.
- iinnPP 4y agoDoes anyone have a good source on brute force and what is and isn't a good idea? I came across the below in a rather important website and am wondering if I should push harder for the to change it. How secure is a randomized 5 digit pin where you get unlimited guesses but after 10 guesses the pin is reset? Guessing the pin correctly gets you enough information to open a bank account. Assuming a system like the above exists, would you consider it a security vulnerability?
- hsbauauvhabzb 4y agoWhat does the system hold? Your library loan history or nuclear weapon launch codes? Assuming it’s reset every 10 attempts, you have lost keyspace and gained random odds. 1:1000000 of getting the password right, 1:500k on average. Assuming I can perform one attempt per second, about 139 hours to successfully brute force a single account. One second is probably pessimistic, most systems are capable of serving much higher rates. Unless you have fail2ban or MFA, consider the pin a formality.
- iinnPP 4y agoThe pin is the MFA. Is it 1000k or 10k (99999/10 guesses)? I can't give full details of what is within accounts without potential exposure of the company. So I called a local bank and asked what I needed to set up an account. All the information required was part of a potential breach. Is there a rate limit where protecting information with 5 digits is ok?
- hsbauauvhabzb 4y agoI would say 1m, rather than 10k, as the value rolls every 10 attempts, the true odds are slightly less than 1:1m, but only because every 9th attempt is 1:(1m-9) and 8th is 1:(1m-8), this is a minute difference. Rate limits and account lockouts create accessibility and availability issues, I’m not aware of any real world case studies where they have been abused, my guess is demographics are important (a student is more likely to do it to a school rather than a random on the street doing it to a finance company). Though, if usernames are possible to enumerate, you should still consider the risk of someone doing it at scale as a dos. What is / is not okay is probably largely defined by any security frameworks that you’re required to adhere to - in Australian Gov there is the Information security manual (google ISM ACSC). It states that password complexity goes up if you do not have MFA, and that without it credentials should be 14+ characters long. Given your assertion that a breach would be possible, I would strongly suggest that your current methodology is dangerous. If you can enumerate usernames doubly so. Are you able to script a proof of concept brute force? Tools like hydra do this, but I prefer python3/requests.
- hsbauauvhabzb 4y agoI vaguely remember recovering a LastPass vault with email confirmation in ~2015, that would be a glaring security hole so maybe my memory is wrong, can anyone confirm that I’m totally wrong and that LastPass don’t have a back door into all accounts?
- jalapenos 4y ago> otherwise it would take 6 hours+ to crack Ok, can you run it for 7 hours without your password in the list and let us know?
- sylens 4y agoThat did stand out to me as a pretty small amount of time to not just let it run normally In my pentesting days if we dumped the DC at the beginning of a test we would let that run in our password cracker GPU machine for days to see what hits we got
- lvncelot 4y agoGiven that a four word password should have around 44 bits of entropy (according to the correct horse battery staple XKCD), that should take 2^44 hashes to exhaust, or 2^43 hashes to have a 50% chance of getting the password. 2^43 hashes / (1000 hashes per second) are about ~280 years. That's a big "+".
- sinuhe69 4y agoThere is always a potentially critical vulnerability in any centralized password storage. Especially, if it requires a (relatively) simple master password to access. A many factors system like the one of Apple is IMO more secure but also easier to remember because they are all pin/passwords one needs (almost) every day.
- malepoon2 4y ago1Password is also inherently more secure because of the extra Secret Key. If a breach like this ever happens to them, users with weak master passwords will still be safe. Also, Lastpass doesn't encrypt URLs. There's really no excuse for that.
- therealdrag0 4y agoWhat is the extra secret key and why is it better?
- lvncelot 4y ago> I downloaded the popular rockyou.txt wordlist and put my actual vault master plaintext password inside (using a quarter of the wordlist), otherwise it would take 6 hours+ to crack. I don't believe the 6 hours+ claim. (Or rather, the "+" is doing some serious lifting in that sentence.) Looking at the password, it's of the correct-horse-battery-staple variety, which could be conservatively estimated at 44 bits of entropy (this is even ignoring the additional number appended to a random word) - which would take even the described "multi-gpu" setup with 2 million hashes a second just about 100 days to exhaust (or 50 days to have a 50% chance of getting it), let alone the 1000 hashes a second macbook the author was using.
- gvb 4y agoYour quote includes the most significant part of the article "and put my actual vault master plaintext password inside". He took a word list which did not include his password and put his actual password in the word list. He didn't crack his password, he showed that a brute force password guesser can find passwords that are in its word list. If he wanted to save six hours, he could have put it first in the password list. No news here.
- birdyrooster 4y agoGood article is good, it shows brute force works with brute force.
- lvncelot 4y agoYes, which is why I'm so skeptical of that claim. "I've put the password in because otherwise it would've taken 6 hours" makes no sense at all - even putting aside my napkin calculation; if it would've taken an afternoon of crunching, why wouldn't you just have done that?
- dylan604 4y agobecause 6+ hours is too hard for a 140 char limit generation of people looking to get internet traffic to a blog while the content is still fresh in people's minds posted before anyone else does it.
- perihelions 4y ago- " Attackers on the other hand can leverage multi-GPU device setups with optimised drivers that could easily reach speeds of 2,000,000+ H/s." Why wasn't LastPass using memory-hard key derivation functions? I thought that's been best practice for a very long time now: we've known about GPU/ASIC hashing for decades.
- oefrha 4y agoWhere’s the ASIC cracking 100,100-iteration PBKDF2-HMAC-SHA256 at 2M H/s? Let alone GPUs. TFA pulled that number out of nowhere.
- upofadown 4y agoThis is an obvious demonstration, but I think still an important one. Lastpass has said this about the breach: > These encrypted fields remain secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user’s master password using our Zero Knowledge architecture. That all sounds great but the number of bits of AES and the cool "Zero Knowledge" designation is completely irrelevant here. It entirely depends on the strength of the user supplied password. So if your password is weak you are in trouble. The other message here is that if your password was installed before 2019 it is probably going to be a lot easier for an attacker to guess. That's it, that's the whole thing, but it still needs to be shown...
- paulpauper 4y agoSo how was the other guy's account cracked? https://twitter.com/cryptopathic/status/1606416137771782151 https://twitter.com/cryptopathic/status/1606416137771782151 this should not be possible to bruteforce
- albertopv 4y agoI hoped for something else in the end of the article. I use a local only password manager with automatically long (generally speaking, some stupid services limit password length to ridiculous short value) random generated passwords, which I don't know myself, it still seems to me to be best approach.