7 ms·
One of the most frustrating things about the LastPass leak is that they still haven't provided all the information needed to determine whether a customer is at
by andrewmcdonough 4y ago
One of the most frustrating things about the LastPass leak is that they still haven't provided all the information needed to determine whether a customer is at risk.
For example, it's clear backups were stolen, but they won't say how old the backups were, or what their retention policy is. So even if you changed your password to a stronger one, with more rotations, it may be that the attacker got hold of very old backups with weaker security. I've asked their support team for information about time windows of backups stolen, if they have a retention policy and whether it was adhered to, but they won't share that information. Instead we are left with a blog post that is more than a month old, no recent updates, and questions remaining unanswered. I'm a paying 'enterprise' customer, and they are meant to be ISO270001 compliant, so a retention policy should be a pretty simple thing to share.
- bombcar 4y agoEven if you change all your pssswords NOW you’ve still had the metadata of where you have accounts leaked.
- ShredKazoo 4y agoIn principle, your passwords might be stored as a JSON blob encrypted using a key derived from your master password. In which case that metadata could still be secure. I doubt it though.
- lolinder 4y agoLastPass already admitted that the metadata was all leaked. Usernames and passwords were encrypted, but all else seems to have been in the clear.
- ThunderSizzle 4y agoBased on what happened to my wife, if the password was encrypted, breaking it was trivial
- lolinder 4y agoShe probably had an account that had a very low number of iterations. LastPass never updated those unless someone knew to do it manually, so if it was an old account she likely had 5,000 iterations out of the recommended minimum of 100,000.
- william_T 4y agojust checked, mine is 5,000
- lolinder 4y agoYep. And the sucky thing is that the only recourse at this point is to reset all your passwords, because what was leaked was the low-iteration vault. Changing it now only saves you for future leaks.
- trogdor 4y agoI believe that my vault was similarly-low iteration, however my master password was an approximately 30 character string that contained no dictionary words. Based on your understanding, does my master password length sufficiently mitigate the low-iterations, or is decryption a realistic possibility?
- lolinder 4y agoI don't know enough to know. I'd change your passwords just to be safe.
- kadoban 4y agoIf your master password has enough entropy, you're safe with 1 iteration. It's not a great idea, and what "enough" is can be ambiguous. But if your master password is provably 70 bits of entropy or so, you should be fine. But it's probably easier to just change your passwords anyway. At this point I wouldn't be suprised if the story gets even worse somehow.
- selykg 4y agoAt this point you should assume you're breached. If they aren't going to give you the details, you should assume the worst. I have asked all of my team to change their passwords. We use LastPass via our parent company and will be switching off LastPass soon for our team. LastPass never would've been my choice, it was made before I joined. But assume you're breached, change it all now, and ideally you're not going to stay with LastPass. Their communication sucks, which is just icing on the cake in this entire situation.
- porter 4y agoWhat would your choice be?
- paradox242 4y agoThis was also the final straw for our organization, we have initiated a company-wide reset of any credentials stored in in their service (thanks, LastPass) and are definitely not going to be renewing. The frequency of recent breaches, and especially the opaque manner in which they have been handled have destroyed any credibility they may have once had with regard to being trustworthy enough to store important secrets.
- panarky 4y ago> definitely not going to be renewing That reads like you're resetting credentials and then putting the new credentials back in LastPass, and then possibly maybe moving away from LastPass at some point in the future. Given how little LastPass has disclosed, and the negligence we already know about, we should not only assume we're breached, but we should also assume LastPass is still storing critical data in cleartext, they don't have a "zero knowledge architecture", and their systems are still vulnerable to intrusion and exfiltration.
- deadfece 4y agoExport from LP and start migrating, starting with changing common social IdPs like Google, Facebook, Twitter, Github, Apple, Microsoft/Live/Xbox/Outlook. Update the password of remote access programs like Parsec, and your cell phone provider's password. Then go through your TOTP generator and start changing everything in your TOTP generator (especially since you might be using LP Authenticator - if you are, then move to a different authenticator at the same time). Next: banking, your work payroll, investment accounts, Tax/IRS, shopping. From here one out start going through the list by the amount of money involved. If you doubt that then go through them ordered by the amount of data involved. If you get lost and stuff seems too hard, if your replacement product lets you sort by age then just sort by oldest and hit 5 today. Hit 5 more tomorrow. Keep chipping at it. At this point you might as well change one every single day.
- vasco 4y agoThere's ISO compliance and there's ISO "compliance". I'm pretty sure if most shops were honest they wouldn't be compliant, but more like compliance-inspired.
- bee_rider 4y agoISO compliance, a la “banana” or “strawberry” flavor.
- tallanvor 4y agoHonestly, even before this latest update, it's safest to assume that your data will be decrypted at some point, and get started changing everything now. Luckily I had already switched over to Bitwarden, but I still had around 250 accounts to go through, although about 40 entries ended up being duplicates, defunct sites/products, or so old that the accounts were already deleted due to inactivity. If you haven't started rotating all of your credentials already, this news should definitely get you started on it!
- adamsb6 4y agoI never expected I'd experience such joy at a website failing to load, or to see it had been turned into a completely different business that doesn't even have a login form. Thanks, LastPass!
- slantedview 4y agoI did the Lastpass->Bitwarden migration around Christmas, and it was probably 6 hours all told just changing passwords for the accounts I administer. The good thing is, you get pretty fast at changing them after a while.
- nicce 4y agoIf you are in EU, according to GDPR, they should share information so that you can evaluate the risk. Otherwise they are breaking the law.
- _fat_santa 4y agoThe title should be updated to reflect that this wasn't data from LastPass but from other products under the Gogo umbrella. > Our investigation to date has determined that a threat actor exfiltrated encrypted backups from a third-party cloud storage service related to the following products: Central, Pro, join.me, Hamachi, and RemotelyAnywhere.
- deleted 4y ago[deleted]
- burnte 4y ago"One of the most frustrating things about the LastPass leak is that they still haven't provided all the information needed to determine whether a customer is at risk." Yes they have. They had a breach, and lied about it. You can't trust anything about them now. Assume a total breach and move on.
- phpisthebest 4y agoThe biggest problem here is for former customers. What if you closed your account 5 years ago, did they still have backups?
- sedatk 4y ago"Assume total breach" implies to update everything you had with them regardless of the timeframe.
- phpisthebest 4y agoI assume for many people that is easier said than done
- sedatk 4y agoIt is, hence the gravity of the situation.
- phpisthebest 4y ago>>they are meant to be ISO270001 compliant means that some auditor, met with someone that does not know anything, and checked boxes in a form.
- emodendroket 4y agoDo they even know?
- Calamitous 4y ago> One of the most frustrating things about the LastPass leak is that they still haven't provided all the information needed to determine whether a customer is at risk. Worst case: it’s entirely possible they don’t know.