Should you be concerned about LastPass uploading your passwords to its server?
palant.de
palant.de
My $.02: Given that all the cloud-based password managers have their own phone (and even desktop) apps, this seems like a moot point since a bad actor could push out an app update that does anything with your keys anyway.
As a long-time LastPass user I appreciate this kind of analysis, but this is just not something I have enough cycles in the day to let bother me. BTW the last time I opened my preferences was 3 years ago. LastPass is quite open to scrutiny and what's important is how responsive they are to new findings -- very responsive, from everything I've ever seen. Including many findings from the author of the article.
By far the biggest problem with LastPass is that it sometimes just doesn't apply (or misapplies) the password or username to the appropriate form entries, and I have to go find it and copy it. Occasionally it also misses the saving of a new password (that it generated) and I have to put it in the vault by hand. I suspect this is a really hard problem given the massive variety of forms out there, but would be curious to hear if other password managers never have these issues.
For a year or two, lastpass for Firefox didn't have the copy option for usernames and passwords. I had to edit, show password, then copy.
The autofill problem became pronounced after the acquisition as well probably through no fault of the new owner. Many sites like Google and Microsoft have switched to a multi-step login process where username is entered first and password is entered on a different page
Also a proof of sites abusing autofill & hidden forms to steal passwords probably influenced the current situation.
UP (uncle post) mentions a home-made Android app to sync... is there a more mainstream option?
password-store uses git+gnupg so backing them up is a matter of distributing the git repo. My git repo lives on each of my laptops and I have a 'central' host of it...so it's backed up via distribution.
For getting passwords to my phone I use a homemade Android app + small web app that sends them to my phone encrypted on-demand from my laptop or desktop. There are Android apps for using password-store but you have to put your GnuPG keys on your phone for that and I prefer not to do that.
(Now I just stopped holding my breath. Ah, breathing is good!)
But overall, yeah, it has been better than LastPass.
Go to a site with saved passwords e.g. http://news.ycombinator.com
Lastpass icon changes to show you have an entry. Click the icon, click "Show matched sites." Hover over the entry and you'll see three buttons: Copy username, Copy Password and More options.
I'm assuming these buttons don't work for you. Right-click instead on the entry and you should see a menu with the following items: Autofill, Copy username, Copy password, Copy URL, Go to URL, Edit, Delete.
Try the copy password entry. Hope it works for you.
Years ago it was Hamachi (the LAN-over-internet software). Then it was LastPass and via it XMarks (itself acquired by LastPass shortly before). XMarks suffered much more grievously than LastPass — I suffered data losses on multiple occasions before finally throwing in the towel.
This seems to me like a great argument to avoid all cloud based providers and their mobie apps. Especially when opensource, time tested, self-hosted solutions exist.
You seem to be more concerned about UX than security. Compromising security for better comfort is not a very good strategy.
From my practical observation: People will go to great length to avoid dealing with a crappy UX. That can include falling back to "YOLO, I'll just use the same password everywhere" if the password management process is sufficiently atrocious. So I'd say good UX is part of the security concept, bad UX will compromise it.
Maybe, but a good UX goes a long way to convincing people to use the solution. The best security solution is the one you actually use.
This approach is exactly why the vast populace has essentially no security. I'd be glad if my parents were to switch to last-pass, as it is so much better then weak password re-use schemes.
I'd say that compromising security for comfort is a given, its guaranteed to happen. The best strategy here is to make sure that users will have the most security after the compromise.
People are reusing passwords and writing passwords down on post-its specifically because they haven't found sufficiently UI friendly options of password management. Regardless if that is out of ignorance of available options, UI not being friendly enough for them, or some other technical hinderance.
A compromise isn't weighing between an ideal scenario and your current situation. A compromise is finding an optimum between value extremes in acceptable real world scenarios. An ideal security extreme is a disconnected system, but that's never something you can compromise towards since the comfort/usability reaches 0.
You're trying to move security up by getting users away from pass reusage and post-its. In this case added comfort happens to also be increased security.
Any app that gets updates is vulnerable to that type of attack.
I think a lot of people feel uncomfortable giving a proprietary product access to their passwords, and feel more comfortable doing the copy-and-paste themselves. But compromising security for better comfort is not a very good strategy.
Keepass has a third party Firefox extension that does this. Bitwarden is open source and has their own extension that does the same.
I respectfully disagree that apps are the same as webpages. The big difference is that apps are signed, so if things are done properly, you only have to trust the devs of the app and whoever operate their CI. Web pages on the other hand have no such security (yet), which means you also need to trust the cloud provider, the CDN, the fact that the website was not hacked, the ops team of the password manager, and probably anyone who is able to make a valid SSL certificate and might do MITM...
Disclosure: I work for a company that makes a cloud-based password manager.
I don't have time to really think about all this complexity and what it means for my security. So I just avoid it entirely.
The website from the service in question also suffers from severe JS-errors on their page (FF 66).
[1]something that will not likely happen between family, work, and chores around having a large property
I always manage my passwords on my computers, and type in on phones as needed. Simpler and just works.
To easy the pain of typing passwords, I always follow a consistent format that's easier. Example:
7,#/T8z%FS%zht6S
ctaq.zwjd.qnbu.ut1A
The first one is terrible to type on a little Android keyboard whereas the second is a breeze, and still perfectly respectable as far as password strength goes.
I use a few different versions of keepass on two laptops and an android, and they all share a keyfile through dropbox. I get most of the same functionality that my wife does through LastPass. It's convenient enough that I don't see any reason to migrate to LastPass, despite their much more polished user experience.
I'm forced to use LastPass at work, and personally find KeePass to be a much better user experience.
A. The auto-fill extensions don't work on enough sites to make it annoying (maybe ~20%). Auto-type is a more consistent workflow for me.
B. Lastpass (and friends) browser extension doesn't do anything for desktop apps, SSH sessions, or anything outside the browser. You have to copy and paste one at a time.
C. I like all my passwords to be a particular format because it frequently happens that I have to type them in manually (Phone, vCenter console, BIOS, etc.) and I just like that to be easy. (I use 5 groups of 4 lower case separated by periods, with one number and one upper case letter in the last group. Still very strong but also manageable to type into an iPhone).
D. I like to record more than just passwords (the email I used, answers to security questions (always random, but legit looking), bank and credit card details, stuff like that). The KeePass UI for keeping those kinds of notes is just so much cleaner, simpler, and better than anything else.
E. KeePassXC has first class support for Yubikeys.
One mitigation is to use Firefox account containers.
If I navigate to what claims to be Bank of America, but the tab doesn't open in my "Banking" container, that's a huge red flag.
Also, as another poster mentioned, Lastpass sometimes fails to autofill. Unless a manager can achieve 100% error free operation (unlikely), even autofill managers will also have a risk of phishing.
I don't think there's one correct answer. For me, as an expert who's confident about my security posture (2FA, verbal passwords for vendors that can reset 2FA, backup codes stored securely offsite), I value the simplicity of Keepass.
That is nice, but it is not sufficient mitigation for the issue to be dismissed.
There are more concerns in this article than the title issue, and it seems that in the past, LastPass has made some questionable design decisions that did turn out to have problems that needed to be fixed. I hope and assume that, prior to adopting these design choices, LastPass analyzed the risk and concluded that it had avoided creating any vulnerabilities, but nevertheless, there were some that it had overlooked.
If you continue in this manner, you are increasing the risk of creating a zero-day vulnerability that gets exploited, and I would guess that a central repository of passwords would be a particularly attractive target for bad actors. I would much prefer a security company to stay away from questionable design choices, rather than have rather complex and more-or-less tendentious arguments that the way they are doing it is safe, especially when there have been cases in the past where their arguments were not sound.
> This is just not something I have enough cycles in the day to let bother me.
Another reason to prefer KISS. If the vendor had refrained from making questionable choices that require complex analysis (such as the decision to fall back to server-provided pages for parts of the browser extension functionality), trying to figure out whether it matters to you would be less of a problem -- to the point, maybe, where you don't fall back on an "I can't be bothered" attitude.
My annoyance is lately it's become less skilled at detecting password changes properly, even when I'm invoking 'Generate Password'.
What do you mean? How are you measuring that? How do you think that would make a password of the same length and character set less secure in a practical way?
https://security.stackexchange.com/questions/77345/security-...
So it seems like LastPass-generated passwords are fine?
[1] https://developer.mozilla.org/en-US/docs/Web/API/Window/cryp...
The thing is, there is a chain of things you have to trust wrt the LP generator: Has the OS implemented the backend API correctly? Were there issues in the browser build that mess up the entropy derived from the OS seed? Has the Javascript done anything stupid?
In comparison, I have complete confidence in the entropy of the passwords I generate via CLI.
Wrt. password length: yes you can change it. But the dialog is a bit of inconvenience that tilts away from the hassle of switching to my terminal and typing "suggest-password". And I have something of a moral objection to password generators that default to insufficient entropy.
Agreed, ambiguously named form input fields cause all kinds of havok, I helped our UX team track down one in our application because it was breaking my lastpass =)
For the second issue, I've just adjusted my workflow to accommodate LastPass's peculiarities. I just click "Generate Secure Password", copy it to the clipboard and fill the form myself. Then I have a copy of the password on the clipboard should LP miss adding the site properly.
While it's a slight pain to work around that particular issue, it's far better than what I used to do with regards to password reuse.
I'm not that familiar with mobile dev, but could a rogue app just sit in the background, making a copy of whatever's in the clipboard?
Lastpass mitigates the issue somewhat by clearing the clipboard after a certain amount of time.
I think this is a good argument against cloud-based or auto-updating password managers in general.
Even including the self hosting setup, my all-in migration time was <30 minutes.
I looked through a ton of other options like keepass and the author's own PfP. But mobile, web, and yubikey support are all very important requirements for me.
Switched to it somewhat over a year ago from LastPass after I read up on LastPass’ ‘security’. The only thing I dislike about Bitwarden is that on their iOS app it sometimes takes a while (>30s) to load the search function. I love that their chrome extension has a dark mode!
https://github.com/search?q=org%3Abitwarden+exceeds+the+maxi...
So the notes fields can't store more than 10k, which isn't going to work for me at all.
Update:
Found this python script and ran it. https://github.com/bitwarden/web/issues/194#issuecomment-464...
Only had two notes that were too long. Added them in by hand. Problem solved.
https://help.bitwarden.com/article/import-data/#troubleshoot...
[0]: https://cdn.bitwarden.net/misc/Bitwarden%20Security%20Assess... [1]: https://hackerone.com/bitwarden
The same could be said for proprietary applications, which may never see third party audits because 'meh, customers have no access to our source and IP protection or something'
Which is a shame, I have reported bugs to a lot of other password managers, but will not dedicate time to one that is not paying me for it.
Sure, you can't eat that, but man does not live on bread alone.
You'd tell a neighbour if they'd accidentally left their car door open, wouldn't you? Most people would even shut the door if they weren't around. Same principle.
This is a poor example because finding bugs requires a lot more effort than giving a door a push (which I find a little spurious - I wouldn't touch my neighbours' car).
There is in practice an almost infinite amount of things you can donate time to and all else being equal (for example, they're all password managers) I doubt you'll convince most people by telling them they should do it because "it makes things better for everyone", they could be making everything better for everyone and still getting paid - that's the superior option. Even if I think you are correct.
I think, for practically everyone, it is far more likely that shared infrastructure (like LP or hosted bitwarden) would be centrally compromised. For example, this post mentioned compromising a safety check for all lastpass users by finding a single vulnerability on a single lastpass domain.
Unless you go to extreme lengths with your personal opsec, a targeted attack by a skilled attacker is pretty much sure to be able to compromise you.
(In fairness, I don't actually know if self hosted bitwarden is enough for all classes of attacks or if I should also compile the clients myself in order to remove any references to the main bitwarden domain)
I believe the opposite to be true. Any use of Shodan or any vulnerability scan of the public internet provides strong evidence that centralized, funded and focused services do security better than 99% of orgs and individuals.
You can’t run infrastructure and app security better than a specialist SaaS company. You don’t have the same time and money.
Yes, the blast radius is smaller for self-hosting, but that’s small comfort when you are still inside the blast radius.
Combining a few of the shelf components (dropbox + keepass in my case) should be easy enough to not screw up so badly it isn't worth putting your eggs in a different basket as everyone else.
Link: https://joinup.ec.europa.eu/sites/default/files/ckeditor_fil...
For example, I chimed in on github semi recently about there being a lack of automated tests and within a week somebody claimed to have decided to prioritize it. With other companies, 1) we wouldn't have known, and 2) we wouldn't ever know if it was fixed
TLDR, long term looks great for bitwarden, short term makes me a tiny bit nervous though
Edit: looks like they added 3 test files that I could find, which isn't terribly comprehensive but I assume there are more I missed on the other repos...
Another reason, It has a polished app and works flawlessly on all the platforms and I can host it myself.
Bitwarden is using Microsoft technologies. If running a MSSQL server is too much for you, you can use alternative servers which are fully compatible with the official clients:
- https://github.com/dani-garcia/bitwarden_rs - https://github.com/jcs/rubywarden
KeePass for instance lacks the ability to do just that. You can either a) share the entire database or b) use multiple databases with different passwords. However, a) is not secure as your co-workers get access to passwords they do not need and b) is very inconvenient.
LastPass (or 1Password, Bitwarden) makes sharing individual passwords within your team very easy, convenient and secure enough. You can create shared folders and define permissions to access those by certain members of your team, and most importantly, deny access to other members. Is there any offline based password manager that allows you to do that (and is usable by the average Joe)?
https://github.com/keepassxreboot/keepassxc/blob/develop/doc...
It's the superior choice to sharing an existing/personal account.
And people will do it, the best you can do is making the sharing secure.
At home, I take care of most of the bills. There are a few services where bills are under her name and account, but I need access.
The other case I've run into is at work, when the company has an account with an outside vendor rather than individual users.
- You have a social media account that a group of people should be able to access. (Facebook does this "right," in that pages don't have their own login credentials, and you go through your personal Facebook account to access the page. But I kind of wouldn't want to use my personal Facebook account for work, anyway. Twitter, Instagram, Reddit, etc. treat each account as its own log-in-able entity.)
- You have an AWS account where you want to avoid a single point of failure for the root credentials. Yes, each person should use their own IAM creds for day-to-day use, but if person X is unavailable person Y should be able to get to things. (And for casual projects, "learn about IAM" is a significant burden over "learn how to upload pages to S3" for limited benefit.)
- You have a web hosting account from someone who's not AWS who gives you a single username and password. Or a DNS registrar account (most registrars I've seen don't let you split up access). Or whatever.
- You have a shared email account for replying to things as a team, or even for just archiving emails. Again, some systems do this "right" - if you're using Exchange, you can allow one user to access another user's inbox. But most people aren't on Exchange, they're on something like Gmail.
- You have an account for some service where you shouldn't be sharing passwords according to the service, but doing so is strictly in the service provider's benefit, not yours. Netflix is the canonical example.
Even if this weren't possible, it would still be better to use 1FA than to arbitrarily pick one person to have root account access and lock the other person out simply because you "should" have 2FA.
On my work computer, I have my own personal DB and my Work DB open at all time. I mainly use the passwords for the web, and the Kee extension in Firefox and Chrome finds the right password without any problem, from both DB. I have my personal ssh keys stored in my DB as well, and Putty can access them without problem.
I can't speak for shared DB though, as I've never used it in that way.
I wish the iOS app would support tombs/vaults though. https://github.com/roddhjav/pass-tomb#readme
It also happens to be great at storing any amount of sensitive text (API keys, etc.).
It's like the phpMyAdmin of password storage.
It's usability (last pass) has been getting worse though....
I hope they took it away for a good reason, like a security vulnerability.
What's so terrible about people using better and better passwords? It's not perfect but I am so much happier with my dad using LastPass versus the shitty password strategy he had before...it was post-it note password management.
I will admit that I don't store my Google password in any password manager. That is the root of trust for everything, so I remember the password and use 2FA. The other accounts aren't as important.
Why? Google is an Ad company...
That doesn't mean it isn't ugly. People deserve better.
LassPass is ugly in a way that makes Oracle's Java download page look well-styled: https://www.oracle.com/technetwork/java/javase/downloads/ind...
This is a complete red herring - it's an argument for using password managers in general, not LastPass in particular. The issues here are whether it is being done in a way that unnecessarily compromises those better passwords.
One organization I worked with accidentally created a password manager and it looked better than LastPass. Since it grew to become a huge security risk it got migrated to LastPass, which was barely useable and, at that time, got hacked, so that's a plus, and then migrated to 1Password the instant they added group vaults.
I think it's fine to enjoy a product, but it's also good to recognise when something could be better. Anything can be better.
I don't see the fuzz here if needing to have a browser extension. When a site asks me to login every now and then, I'm ok with opening the app and copying the password.
However for many years I used just a single db for every device and didn't had a single problem with it. Started to used two, after I switched from Dropbox to iCloud on a mac and iPhone.
So I switched to KeepassXC, which allows me to have a cross-platform app, and the database is stored inside my Google Drive. I also use a security file that's kept out of the Google Drive as another security layer.
Oh, and the auto-type feature of KeepassXC is amazing. Some sites have a weird username/password combo scheme, so I can program KeepassXC to enter the correct keystrokes for a given website. Works perfectly.
For those who wonder why one might subscribe to the cloud service when one is only going to use local vaults, rather than buying a license for the non-cloud version, the non-cloud version requires separate licenses for your Macs and for your Windows PCs, and major upgrades cost a substantial fraction of the initial price.
With the cloud service one purchase covers all your devices and all major upgrades for as long as your subscription is active.
I think it worked out when I did the math almost a year ago that if you have both Macs and PCs, then the cloud came out cheaper if you assumed a major upgrade every couple of years.
I'd be more comfortable with bio-authenticating per password (though that might use more battery) and preferably asking for the password/code if you look up more than 5 passwords too quickly, but I'd rather have to trust a big company than a smaller third-party that gets acquired and sold around.
What are the advantages of LastPass and other password managers over iCloud Keychain?
KeepassX works well as the actual database of credentials.
Great, so rather than being able to access all your passwords, the attacker can only access your two personal email, company sso (including email), and two bank accounts. The rest can be obtained with password resets.
I followed some instructions and toggled iCloud keychain sync on my iPhone (just turned it off and on) and it proceeded to erase about 250 of my 300 saved passwords. Wasn't able to get to my other devices fast enough to turn off the networking - they had all already been deleted from my Mac, iPad, etc as well.
Spent an entire weekend resetting passwords - never again. I am now a happy Bitwarden user. Even if it eats all my passwords one day, at least it's trivial to export them all to CSV.
Given I haven't looked into it in a year or so... but the Dead Man's Switch alone makes it worthwhile for me. My lawyer has this, and 30 days after I kick it he can go in and delete all my accounts.
Sharing passwords with a team, it's really helpful. Being able to share access, but not the password itself... really nice feature.
The password audit, showing me how old my passwords are, or which ones are weak... it's nice to have a sanity check on all this stuff.
Anyway, been on LastPass for a decade or so... tried a few others, always find myself back with LastPass since the others don't quite have all the features I want.
How you just share access? You mean the password is autofilled?
1Password offers this as well. Not allowing the end user to reveal passwords it isn't an ideal solution. The password can easily be obtained by anyone who is capable of using the browser's developer tools. Simply inspect the input element after it has been filled and the browser will give the secret away. The only way to be sure someone doesn't have access to an account after you've shared credentials with them (even "hidden" credentials) is to change the credentials for that account.
> The password audit, showing me how old my passwords are, or which ones are weak... it's nice to have a sanity check on all this stuff.
1Password also offers these sorts of checks.
> Given I haven't looked into it in a year or so... but the Dead Man's Switch alone makes it worthwhile for me. My lawyer has this, and 30 days after I kick it he can go in and delete all my accounts.
This, admittedly, we haven't found a good secure way to implement yet. Our current recommendation is to share your Emergency Kit with your lawyer, or whoever needs access, perhaps in a sealed envelope marked to only be opened upon your death.
Full disclosure: I work for 1Password.
You'd know, is there a tool that would let me migrate all my passwords from LastPass to 1Password? I think I have like 3k passwords and the thought of manually building that DB up again is daunting.
I’ve also seen it recommended by Troy Hunt (haveibeenpwned creator): https://www.troyhunt.com/password-managers-dont-have-to-be-p...
(I’m using bitwarden myself, couldn’t justify the subscription cost for my usage)
Reply from Wladimir Palant:
Unfortunately, I didn’t make notes last time I looked into this – the issues simply weren’t serious enough for reporting. And I only looked at a small portion of the codebase, so when I look at it now it will probably be some different code paths. So the getDomain() function I see under https://github.com/bitwarden/jslib/blob/dd46d5ecdd51f91dace5... is indeed using URL objects. It also knows that tld.js won’t handle IP addresses correctly, but it will only consider IPv4 addresses in dotted decimal notation and not IPv4 addresses in other notations or IPv6 addresses. All of that appears to be a minor risk but not an actual issue – assuming that URLs are already normalized when they get here (ok, let’s ignore the code prefixing URLs with http:// here).
The code at the bottom of this function is quite problematic however. Rather than ignoring non-HTTP URLs, this function will pass them to tld.js. But tld.js isn’t aware that non-HTTP URLs can have different semantics, so it will happily return “example.com” when it is fed something like “data://example.com,asdf/”. Oops, I think that one might even be exploitable…
I think I’m going to stop here. This needs a structured effort, not spending ten minutes every now and then. As I said, the codebase isn’t bad. But there are obvious issues that shouldn’t have been there. As always, spotting the issues is the easy part – proving that they are exploitable is far harder. I’m not going to spend time on that right now, so let’s just file these under “minor quality issues” rather than “security problems.”
https://www.passwordstore.org/
Keep it simple, keep it local, keep it CLI.
The password for my password safe is one three passwords I know: unlocking my root partition, my desktop account passwords, and this.
I have infinitely more faith in something whose encryption is zero knowledge with multiple tiers, as opposed to LastPass. I'll never understand the notion of password as a service being an acceptable risk.
For me ideal is keepass but once got db corruption when syncing with dropbox like service. Hence went with enpass which allows me to sync password across devices and encrypt with keyfile and master password like in keepass.
.
Firefox's password safe comes close it seems, but I haven't read too many opinions about it.
Password managers are widely recommended in almost all ‘protect yourself being hacked’ writings.
I use keepass + spideroak to sync.
Keeps things simpler, IMHO. Maybe slightly more effort to log into things but I value having control and simplicity in my workflow.
It's safer to self-host and store encrypted backups elsewhere for integrity. If you're not familiar with encryption or cryptanalysis, then you can use some open source encryption programs and a text file on an encrypted partition. That's a thousand times more secure than any proprietary online password manager.
For some passwords it is also more secure to keep them in plaintext on physically secured notes. It depends on the threat scenario.
The integrity of that information is only protected by your contract and the law.
I'm not sure if this is a good idea now that I've read this...
Anecdotally, Joe Siegrist personally emailed me when I launched my first SaaS product to say he liked it. That felt great.
Sucks that Logmein bought it (horrible company who hates their customers) but glad he got a win out of that business for himself.
Ease-of-use and "looks pleasant" be damned, just security-wise. https://www.xkcd.com/937/
Sharing password files via Dropbox, Google Drive, etc. is convenient, but how is that really different than what Lastpass does?
With Syncthing being peer to peer, there's a lot less opportunity for someone else to even know your password file exists.
What happens if your home burns down: do you have backups of the notebook?
Any password uploaded to a server you don't control should be considered disclosed. They can say what ever they want about their encryption pipeline, even release it as open source software, you can't be 100% certain that they run it unmodified.
You simply can't trust a company (that want to make profit at any cost, like all companies) with profitable data (like your login/password). One day someone will sell them.
Everyone takes some risks and the vast majority of people I trust to take the most calculated ones use a password manager. Incidentally I do too. However I do not upload my bank passwords, and my Gmail / Facebook passwords there, so I did account for the absolute faint possibility of LastPass being compromised. I guess I just don't care about my Reddit or HN account that much!
Taking drugs is also a calculated risk, still, most people agree that you shouldn't...
That fear is irrational. While you go on to describe one reason for that, another is that cracking a solid encryption isn't something people can just do.
The vast computer power necessary to maybe crack something like a humble RSA1024 in 8 years can more easily make enough BitCoin to buy a small nation.
Thus a (smart) attacker needn't guess the user's encryption key directly. They just need guess the user's password, "hash" it via PBDKF-2 with the proper params and see if it decrypts the data.
Using a sub $1,000 GPU and a table of common passwords obtained from popular website database leaks it's not that hard to crack the average joe's vault.
I think i saw that some of these managers have integrations with https://haveibeenpwned.com/ and that could extend to the vault password too. Maybe it already does.
The ironic thing here is randomly generated passwords produced by a password manager are highly likely to be more secure than the password that protects the password vault itself.
Indeed. Which is in part why we developed the Secret Key. Even if someone chooses a relatively weak Master Password and all of the data were stolen from our servers cracking even just a single password of a single user via brute force would be implausible. The effort to reward ratio is very high (perhaps insurmountably so) on the effort side.
Full disclosure: I work for 1Password.
The problem of course is deciding what a reasonable number of iterations is, but given the time it takes to decrypt my password I'd say they use quite a lot.
[1] https://palant.de/2018/07/09/is-your-lastpass-data-really-sa...
It's certainly straightforward to use PBKDF2 in a way that is resistant to common / leaked passwords: add a per-database salt, then you can't go through the table in advance. For each individual user you want to target, you have to start trying passwords.
But even if you don't, the whole point of a password manager is to allow the single master password/passphrase to be something complicated. The average breached password should not be relevant here, and a good password manager's UX should encourage/force you to use something more complicated.
1Password, for instance, requires that you provide a 25-character random string in addition to your passphrase; it's not enough to just have the passphrase. I believe they're both used as inputs to key derivation.
In LastPass's case, assuming the attacker has obtained a copy of the encrypted data, a smart attacker can ignore the authentication hash and just try encryption keys directly.
5k rounds of PBDKF-2 on a sub-$1,000 GPU is quite tractable to crack.
Was it a trivial thing for LastPass to fix? Of course. But that's not the point - if an attacker got a copy of the data before you fixed it - it's too late.
[1]https://palant.de/2018/07/09/is-your-lastpass-data-really-sa...
https://addons.mozilla.org/en-US/firefox/addon/passcell/ https://chrome.google.com/webstore/detail/passcell/mjbndaapn...
All encryption/decryption is done inside the browser, as you can verify the source code, https://github.com/zncoder/passcell.