How is this possible????
How is this possible????
What is the probability that you, techknight (the other user in this thread) and me used the exact same compromised software back in ~2017 and had our master passwords stolen then? And for that person/bot (in Brazil) to try all of those master passwords now?
It's beginning to look like this is a LastPass issue, no..?
I've emailed you a list of the extensions I use in Chrome - if you want to share publicly any that we have in common I'm okay with that
Since I haven't used this LastPass master password since 2017, I'd have to remember which extensions I had back then, which is hard to do...
I may have had 1Password and Adblock Plus which you had/have too.
But it's hard to say. It's a possible vector (that you, dogman123 and I had the same compromised extensions) but also... why would the hackers have sat on our master passwords for nearly 4 years (in my case)?
It's looking like you got phished a long time ago, or installed malware which targeted the lastpass extension.
Did all of you use the same OS four years ago? (Windows perhaps?) Some malware targets Chrome/Firefox files on disk. A malicious extension probably wouldn't be able to affect your LastPass extension, but a malicious malware app could easily modify it.
I used macOS/Chrome back in 2017. I definitely could have been phished then, or used a compromised extension.
Or does LP shoot an email if it detects a suspicious geo-IP login before the 2FA prompt?
Once the IP is approved (you have to follow a link from the email), then you login again with the correct password and then get the 2FA prompt.
Edit: I found an old post from about 5 years ago on a vulnerability in LastPass’s extension [0]