Unusual login activity was due to bug
blog.lastpass.com
blog.lastpass.com
Additionally, it is bothersome that absolutely zero detail on this error is given.
Given the incredible gravity of the situation (potential of having one's entire password vault compromised), I expect a better response than this
I don't understand the thought process behind such legal-ese talk. Do they think we are dumb and can't see through it? Putting this sort of stuff up is just saying "we don't care about you in reality but here is a post saying we do".
The post sounds like it was actually written by either legal or marketing instead
> some of these security alerts...were likely triggered in error
one can conclude that they do not know that any of the alerts were triggered in error (else he would have said as much). Some of the VP's statements were likely triggered by the legal department, though I don't know that any actually were. It doesn't exactly shed light on anything.
> some of these security alerts...were likely triggered in error
Our VP made no statement about the totality. Draw what conclusions you may from the equivocal register of this public-relations statement, but he is relegating his statement to those alerts which, by his own words, he cannot say to a certainty whether or not they were triggered in error. I presume that this statement is calculated to exclude all those alerts that they can know were legitimate. If you want to expand the scope of the statement, then the only implication would be that they cannot discern the legitimate from the illegitimate alerts.
The only purpose of my comment was to draw attention to the apparent equivocation, that is, the art of misleading without lying. If they can't tell right from wrong (alerts), so much the more damning.
But come on, Lastpass has been on a downwards slope for a very long time. They can't even make their main product as good as Bitwarden which is free.
While they have had security trouble in the past- they're big enough that it's not surprising at all to me that many people, including those on HN, are their customers.
I would also not be surprised if they lose a chunk of tech-savvy customers over this- as they should.
They've had their issues but the idea of it being built by a novice programmer is very far from reality.
With this, they say nothing more than "it was not a cyber attack". It is a statement of relief for shareholders. It's not about the customers.
I do agree that they’re patting themselves on the back a bit too much and also should have been a bit more humble when dismissing things as password reuse.
I would want some follow-up answers, to questions like:
- Why would a bug trigger alerts that are as severe as "someone else tried to use your unique not-used-elsewhere master password"? I understand bugs, even severe ones, happen- but can I trust that your alerts aren't going to cry wolf on my account going forward?
- Why did you originally conclude it was credential stuffing/reuse, when there are a number of people that got the alert that clearly stated they had never used their master password anywhere else? Are you monitoring user reports / social platforms / etc to respond to and address these situations?
- When you say "some" were triggered in error- does this mean some of the attempts were legitimate, or were they all due to a bug? Do you even know the answer to this question? If there are legitimate attempts on non-reused-password accounts, it appears master passwords are leaking/being captured/etc in some other way and that deserves further investigation
I just want more than a sentence or two surrounded by 10+ paragraphs of "this happened because of how good we are at keeping you safe"
A lot of corporate text in this blog. This seems to be the only sentence where they say that the unusual login activity was actually a software error.
(PS: I editorialised the title since the actual title is very generic says nothing)
What's the error?
- was the message which says 3rd party had the correct password wrong?
- was it was sent out to accounts other than those for which the 3rd party had the password?
- something else?
They originally said they “determined the activity is related to credential stuffing” [1], then edited the blog post and now they are saying it was just a bug. That sounds like their original story was simply a lie.
[1] The original version of their blog post is no longer available, but Bleeping Computer quotes their PR Director: https://www.bleepingcomputer.com/news/security/lastpass-user..., below the “LastPass says it's credential stuffing” heading.
>Pretty uncomfortable with the idea of hosting it on digitalocean or similar
Everything is encrypted. Use strong master password and 2fa, even if your VM gets dumped and your password gets stolen there's no data they can recover. Alot of people host it on raspberry at home, if you have VPN to home it can be more secure. Also clients are synced, so you can sync while at home network - your in-browser or in-app vault will be available even if server is not reachable at the moment.
* access to your server with bitwarden/vaultwarden (this one is tricky, someone might inject something in webui JS if it's open to public internet, so keeping it VPNed might be good idea indeed)
* access to your master password
* access to your mobile device / totp storage and password for it
I'd say it's pretty safe from random hackers, but if someone is dead set on getting your data, well https://xkcd.com/538/
(Plus their support is excellent and saved my butt once - I upgraded my personal account to a family account and made my father an admin, after which he decided to 'cancel' his account by deleting the full family account, despite a warning saying everyone's passwords would be permanently erased for the full family. I lost access to all my accounts, however thankfully the 1Password team were incredibly helpful and managed to recover our vault from a backup).
I'm going to switch to another password manager. Is there anything that is a drop in replacement for LastPass? ie has a browser extension for firefox, hosted in the cloud (I don't want to be managing a server for this), and has a mobile app. I've heard a lot about bitwarden and keepass, but they're usually accompanied by comments regarding self hosting, which I'm not interested in doing.
You use Bitwarden premium for 10$/y
you might want to reconsider this. browser extensions has historically been a common attack surface in the past[1].
Bunch of people report their unique password gets this message and they investigate credential stuffing? Makes no sense.
>some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error.
"some"? "likely"?
They really don't sound like they've got a grip on this
You never worked in IT if you believe what your customers tell you, especially the ones that don't pay you.
I'm moving to something else now. Other companies might get away with "we fixed a bug, don't worry your pretty little heads." Not this application. Strike two.
If this is nothing to worry our PLH's over, I wonder what their response to a REAL security issue would be like.
Whatever it is, I want to experience it from a distance. I'm out.
Recent and related:
LastPass Login Attempted Activity Blocked – More Information - https://news.ycombinator.com/item?id=29731317 - Dec 2021 (12 comments)
LastPass says no passwords were compromised following breach scare - https://news.ycombinator.com/item?id=29723319 - Dec 2021 (68 comments)
LastPass users warned their master passwords are compromised - https://news.ycombinator.com/item?id=29716715 - Dec 2021 (313 comments)
Ask HN: How did my LastPass master password get leaked? - https://news.ycombinator.com/item?id=29705957 - Dec 2021 (508 comments)
Especially given their history of issues and prior poor or misleading communication.
I don't know if this is becoming the norm, it seems really weird that cancelling things is becoming more difficult. I could have sworn cancelling the subscription used to be easier, it seems they've implemented more dark patterns to make this more difficult? Maybe it might be my imagination
Also I moved to 1password and it's wayyyy more polished than lastpass. Not sure why I didn't move to a different service sooner
i use pass https://www.passwordstore.org/ git sync'd (encrypted) to a $5/month vps that also runs many other things. you could even get a free one from large cloud providers.
pass has lots of clients for all kinds of platforms, works really well (how could it not? it's just a thin wrapper around git + gpg) and i don't have to worry about anything like the topic at hand.
what am i missing?
There's no simple mechanism for sharing. Many clients don't support using multiple stores. Even if they did, the UX is never one that I would be able to convince anyone other than a software engineer to use.
Single-party centralized solutions offer a simplified trust model and a common auth service makes sharing and recovery much simpler.
The main reason for sticking with LP is that it is easier to find and display or copy a password in LP than in Keychain, which really isn’t organized for direct human use.
Typical use cases, just this week: 1) logging in to Quickbooks after a long time not using it; it is not integrated with either KPad or LP, so hunt and paste it is. 2) logging back in to Dazn on my Roku: I have the enter the password manually, unlike some services that allow me to authenticate via my mobile.
Overall, I prefer the near-seamless integration and ease of use of Keychain, but for the edge cases, LastPass has simply been easier to use. (Which is saying something itself, because LP has a poor UI 8-})