LastPass says hackers stole customers' password vaults
techcrunch.com
techcrunch.com
Often when these things happen, the reports make it sound like some amazing feat of technical engineering. But...
> LastPass CEO Karim Toubba said the intruders took a copy of a backup of customer vault data by using cloud storage keys stolen from a LastPass employee.
Ah, there you have it, the good ol' careless human vulnerability! I understand such breaches from ordinary companies, with employees roaming around coffee shops with their work laptops full of these keys, nicely shielded from the world with unbreakable secrets like "Password1", but I'm baffled that security focused ones would also be caught with their pants down like this. Keys stolen from an employee? How? Were they mugged? Why didn't they think this was a possibility? Their entire business revolves around them being ten times as paranoid about this sort of things as the rest of us.
I just don’t understand how they can be so consistently bad at this when they are a security company. I can understand why “Farmer Joes Potatoes” gets hacked, but LastPass? Bruh.
Once available offline things are easier to brute force at speed
Maybe some password hashes are detectable and equal the same password, so lots of low hanging fruit
What's stopping them from looping through the 10k most common passwords and trying them all on every vault?
- Customer Names / Company Names
- Email Address of main LastPass account
- Billing Address
- Telephone Numbers
- IP addresses (from where customers accessed the service)
Unencrypted fields in password vault include:
- *Website URLs* saved in LastPass vaults
- Password creation time
- Last password modification time
- Last password access time (great to guess which accounts might be used more often!)
- Whether you added this account to favorites
- Whether or not the password was auto-generated (great to figure out which passwords might be more vulnerable!) ... and a lot more, which might contain a good amount of data about your usage habits as they concern specific sites (e.g. whether you enabled auto-logon)
- Encrypted vaults secured by only the master password of the time of backup. Weak master passwords are probably readily crackable with current password hashing/guessing techniques. For stronger password it is only a matter of time until hardware becomes powerful enough. See [/u/dschwarz's post on bruteforce time estimates for your password](https://www.reddit.com/r/Lastpass/comments/zt6h1t/zxcvbn_can...).
I also have a bone to pick with LastPass communication here:
- LastPass lied in their marketing about Zero Knowledge vaults: website URLs are UNENCRYPTED, this is sensitive information and exposes you to large-scale automated targeted phishing, doxing, social engineering and blackmail attacks.
- LastPass waited 5 MONTHS after the August breach to warn us. They waited the day before Christmas to announce this with obfuscating language to minimize reach of this bad news.
- LastPass will unlikely survive the litigation, class action lawsuits and customer exodus that will follow. This will result in decreased operational security as whole teams are fired during bankruptcy, processes deteriorate and disgruntled employees head for the door.
Obviously, the unencrypted URLs mean we may see another wave of blackmail a la Ashley Madison, but there's a huge potential vulnerability in that most people only have one personal email address.
I have my GSuite configured so that I can make email addresses start with a few special characters and then I can just make things up after that (e.g. abc123.anythingiwant@mydomain will get auto-routed to the me@mydomain inbox), so if I used LastPass, you couldn't even try to break into any of my accounts since my vault login email would be completely different from every site I have in the vault. But I'd bet most people don't even know it's possible to do this, much less know how to set it up, and they are thus vulnerable to attackers clicking "Forgot password?" links and typing in the LastPass account email.
I'm glad I switched away from LastPass years back. They always seemed fast and loose with security. BitWarden offered a much better mobile experience and seemed to take security much more seriously (self hosting? heck yeah!), and each time LastPass ends up in the news, I am all the more grateful I made the switch.
Edit: If anyone else uses GSuite for their personal email, if you want to be able to generate custom addresses on the fly, go to the GSuite Admin Console > Apps > Google Workspace > Gmail > Default Routing, and add one or more rules like so:
1. Recipients to match: Pattern match
Regexp: (?i)somelettershere\d*?\..+?@domain\.tld
2. If match: Modify message
Envelope recipient: (check the box for) Change envelope recipient
Replace username: <your normal GSuite username>
3. Options: (select the option) Perform this action on non-recognized and recognized addresses
After you setup the rule, make sure to set the order such that any pattern matching goes before the default "All recipients" rule.
I have two of these rules in place so that I can create email addresses in either of the following formats:
<name>.<whatever I want>@domain.tld
<initials>mr<random numbers>.<whatever I want>@domain.tld
This is super useful since a lot of websites don't let you include a "+" in your email address, so you can't use Gmail's helpful "+" functionality. This entirely bypasses those arbitrary restrictions.
Edit 2: Just thought about all the terrible web applications I've used over the years which store identifying info in URLs, including session tokens in some cases (yes, you read that right - they don't bother with cookies, so if you send someone a URL without sanitizing it, they get auto-logged into your account!). This info is all unencrypted, and most people probably don't bother sanitizing URLs before putting them into their vault (in fact, they probably just let LastPass pluck the current URL to save). Applications that bad typically don't bother expiring sessions for inactivity and thus the accounts are completely open to compromise!
I have to wonder if LastPass is implemented as a huge multi-tenant database keyed on user and website URL...? Lunacy.