LastPass breach is worse than you think because URLs were unencrypted
twitter.com
twitter.com
- Customer Names
- Company Names
- Email Address
- Billing Address
- Telephone Numbers
- IP addresses (from where customers accessed the service)
- Website URLs saved in LastPass vaults (LastPass doesn't encrypt the website URLs)
- Encrypted vaults
That is a massive privacy violation and a puts every customer at risk for massive automated phishing, blackmail, and doxing. They marketed the whole vault as being encrypted in their Zero Knowledge architecture(TM).
And LastPass probably knew since AUGUST and tells us the day before Christmas. Note to obfuscating, dense language in the blog notice. Specifically "unencrypted fields such as website URLs", implying other vault fields could have been unencrypted but they can't/won't say.
LastPass will not survive the pending customer exodus and class action lawsuits.
Seems like instead of spending Christmas with my family, I will spend it changing passwords for 100s of accounts.
there is probably a technical word for this similar to when news is released Friday night to suppress it. what is that called?
Weekends are a prime candidate because press and journalists are off, but social media thrives in weekends. Friday afternoon is the sweetspot if you want to avoid press and social media virality.
Literally nothing will happen. Mark my words.
Don't know where you are getting this fantasy of the company not surviving, and class action lawsuits. Every similar example in the last 10-15 years that I remember was the same (people forgot after a week and nothing happened).
Why didn't you just use decent passwords in the first place? You were using a password manager, what's the fucking point if your password is still "kittens1"?
This is all on you.
If you did use a bad password for the cloud based password manager, you're the walnut. The whole sales pitch is that lastpass can't fuck you as long as you have a reasonable password protecting your vault.
Same rationale applies when a random website gets hacked and leaks their password database. Yes, your password is salted and hashed, and hypothetically unrecoverable. But you change your password anyway.
You have the option to guarantee your accounts are secure, or do nothing and hope it will be fine.
There's a lot of situations where your vault might be decrypted. Sure, they're all pretty unlikely, but the risk is not zero. Changing your passwords does make that risk zero.
You're already fucked. LastPass lied in their sales pitch, and they released a bunch of your data unencrypted. Having absolute trust in their encryption as your sole layer of security at this point is incredibly reckless and stupid. You don't know that your master password isn't uncompromisable, you're trusting the company's sales pitch, and they've already lied to you. There is no reason at all to assume your vault will be secure forever.
This is why you always do your own encryption on offline computer using trusted tools like VeraCrypt . Relying on cloud storage to encrypt is doomed to fail eventually.
Well, yeah. Just like you leak your encrypted password to the internet every single time you log into a website.
>What if there is an undiscovered or undisclosed vulnerability in the encryption?
lmao, if aes-256-cbc is broken then LastPass is probably the least of anyone's concerns. This happens to also be one of the more difficult AES modes to screw up.
>What if last pass isn't using encryption as secure as they claimed?
Shit, if that was a real concern you would have to be a complete idiot to use LastPass in the first place.
Remember that last pass has just been caught lying about their security, and you can't trust what they say.
Calling other people idiots just makes you look like an uninformed asshole, so stop that. You're wrong, and you're trying to justify yourself rather than just back down.
Changing passwords in the face of a breach like this is standard practice and is the only logical step forward. You cannot trust last pass security from this point forward. Whether or not you should have trusted them in the first place is irrelevant in the extreme.
Last pass users should change their passwords, period. Telling those users that they're idiots who shouldn't have trusted them to begin with makes you look foolish and toxic.
Do better.
I'm curious, what were they caught lying about?
>What proof do you have that last pass uses that encryption scheme? Is there any evidence to suggest that it meets rigorous standards?
LastPass has been extensively reverse engineered. There are, for example, public Defcon talks about it.
>Changing passwords in the face of a breach like this is standard practice and is the only logical step forward.
This is not logical at all.
>You cannot trust last pass security from this point forward.
Why not? Because they disclosed a breach?
> such as bad RNG
How could that be a problem? The attacker doesn't control your passwords. How would you exploit a known IV as an attacker in this context?
What are you even talking about? Of course it's a real concern. That exact kind of thing happens constantly. And of course, the nature of the concern here involves us not knowing that LastPass was fucking up. LastPass might not even know. It's not like companies regularly announce in public, "hey, customers! We're actually massive fuckups, we know it, we haven't fixed it, and we just thought you'd like to know!"
>That exact kind of thing happens constantly
Like when?
>And of course, the nature of the concern here involves us not knowing that LastPass was fucking up.
What do you mean? The cryptography used by LastPass is very well understood.
In your other comment you claimed it was "likely" to be badly implemented, but here you state it as a fact. What's up with that?
i have a keepass on my laptop and its copy on my phone. if occasionally i have to update anything, i do that and copy the file to the other place. say i update on the phone so next time i just share the file to the laptop and i am synced.
this "janky" method has worked for over 5-7 years now without any problems so i dont understand why anyone wants to "keep live sync" enabled for such things and have to pay someone for the privilege and then have to wait for them to get hacked. nonsense
I would not use them for anything sensitive ever.... But you do you I guess
mind- your own mind/post-it notes- you forget and you loose notes
offline- keepass- works. is safe. has not been broken
online- whatever SAAS- works but only pinky promise of being unhackable- can leak from beyond your own control.
your keepass could be hacked but they would require access to your device. you have control over that. you do not have control over lastpass servers
I keep a copy of my password file in Dropbox, as one of several backups.
(The file, to begin with, is GPG-encrypted.)
My passwords are all unique and contain plenty of entropy and memorizing them was not actually very hard. I also memorize various phone numbers, email addresses, important dates, etc.
Maybe google has wrecked your brains, but I suspect this technique is more accessible than you think. Or are you arguing that it's less secure?
- people forget
- you can't remember dozens of passwords without a system, and having a system is bad, and almost everyone has dozens of passwords
- this still doesn't help you when a provider (like your ISP or credit card company) is hacked, and since you're probably using some kind of system or the same password in lots of places for ease of memorization, you're hugely at risk
These discussions basically end up speedrunning to "everything is a magic link email" a la Slack (once you filter out the mob pushing their fave password manager), which more and more services are moving to. It's nice because:
- you don't store passwords
- you have no password recovery flow (or, you could also say you only have password recovery flow, but your users never actually set a password)
- your users can't forget their passwords
- it's pretty much just as secure as your email, which is probably gmail, which is fine
I think you get downvoted because your method isn't broadly applicable. I don't doubt it works for you--and I'll side note that I'm old enough to remember actually remembering things like phone numbers and what-not--and that we could all probably use some practice remembering. I'll also say that it's probably the case that most "accounts" are just to harvest your email address to spam you or track you and sell your info to marketers, so a system with some built in back pressure on adding an account is useful in that sense. But if we geek ambassadors go out there and tell people "just remember dozens of passwords or you're asking to be hacked" we're inviting them to spend a lot of time with customer service and in forgot password flows.
You did touch on one of my secrets, I don't maintain hundreds of superfluous "accounts". I'm not going to count them, but I suspect I'm at around 30. If I don't log into a service for a long time then I just go ahead and transition that to "never" in which case it doesn't matter if I remember the password or not since it's clear I don't need that account anyway.
I also use unique logins and emails with each service which I guess is even more to remember.
For throwaway accounts and things that really don't matter I use an easier to guess (and crack) leetspeak pw and/or a post-it note.
I suspect people who are not techies have even fewer accounts to remember so this may actually work for many (though I agree, not all) of them. Probably more than you give credit. In fact I assume that most non-techies are simply keeping credentials in their memory in which case the best advice is probably just to remind them to use unique ones, at least for their email and their bank...
I've also worked help desk and no one ever called to report that everything was hunky dory.
Anyway, I appreciate you taking the time to address the issue rather than just leaving another drive-by downvote.
And yeah I think the big bad we're working against is people using the same password (or a password with some very small variations that's super easy to guess from a variant) across all their services. I'm sure almost everyone does this, I even know sophisticated engineers who do it, I also do it for accounts I don't care about. "Use a password manager browser extension" is the easiest thing for us former help deskers to tell people, and as long as that person didn't choose LastPass (which you should never have chosen, how many breaches will it take) they'll be in great shape.
“Just have less accounts so you can remember your passwords!” is not real advice
However I’d say give that the password vault is open-source and can be self-hosted (like Bitwarden) there are many reasons to use it over an encrypted flash drive. It can be automatically backed up easily, is supported on every device (including mobile) via a web browser. It also includes useful tools like a configurable password generator, versioning, and auto fill. For the average person that is much better than an encrypted flash drive volume, which IME are platform locked (LUKS doesn’t work on Windows, Bitlocker doesn’t work on Linux), are much less convenient, and are much more fragile.
Of course, use whatever works best for you, I don’t know your situation.
If you could explain how "monthly" is relevant to the discussion, that'd be great.
Like you we have TONS of credentials (and other supported items), around 2800 vault items in total, some of which we definitely only use once a year, others we use multiple times per day. Probably started using a password manager and some technique to share some vaults around 2010, so also a decade.
This is absolutely insane to me.
The number of people reporting needing access to multiple hundreds or more of required credentials is blowing my mind. If this is the reality of how people are using the internet these days then we desperately need a better cross-platform solution to identity management and authentication than can ever be offered by passwords. These vault programs are sounding more like a horrendous bandaid than the mere unnecessary convenience I viewed them as.
If you need to share passwords amongst multiple people I guess I can see some of the appeal of these networked vaults, but it strikes me that even this is a drastically subpar situation that ought to be handled on a deeper architectural level (like with sub-accounts and ACLs).
What's absolutely insane to ME is how consistently your responses seem to ignore that other people have different use cases for passwords. Nobody cares if something seems "insane" to you. It may surprise you to discover that services like these exist, perhaps, because people interact with passwords in a different way than your "I only keep passwords that I use monthly" brain database paradigm.
I mean, this is all apples and oranges, but if you could, examine your browser history across all devices as a household going back let's say 10 years. Lots of sites, right? How many did you ever create an account on for whatever reason? Are those all in your vault today? They essentially are for us. To the very best of my knowledge (and there's functionality in 1Password to analyze this, obviously anything not in vaults is invisible to it however) we have no duplicated passwords, anywhere on the internet.
To give some examples of how we do use 1Password, in terms of "Online Shopping" (just one of our shared vaults) that has 100's of credentials for everything from Amazon through Walmart and covering whatever we buy online from groceries to ammunition. Tons of more specialist or niche suppliers like Christmas Designers also make you 'Create Account' to have order histories and to be able to track shipments - this one in particular is a great place for garland, lighting and other holiday items, tis the season!
1Password also stores all our rewards programs (i.e. Store Cards, Airline, Hotels). I'd guess we are signed up with 40-50 merchants for some kind of "Rewards" (i.e. Fred Meyer or QFC, and where the ROI for signing up for their program is some items will be $2.49 instead of $4.49 on offer). I have traveled a lot for business and so can't always fly one carrier alliance or stay entirely within one hotel chain, so I guess that's another ~20 (airlines) and ~20 (hotel chains) for you.
I'm not going to memorize software licenses (serial numbers or license files for e.g., Bartender for macOS), nor other access tokens (i.e. SSH Keys, API Tokens) to various geekery.
Two other things which end up helping a lot, one of which adds lots of vault items: the integration story with Privacy [1] and Fastmail [2]. We've used and loved Privacy for a long time, and this integration stores the unique per-merchant credit card details in a vault. With Fastmail you can create 'Masked Emails' so you've got a unique email for each place you signed up. We've easily rotated both card details and emails on accounts when we find out someone was compromised, and with these integrations we're only rotating that site, not potentially 100+ sites using say the same Chase Sapphire card.
So, your own approach may vary, and I see from other comments that you memorize all your accounts (?) and commented on the frequency of access ("monthly") being relevant to you, so I'd assume frequency/recency plays a part, and you duplicate credentials for less important sites or rely on 'Forgot Password' functionality for less used sites? How do you deal with accounts you didn't need in the last 60 days? In any case, 1Password works amazingly for us, and quite a large number of our friends too, although anecdotally they've usually got 100's not 1000's of items in vaults. :)
I am entirely happy for my family to just have access to the Amazon or Netflix email addresses (logins) and passwords without any of that overhead.
I think it's very typical to think of HN users to think of the average person as tech-savvy enough to do what you're doing, but they aren't. People are fallible, people forget things, people lose things. Some people would rather entrust a reputable service to handle the very menial task of managing their passwords for them, rather than go through the hassle of doing it themselves.
Not only do these services provide better convenience, they make you more secure! Many people reuse the same password, so when a site gets "owned", any site using that same password is now compromised as well. Some of these services will even automatically tell you when a site gets "owned" and offer to change that password for you retroactively.
Now, if you want to go ahead and use a local only method, be my guest. But please, don't ever suggest to anyone else that they should do the same, that's just bad security advice! By the way, getting hacked in the password manager does not mean all your passwords leaked. It just means some extra metadata about you may get discovered, which I'd argue is a reasonable trade-off.
There is no universe in which having a local encrypted key vault that is not online and not synced to the cloud is less secure than having a cloud synched version of the same thing.
There is literally no way that can possibly be less secure.
So if your argument is that the convenience of it makes it more secure … I dont know to say except:
you’re wrong.
> Not only do these services provide better convenience, they make you more secure!
Nope.
> By the way, getting hacked in the password manager does not mean all your passwords leaked.
Nope. That’s not what it means. It means your encrypted vault was leaked, which includes your passwords, if they bother to crack it.
> which I'd argue is a reasonable trade-off.
Well, at least it’s fair to say you saved that as an opinion; fair. Other people probably agree that the security risk of using an online password vault is worth the convenience of using it.
Fair.
…but, fundamentally less secure.
Anyone who chooses to manage their own passwords, offline, is choosing a more secure, less convenient alternative.
I think that’s fair too; and, given number of hacks to lastpass, okta, etc… not, perhaps, terrible advice.
You don’t need cloud synced passwords.
You just want that, because it’s easy.
I don't feel too strongly about this, just replying since you were being an absolutist.
this should be taught in schools if that is your concern. what i am doing with the "manual sync" for files is because i have 2 machines i want to get my passwords. there is a HUGE population who only have a phone. for them, keepassdroid or some other keepass app is the only thing that they should ever need or use. i know because i have set up the files for my family members, they only have their phones at hand and the file has served them well for years without any problem.
now they "whatsapp or email" the file to themselves or to me if they have to change their phone and get it back in a matter of minutes. this is not as big of a deal that you need to have online tied system and be a techie otherwise
I'm not sure what you're referring to that should be taught in schools. The problem of forgetting things is often "human error" not "pilot error", a random packet loss of the mind rather than lack of skill.
There's strategies to mitigate it, like always leaving the house with the same set of items and never changing it up, and avoiding situations where you rely on memory, but live sync is going to prevent a lot of mistakes.
But doing password saving and live sync through a third party service it's pretty crazy to me. Why not split the threat? One program to store your passwords and one service to sync them. I use keepass2android and keepassxc with my own file sync server as sync method. If you don't want your own server you can use a multitude of third party ones.
What should be taught in school is to store your passwords in a secure way just like any other important real life skills like doing your taxes, basic eating and physical health, etc.
I suspect the most secure way to store passwords is in your Google account, because they have a far higher budget than almost anyone else. They will spy on you, but they also keep random hackers out.
I use BitWarden (with gmail as the 2FA) instead because I wanted the ability to try different browsers, and I like being able to store other bits of critical info in my vault.
You generally can't get hacked on anything important unless you already lost your phone, even if they have your password, because of 2FA.
You also don't lose your account if you lose your phone if you use SMS 2FA like most people do even though it's not perfectly secure, because your cell carrier can recover your number.
Bitwarden is still vulnerable to hacks, but I guess it's a bit like saying all banks have issues, but we can all agree Wells Fargo (lastpass) sucks.
So a hacker would have to get hold of the encrypted data, together with the secret key for each account. The secret key isn't stored by 1Password, requiring the hacker to brute force it. However, each key provides 128 bits of entropy, which makes it infeasible to brute force with current technology.
More info: https://support.1password.com/secret-key-security/
Although it's possible they implement this with a local bloom filter or something. I'm just speculating. And either way, those requests would only end up stored in some server logs somewhere, rather than in a database row directly linked to your vault.
EDIT: It is in fact done locally. :) see: https://support.1password.com/watchtower-privacy/
Do you trust them to tell the truth about whether all your data was reliably, securely, and permanently deleted? Can they tell you when and how?
I used lastpass reluctantly, knowing the risk but also knowing it was better than re-using passwords.
What a fun way to spend christmas holiday resetting passwords
New URL is at : https://twitter.com/jsrailton/status/1606195077939744768 apparently, and it worked for me just now.
Feels very robust and I get to be in control of my own data and passwords.