Experts fear crooks are cracking keys stolen in LastPass breach
krebsonsecurity.com
krebsonsecurity.com
All those consumer gpus in now-illegal Chinese crypto farms are probably hard at work mining for keys. What else are you going to do with them?
> these numbers radically come down when a determined adversary also has other large-scale computational assets at their disposal, such as a bitcoin mining operation that can coordinate the password-cracking activity across multiple powerful systems simultaneously.
Yeah, and the best part is they already paid for the cards and can't use them for mining anymore because they're on their last leg and have been surpassed by newer generations of hardware. I'd bet a lot of the operations that got stinking rich five years ago are absolutely swimming in cards that they'd otherwise just be paying to get rid of. The ROI must be incredible, it's probably just a few hours to crack a key and you get to do a Storage Wars-style walkthrough of the secrets some poor LastPass user thought would be secure.
No, they're still mining Bitcoin. There's absolutely no way to crack secp256k1 keys with even a datacenter GPU. We're firmly in the realm of quantum computers if you expect to crack anything before the heat death of the universe.
There has been a lot of work being done to crack brainwallets, also there are a number of leaked/hacked/shared wallets that people are working on cracking. There have also been a number of wallets generated with weak RNGs which get cracked, vulgarity wallets etc, and of course, the LastPass vaults as described in the article.
That's not what the article is implying is happening.
> “An Nvidia 3090 can do roughly 4 million [password guesses] per second with 1000 iterations, but that would go down to 8 thousand per second with 500,000 iterations, which is why iteration count matters so much,” Weaver said. “So a combination of ‘not THAT strong of a password’ and ‘old vault’ and ‘low iteration count’ would make it theoretically crackable but real work, but the work is worth it given the targets.”
You can find a lot of Hashcat benchmarks online giving you are rough idea of what current consumer hardware can do against argon2 or brcypt:
https://gist.github.com/Chick3nman/32e662a5bb63bc4f51b847bb4...
They were sold, sometimes as new by unscrupulous vendors. Mining graphics cards flooding the market was a huge problem a few years ago.
Seems like quite the leapfrog there without substantive evidence, unless in today's America you can simply short circuit as long as there's 'Chinese' somewhere in there.
This spring I spent a good 2-3 days pruning old accounts, I used 1passwords migration tool (which worked flawlessly)[1], and changed every password that had any monetary or identity value. I've definitely been targeted for attacks in the ensuing months as numbers keep texting "Hi <name>" or other kinds of (spear) phishing.
At this point I don't really know how to protect my self and think it's mostly 2factor thats kept me safe.
>However, these numbers radically come down when a determined adversary also has other large-scale computational assets at their disposal, such as a bitcoin mining operation that can coordinate the password-cracking activity across multiple powerful systems simultaneously.
Wow. I'll bet Satoshi didn't consider this second order effect of the proof of work scheme. People who build energy intensive mining operations have the means and incentive to turn their mining operations on existing accounts when that becomes more lucrative than creating new blocks.
Instead a user still has to create a folder for compromised secrets, change them and move them out of the folder one by one. Best of all, users would hit a bug where moving entries to/from shared folders would destroy the entry.
Edit: at least let the user (or entreprise admin) mark a vault as compromised. Must have been an absolute nightmare to get corp users to rotate their passwords.
However after some verification there was simply no other answer other than the fact that he did indeed have that seed on LastPass.
At this point, I think it’s just a matter of time before they suffer their own breach for some reason or another.
I've been on websites where they force you to update your password every X months (and it has a lot of special key requirements) and you cannot reuse old passwords (which would really not be a problem regarding cracking... unless they store your old passwords... which is counter productive...)
It basically turns into being unable to memorize all your passwords and being forced to use a service like this, which OBVIOUSLY any genius knows eventually will get hacked and your passwords leaked, ALL your passwords, at the same time.
If you instead attempt to memorize (like I do) because of all the different cases in which you have to swap passwords, you end up with at least 20 passwords you gotta memorize for every site...
I actually absolutely hate how the web works today especially regarding logging in.
Old leaks often show up a long time later. A lot of people had yahoo? email accounts hacked because they used the same linkedin? password, but the leak was from years prior. If yahoo had required rotation, the password list would have been useless by the time it circulated.
I suppose momentum is much more important than I thought.
I mean I understand not immediately changing the password for some online fan fiction forum, but I’d assume you’d at least put changing your password for your dozen or so important financial/email/health accounts on your todo list?
This way there is no "master password". You need one of the keys and its PIN even if you have the encrypted passwords. Anyone with access to the encrypted files would need to brute force a truly random RSA2048 key which is NSA territory (and elliptic key can also be used now). Or steal one of the yubis and crack the hardware because the PIN is limited to 3 attempts just like on a bank card. Or attack the endpoint which is feasible with any password manager, in fact mine has extra protection because the yubis require a touch for every decode.
Clients are available on desktops (CLI and with GUI) and Android. iOS is sadly not possible because you need more access to the NFC chip to talk to OpenPGP smartcards than Apple allows. They only allow fido2 and basic tags. I wonder if this could be done with fido2 hardware backing but for now it's not possible.
This attack in the article uses the fact that the encryption key is directly derived from the master password using a key derivation algorithm. I'm surprised there is no commercial password vault that uses hardware-backed security like I do because it doesn't have this vulnerability which is clearly an issue in the real world.
With hardware backing there is no delicate balance between usability (waiting for the master password to go through the key derivation) and security (a feasible brute force attack) because these two items aren't directly related. This kind of breach shouldn't have happened.
I'm thinking the canonical example of an open network is Bitcoin. Here, everyone knows the public key and could potentially crack the private key from it (for enormous gain obviously). Just do the same thing with a sufficiently large AES key for example.
Access controls to the vault do place a high burden on the service operator, but without it, I believe users with semi-weak passwords would get picked off left and right.
That's unfortunately very hard: Determining what constitutes a weak password is computationally more expensive than actually attacking a database dump of many weak password hashes.
> turn the bad guys into good ones by offering a reward for any cracked credentials
What bad guy would take your reward if it's lower than the value at risk? And if the reward is higher – how would you fund that?
> Seed the system with fake credentials that can be used by authorities to track down criminals
How? This might work for online account takeovers, but not for the problem discussed in the article, i.e. compromised crypto wallets.
Hash cracking doesn't leave a fingerprint.
I've switched providers and deleted my LastPass account after this last breach but getting to see that would make it a lot easier to understand risks.
Anyone please correct me if there have been updates here:
In August-October 2022, attackers obtained, among other things, backup files containing LastPass users' vaults. I don't think the company mentioned what timeframe the backups covered, or whether this contained vaults from users who already deleted their accounts.
A vault file contains both plaintext and encrypted information. The Secure Notes function which might be used for, say, crypto seed phrases, was encrypted. Passwords are encrypted. However the URLs for those passwords are in plaintext, possibly along with last-access time. Someone with your vault can see what sites you have passwords for, before even trying to crack the password. Not great for anyone but especially for high-value targets or for those who are in politically-hostile environments.
Since attackers took the files from the source, it does not matter whether you had 2FA (edit: 2FA on LastPass that is. 2FA, with secret outside of LastPass, for sites in your vault is very beneficial here!). They can throw a bunch of GPUs at cracking our master passwords offline. There's nothing we can do; the horses have left the barn or rather were abducted by UFO.
One other thing that affects mostly older accounts is that while modern best practice is to use 600k+ password hash iterations, some users had far smaller numbers, like 5000, or 500, or 100. Or even 1. Not joking. LastPass could have upgraded users on login for years--I believe they do now, but that has no benefit to the compromised data.
[1] is an article on what might have happened: engineer with high-level credentials logged on from a home machine that was compromised from an old version of maybe-Plex (which fixed the relevant vulnerability long before). And of course the company had security practices that allow engineers to access the kit and caboodle of user vaults from their home machines, even if indirectly. In the end it seems this was caught due to Amazon's automated warnings around certain IAM change actions.
ETA: I do appreciate the difficulty of guarding high-value data against determined adversaries. I also wish LastPass would have been more forthcoming as to the details here; to my knowledge they haven't provided exact details on what was taken, or suggested users change passwords in vaults as of October of last year. Is this still correct?
[1] https://arstechnica.com/information-technology/2023/02/lastp...
> In November 2022, the password manager service LastPass disclosed a breach in which hackers stole password vaults containing both encrypted and plaintext data for more than 25 million users. Since then, a steady trickle of six-figure cryptocurrency heists targeting security-conscious people throughout the tech industry has led some security experts to conclude that crooks likely have succeeded at cracking open some of the stolen LastPass vaults.
> longtime cryptocurrency investors, and security-minded individuals
I'm not sure how "security-minded" you are if you, months after a breach of your password manager, still haven't changed all the involved passwords and keys, especially those involving things worth a lot of money!
What I found was a lot of people made security assumptions and never revisited those assumptions. Or never fully did.
Sure, there's nothing in the TOS contractually obligating them to do this - but starting a low level awareness campaign to warn people with passwords that haven't changed in years about this risk seems like an easy thing to do that a (in keeping with the theme) "security minded" company should be enthusiastic about doing.
You can't nanny everyone, but surely if you're paying for a password manager you'd appreciate these kinds of notices.
Rate of change seems like a very poor signal compared to absolute password strength, which won't change over time. Isn't this already built into lastpass?
I started using 1Password in ~2010, not long after the founding of LassPass, and my first master password was 30+ characters, 90+ bits of entropy. After a few years I upgraded to 50+ characters, 140+ bits of entropy. Good luck cracking that even if only one round of PBKDF2 is used.
But I suppose you have a fairly loose definition of "security-minded".
One supply chain attack.
One upstream dependency.
One contractor clicking one wrong button in an office document.
Your entire digital life compromised, in that one click.
Based on history, if you store a password in a obfuscated location on your computer, and you copy and paste it into every websites, its more secure then using a password manager in my opnion. Sure you wont be able to login to every secure websites from every device you have; but SHOULD you be? What is the price of that convience?
BUT… this never mattered if you used a strong master pass phrase.
8 hasn’t been the recommendation in quite a long time.
I pushed Lastpass to my company in 2017, made everyone use 24 char.
The LP hack was bad, but I wasn’t worried for any of our people.
Do people actually memorize that?! If so, I strongly suspect that these pass phrases have much less entropy than 24 truly random characters would allow.
I trained people for 5 word pass phrases with no BS.
They were free to spice them up if they like. In 6 years I have had zero password reset requests.
That's about as much as a 12-character truly random case-insensitive alphanumeric password without special characters (log2(36^12) = 62).
> In 6 years I have had zero password reset requests.
What do you mean by that? This can mean that either your scheme is secure, or that nobody has ever attacked it (or you haven't found out that it did happen).
[1] https://crypto.stackexchange.com/questions/62597/calculating...
Now… get 80 people to remember a 12 char randoms.
No resets means no one has forgotten their pass phrase. I can not be just explaining passphrases to you now.
But also, spicing a pass phrase up is huge and not just a few bits more entropy. You go from 24 chars that are 5 word options to 24 char almost completely random again.
I appreciate that KeePassXC has a feature to audit your passwords (Database -> Database Reports -> Health Check), which tells you which of your passwords are weak / should be changed.
https://keepassxc.org/blog/2020-08-15-keepassxc-password-hea... for more details (the threshold for "good" has since been bumped from 65 -> 75). The score corresponds to bits of entropy, with penalties for things like password reuse.
(It also has HIBP integration if you want to perform a one-off check that none of your important passwords have been compromised.)
My point is that if your password manager allows you to readily identify which of your passwords are insecure / have been compromised, that's a very useful tool to revisit any previous security assumptions you may have had.
I'm not sure how "security-minded" you are if you used a centralized, network-accessible password manager service in the first place.
Actual security minded folks keep their password vault on an air gapped machine they maintain full, physical control over.
The kind of people who use centralized, networked password managers are, by definition, those who prioritize convenience over security in the first place.
Sure, using something like LastPass is better than just saving all of your passwords in your browser, or just using one password everywhere.
Citing this as evidence someone is security-minded is like saying someone is environmentally conscious because they recycle aluminum cans, despite driving a Hummer H2 and burning the rest of their trash.
Is it better than nothing? Absolutely. Does it make them an environmentalist/security-conscious person on it's own? No. Does it make up for the other shortcomings in strategy? Nowhere remotely close.
It's a half-assed baby step for people who want to LARP as being serious about their goal (environmentalism or security), without the slightest ounce of inconvenience to their otherwise completely polluting/insecure habits.
Keep driving your H2 and telling yourself you're environmentally friendly.
Keep using your PMaaS (password manager as a service) and telling yourself you care about security.
Being serious - if the system is already not able to get anywhere, nobody needs to authenticate on it or with it. If you have passwords there, they don't _do_ anything.
I'm pretty security minded - the word "security" is in my job role - but my password vault is in Google Drive. I need to have it on many machines, and I want it to be backed up. I know my limits - I don't have the hardware and software infra and expertise that Google does - so I trust them with that data. Could it bite me? Yes, but it would require someone a) downloading my passwords file and b) decrypting it. That's enough steps that I'm confident that I'm safe enough.
Get read and re-entered by exactly 1 person, the only person who's authorized to read them.
Oh, sorry, you wanted to copy and paste because you didn't think twice about the security of your clipboard, whether other userland programs are reading your memory? My bad.
> I'm pretty security minded - the word "security" is in my job role - but my password vault is in Google Drive.
I'm on a corporate red team. People like you with your mindset are why I have a job and why big breaches of F500's that "care about security" will always keep happening.
You don't prioritize security, you prioritize convenience, and security is a nice add-on to your convenience.
By all means, please continue doing things exactly as you do - my bank account and I will forever be grateful for folks like yourself. Never stop prioritizing your absolute convenience!
What do you do about keyloggers?
> People like you with your mindset are why I have a job and why big breaches of F500's that "care about security" will always keep happening.
And attitudes like this are what sours the relationship of regular users (who are not opposed to security but don’t consider achieving it their main objective) and the security/IT/… team of their company.
Provide users an actionable, practicable alternative to their existing insecure practice, or you haven't solved any problem. Ridiculing or belittling your user base doesn't help either.
This is a PERSONAL store. Not a corporate store. If this gets busted, I’m out a lot of money, but my company is very safe.
If you have expertise here, I’d be very interested. What is your backup and restore solution? How do you guarantee that your files are safe?
I’m still not sure that we’re using the same definition of “air-gapped” here. From my experience, and air-gapped system is one that is entirely off the network. Like you said, one user, but the system is gapped because there is something dangerous on it. Airgapped systems are used for research. The user should always have root privileges (they can’t mess anything up too badly, and if they do, image the machine or dispose of it in a fire or whatever) so… again, why passwords? What do they do? What do they protect?
They protect data/accounts on other machines. Similar to a piece of paper you'd write a password on but probably with added encryption, which would be difficult on paper.
Want to sign into account XY on the internet connected machine? Just look up the password (which might be a hard to remember sequence of characters) on the air gapped password machine.
Check out the mooltipass, onlykey, beamu, etc. There exist many such devices - some better than others. Note that this isn't an endorsement of the mentioned products, I just mention them as examples. Note also that not all of these devices constitute a true air-gap, though such devices which can display passwords without any kind of connection (be it bluetooth, usb, etc) can still meet that criteria.
Apparently this was said without laughing out loud, unlike my reading of it.
Offline wallet making it slow and difficult to transact is a feature, less chance to be scammed.
Independently verified because we can’t take Lastpass at their word: https://www.reddit.com/r/Lastpass/comments/zzz5x4/notes_are_...
Doesn’t seem critical if we’re talking Facebook and twitter but becomes problematic with human rights orgs and the like.
The justification was that it was used to match login fields against vault items. I’m no crypto expert but it seemed flimsy to me
The main problem is that I can’t add or edit passwords when I am not home.
I’d love another, similar, open source solution that used a crdt to merge offline database edits.
Lastpass wasn't great at doing this automatically, but Keypass cannot do this automatically at all.
Any recommendations?
Stop!
reqaccts_js_bundle_jquery_3_6_1?1693888551:2732 This is a feature for developers and researchers! If you are not a developer or researcher, pasting something here could cause your account to be compromised
The risk here is different but you could imagine someone trying to migrate password managers and pasting a script they found on GitHub that purported to help.
Also, what I consider "non obvious" isn't that non-obvious. Given enough of a sample size, a committed attacker can guess a lot of rules. And if the prize (a crypto wallet) is big enough, they might be motivated enough to give it a go.
Of course all this became unmemorizable for less frequently used accounts over the years. So I had to use a password manager. However, I store only the rule/hint to generate the email address and password, not the data itself.
Could dedicated hacker with a keylogger learn my scheme? Absolutely yes. Am I afraid of any automated attack? No. I guess the keylogger is the real threat here. Once I am infected with that, the dedicated hacker can save their effort to learn my schemes. (Where I use keylogger in a wide sense, covering accessing your clipboard / browser input fields.)
The legendary researcher Dan Kaminsky had a hash of his password leak when some hacker forum got breached. Turns out the name of the forum was in the password, and by changing that, his password to his twitter, his blog, and his VPS with all his servers were all using the same pattern. It was a bad day for him.
For example, if I give you a sequence of 2 points, there are an infinite number of functions which could pass through these two points. A hacker who knows 2 numbers would not be able to figure out the other points unless they know the function.
Actually it's weird (to the point of being suspicious) why none of the password managers I know of use this principle for generating passwords from a single master password; then they wouldn't even need to store any of peoples' passwords at all. You wouldn't need password manager companies since it could be implemented as a purely front-end component (e.g. a standalone Chrome extension which doesn't connect to any server). The user would only have to remember a single master password.
You can basically do this using hmac-sha256 hashes to produce an infinite number of new hashes from a single secret seed and it's impossible to figure out hashes based on their sibling hashes and also impossible to figure out the secret seed (preimage) from any hash.