LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
krebsonsecurity.com
krebsonsecurity.com
Everybody with a clue knows LastPass is a lost cause, but what’s more interesting to me is how we can generalize the lessons we’re learning here. I’d propose that user blaming in general is evidence of bad tech and magical thinking around it, and that points a finger at some very interesting targets.
Yeah at this point, I have to wonder how there are still lastpass users to worry about whatever the latest lastpass scandal is.
- until recently, didn't have 2fa
- doesn't support multiple domains under the same account (e.g., the stackexchange network is considered one site per subdomain)
- doesn't support generating complex passwords (it'll generate passwords but I'd hardly call them complex…)
- doesn't support credentials not associated with websites (e.g., an SSH login, a bank pin…)
I'm also not sure if those built-in password managers sync to other devices and if you want to trust them with it.
Upside is that it also syncs to my Firefox on Linux, which Apple’s doesn’t.
This does fascinate me. How many people who have won the crypto-lottery like that still keep invested? Is most of the crypto gain unrealised so far? Or most of it been drained out?
I.e. to someone who was early into Bitcoin, they might wish to never sell off all of their BTC.
And besides, even if you wanted to sell off your Bitcoins, there are a number of things to consider:
- Taxes. Why sell millions of USD worth of Bitcoin now, and pay taxes on all of it today? Possibly better in some situations to sell enough to live comfortably for a few years, and then sell more later when you need to again.
- What are you gonna do with the money instead? Put it in stocks? Buy a bunch of houses?
Whelp, spent the first 50 on a house all humans will drool over. Got the compulsory car. Got the compulsory jet. Got the compulsory yacht (not quite as large as Bezos' (ehmm, banana?) that could not leave its construction port). [1]
And with the other 600 million? Private air force? [2] Air craft carrier for your private air force? Or you end up like every wealthy human, dumping your money into real estate so that you can buy 1000 houses for every normal human, and completely "disrupt" the housing market.
[1] https://en.wikipedia.org/wiki/Koru_(yacht)#Koru_and_De_Hef
[2] https://www.thedrive.com/the-war-zone/32869/this-man-owns-th...
People quite literally just hand money to people who already have money. I have sat in a room, and watched someone nearby check their phone and say "There's a minor wealthy celebrity nearby! We all need to go and buy tickets to the stadium! We might see or meet them!"
I went to Dragon Con a few years ago, and people were willing to stand in line all Dragon Con, their entire weekend experience, to see a wealthy famous person. I'd go play games, go out, and see the people move in the line slightly. All weekend. Stretched all the way around the entire block and down the street. Wasn't even "that" famous (supporting movie character).
Citation needed. I got into bitcoin back when mining on your CPU was actually a reasonable thing to do. I tried selling it when it was worth about $50, only for mtgox to promptly fold.
Suffice to say I firmly believe bitcoin isn't really a solution to anything.
Of course anecdote does not data make, but neither does an unsourced claim.
Satoshi is in theory holding onto ~25 billion in coins. Trying to cash that out would however absolutely tank the current valuations.
But that’s hardly the only major risk. Bulgaria has something like 213,000 bitcoin worth nominally 5 billion or so and no particular interest in bitcoin, but trying to cash that out is again problematic.
I've personally watched sell pressure on Coinbase in the multi-million range get executed over the course of a few minutes, with only a modest temporary effect on the price.
Which is why very large transactions frequently occur either outside of open markets or across a surprisingly long period.
The other crypto lottery winners I know (those who have admitted it, anyway) gave up a lot of their winnings either by doubling down in BitCoin at the highs or by gambling on altcoins in the hopes of a repeat. They started as believers and their early winnings only galvanized their confidence. After that, they were dumping their cash into crypto at every opportunity because they thought it was going to make them supremely wealthy.
I probably lost at least another ~1M$ worth (not projected: at the time. it sucks but you move on) through completely preventable ways when acting agains my own better knowledge. Check. Your. Backups. 3-2-1.
I made great "second-order-gains" from my dabbling in crypto I guess you can say, since I made a decent career in the crypto industry. Most people I know in the industry personally who have been around for as long are still invested to various degrees and defi people gonna defi.
I'd probably balance my portfolio more towards real-estate, commodities and maybe stocks if I'd be smart about it but I have enough of anxiety around taxes that I'm postponing doing anything that means having to file paperwork or that may be illegal. No accounts on exchanges. If it really comes down to it I guess I'd had to consider changing countries if my country of residence becomes hostile enough that using my crypto becomess untenable. I'm still very much a "true believer".
(throwaway for obvious reasons)
couple of points
1. You said fear of taxes - have you spoken to an accountant? I understand it's capital gains.
2. What's your view on why the price went up and stays up-ish? Speculation? Funnel for money laundering?
3. What's "believing"? If central banks all published their own coins does that solve the problem of native digital cash? or is this money without fiat type of thing (I am sorry for strange questions - I am sure there are places to dig this up online but it's only what I can glean from around)
I have not benchmarked these recently, but I fear that they had to compromise # of iterations to give "2012 low-end Android device" some chance of ever being able to unlock their vault. As a result, everyone else is vulnerable. Adding icing on the cake is leaking everyone's encrypted vault. Whoops!
If you control the parameters you can improve that boundary-- say, FDE with a KDF that uses 8GB of RAM and 10 seconds to compute-- but consumer products are limited.
Such as…
> That user signed up with LastPass nearly a decade ago, stored their cryptocurrency seed phrase there, and yet never changed his master password — which was just eight characters.
I don’t want to victim blame and I agree with the anti-LastPass sentiments. I just find it amusing that Krebs keeps trotting out the “security conscious“ victims with 8 character master passwords.
The lastpass documentation makes clear over and over that your entire DB can be compromised but as long as they don’t have the master password, you are safe. How people do not think one step past this and realize they need a very secure master password is beyond me.
And yes I know there will be a host of comments telling me they are in the password business so they need better something and guides and whatever, fine. But for anybody with the slightest bit of common sense, lastpass was and still is secure and lived up to their promise.
I don’t think LastPass is using MD5, but my point is that their job is to make any master password harder to guess. They’re not doing it.
The 1Password approach provides much better security. The vault is protected with the master password together with a long randomly generated string. That random string is saved on device on first login, so subsequent decryptions just require the master password. Logging in on new devices require this "account key", but the added security of having a completely uncrackable encrypted vault, regardless of the entropy in the master password, is very much worth it.
But you are absolutely correct, if you lose your device and the Emergency Kit you're SOL. It reality, though, that is mitigated by the fact that:
1. I think it's probably pretty rare to install 1P on only a single device, as the biggest benefit of any hosted password manager is syncing. I think the vast majority of people will install it at least on their phone and a laptop/PC.
2. I think the user experience for setting up the Emergency Kit is done well and most people are likely to do it.
https://codepen.io/pmarreck/pen/gOQxdqW
Here's an online demo of the zxcvbn library which makes a good-faith attempt to rule out passwords based on semantic/contextual evaluation:
The most efficient way to brute force "Horse Gone Barn Bolted" would be with a minimal dictionary attack, say the most common 2000 words, plus s ed *ing variants. you're still looking at 1+ quadrillion combinations for that password, not including spaces.
That can't be that fast assuming a slower hashing algorithm, right? -non crypto person's wild guess
Even if their entire database was leaked, the Secret Key guarantees a good minimum password strength.
(The main drawback is that the user now needs to save this Secret Key or get locked out forever. But it's less sensitive than the master passphrase, since it's mainly designed to protect against this mass-leak scenario.)
Then handle backups with a cloud provider of your choice + additional encryption (basic rule I've been happy to see validated: never upload personal files to the cloud without encryption, after the whole Google content scanning debacle).
Speaking of which, if you want to generate long memorable passphrases, I have an open source cli tool I wrote for that, which I myself use.
Give it a spin
How does this help?
Iterating a hash function (e.g . PBKDF2) is most just a way to make hashing take longer. Since attackers have to make very many gueses (while legit users only have to hash the password once), increasing each guess by a few seconds can really slow things down.
However in modern apps they usually try to use more complex constructions like argon2 to make it so you cant use GPUs to do lots of guesses at once.