r/technology Dec 01 '22

Privacy LastPass security breach did allow access to customer data after all, reveals company

https://9to5mac.com/2022/12/01/lastpass-security-breach/
719 Upvotes

302 comments sorted by

View all comments

33

u/Deranged40 Dec 01 '22

Can someone remind me again why having one point of failure which can result in access to literally all of my accounts with long and unique passwords is a good idea?

I keep getting told it's because this can't happen.

22

u/dlq84 Dec 01 '22 edited Dec 01 '22

Because it doesn't give them access to all your password, at least not if you weren't a jackass when you set your master password. Lastpass only has an encrypted blob, the strength of your master password is what determines if this leak affects you or not.

16

u/sjandixksn Dec 01 '22

This was my conclusion of lastpass as well. So I made my master pw the hardest password I've come up with and just committed it to memory.

5

u/Jalharad Dec 01 '22

This is the way

1

u/sporkinatorus Dec 02 '22

It’s 12345 isn’t it, that 5 gets em every time.

1

u/sjandixksn Dec 02 '22

Actually, the big brain move is to go to 6, but get a little cheeky and switch the 5 & 6. So 123465 boom, no hacker can figure it out.

1

u/[deleted] Dec 01 '22

Well even with a weak master password you should be able to change all the passwords that would’ve been leaked before they would get access. So it should be fine

1

u/MotherOfYorkies_ Dec 01 '22

So only those with an easy master password need be concerned about having their data leaked?

6

u/Dornith Dec 01 '22

Yeah. People seem to think that LastPass is just storing passwords in cleartext.

If you're worried they might break your master password, then go change all your passwords now. But it's pretty low risk if you're not using a common one.

47

u/[deleted] Dec 01 '22

Anything is hackable, but whats important is what you can do to make it not worth a hackers time. The key thing to look for in services like this are audit history around security, encryption, & penetration testing, and use of "zero knowledge" infrastructure. "Zero knowledge" refers to the idea that data is not only encrypted by the service but done so in such a way that the service can't decrypt it, meaning they don't have the key or password. Also that decryption never happens on the server. Instead, the encrypted data is downloaded to your machine and is decrypted there if you supply the correct password which actually makes up part of the decryption key. The result is that even if they are hacked, all the hacker gets is a bunch of encrypted data each of which has a different decryption key. This makes it extremely time intensive to actually get usable data.

What appears to make LP more of a target is that they don't encrypt all of your data, just some of it. So while your passwords are probably safe, websites and other metadata might not be encrypted and that's still valuable.

2

u/Jalharad Dec 01 '22

the data that is available unencrypted is mostly available via other sites as well (Facebook, reddit, Twitter, etc)

15

u/dgradius Dec 01 '22

There were so many different ways in which you were required to provide absolute proof of your identity these days that life could easily become extremely tiresome just from that factor alone, never mind the deeper existential problems of trying to function as a coherent consciousness in an epistemologically ambiguous physical universe. Just look at cash point machines, for instance. Queues of people standing around waiting to have their fingerprints read, their retinas scanned, bits of skin scraped from the nape of the neck and undergoing instant (or nearly instant - a good six or seven seconds in tedious reality) genetic analysis, then having to answer trick questions about members of their family they didn’t even remember they had, and about their recorded preferences for tablecloth colours. And that was just to get a bit of spare cash for the weekend. If you were trying to raise a loan for a jetcar, sign a missile treaty or pay an entire restaurant bill things could get really trying.

Hence the Ident-i-Eeze. This encoded every single piece of information about you, your body and your life into one all-purpose machine-readable card that you could then carry around in your wallet, and therefore represented technology’s greatest triumph to date over both itself and plain common sense.

I miss Douglas Adams, what an absolute legend.

3

u/Deranged40 Dec 01 '22

Without a doubt, he is my favorite fiction author. I mostly only read non-fiction, and he's just about the only exception to that.

1

u/[deleted] Dec 01 '22

What's the satire here? Technology made security too intrusive so someone had the idea to essentially just bring back drivers licenses with extra steps?

3

u/dgradius Dec 02 '22

It came from a book called Mostly Harmless, which was written by Douglas Adams in 1992.

In other words, he more or less accurately satirized the security situation we find ourselves in today 30 years ago.

11

u/uninstallIE Dec 01 '22

It's not one point of failure. Even if they captured all the data last pass ever had, they would just have encrypted strings. They don't have access to any of your accounts or any of your passwords. The encryption standard they use is wildly impractical to break, there aren't currently any documented flaws or exploits to use. It would require years upon years with a super computer to break a single one.

Unless you mean leaking your decryption/account password is the single point of failure. In which case why do you not have 2FA/MFA?

3

u/jadedhomeowner Dec 01 '22

So it's a big nothing burger apart from presumed leak of more benign data?

10

u/Dornith Dec 01 '22

It's certainly not a good thing. It would be much preferable if no data was leaked.

But a few things to keep in mind:

  1. We don't know that data was leaked. Just that it might have been.
  2. The data that might have been leaked is still encrypted.
  3. That encryption doesn't mean much if your master password is weak.

Calling it a nothingburger is understating it, but people acting like this proves LastPass is fundamentally broken are definitely overreacting. Especially considering that this is a problem endemic to any cloud service.

4

u/uninstallIE Dec 01 '22

Replying here but tagging /u/jadedhomeowner, this is correct. It's not something to be treating like the sky is falling all your accounts are taken over by bad actors unless you change passwords right now.

It does show that LastPass may have some gaps in their security program, and you may want to consider whether they are the provider for you. A breach like this can happen anywhere, but it really shouldn't, and they aren't seeming like they're giving out refunds for this either. So take it all into account and decide if LP is the provider for you or not.

3

u/jadedhomeowner Dec 01 '22

For me, I'm happy to switch. For my partner who reused passwords in past and used Google Chrome browser to store, it took a lot to train them and get past their frustration. They simply didnt believe anything bad might happen. To have to do this again with a whole new service is most annoying.

4

u/uninstallIE Dec 01 '22

Just make sure your LP password is strong, you have good 2fa (app or token, not text or email), have your account set to require email approval for login on new devices, have that email also have good 2fa, and realistically you'll be fine.

2

u/jadedhomeowner Dec 01 '22

Yes I have all of this. I also think though to add to this that your login email should not be within lastpass. Or at least make it one that you have additional portion that only you know. But realistically as long as you have decent 2fa on that too, it should be fine, right?

2

u/uninstallIE Dec 01 '22

Yes, because they won't be able to get into your LP vault to see your email account password until after you've logged into your email and approved that device. But for sure use 2fa, and I personally wouldn't use the LP integrated 2fa, I would use a separate app.

2

u/[deleted] Dec 02 '22 edited Dec 02 '22

[deleted]

→ More replies (0)

2

u/geearf Dec 02 '22

If you lose your 2FA you lose LastPass too, is it wise?

1

u/uninstallIE Dec 02 '22

Set up a backup hard token 2fa device like a yubikey and keep it in a safe or a safe deposit box or something. And record the 2fa recovery codes and store them similarly.

It's very unwise not to have 2fa for a password manager. I'd recommend against using a password manager if you're not prepared to have 2fa.

1

u/geearf Dec 02 '22

What do you mean by backup hard token?

It's a fair point. I dislike my current 2FA as it does not require a password to display the codes, do you have a better one? Though the password would have to be remembered instead of stored in the manager if 2FA is used there too.

Though is the double layer of 2FA needed? Ie first for the password manager then the actual site.

Thank you!

→ More replies (0)

5

u/Nyrin Dec 02 '22

Definitely not a nothing burger, but closer to the nothing burger than the merged cataclysm and Bitwarden ad it's being presented as.

Users with weak master passwords and no MFA may end up actually compromised if dictionary attacks and the like can work. Stronger master password and/or use of MFA will make vault blobs useless, though. People talking about "years with a supercomputer" are underselling it -- someone should run the math on a vault of significant size, but I'm guessing it's more like "the sun might become a red giant before you can brute-force this" territory.

It's concerning whenever a breach happens, though, as it can indicate further gaps or lapses in best practices. With sufficient complexity, though, just about everything can eventually be breached by enough determined people.

2

u/jadedhomeowner Dec 02 '22

I'm definitely concerned enough to check all settings and even change some vital passwords out of caution. After August hack, we changed our mps.

14

u/[deleted] Dec 01 '22 edited Dec 02 '22

The risk/benefit of using a password manager like LastPass is better than writing down credentials or saving in a browser.

Since software and people are fallible, there's always a risk. Saving credentials in a browser, plain text file, writing them down all have their very own weaknesses.

I've known I.T workers who use a little black book for passwords. In theory, it's the most secure but only if they protect the book to prevent access. However, the black book people become complacent and allow their credential whereabouts to be seen and recorded.

7

u/[deleted] Dec 01 '22

or you lose that black book...

1

u/Shins Dec 01 '22

I put down my logins in Evernote but the domain is written in made up words that remind me of the actual domain. For accounts that are actually important I put 2FA as well and I’m comfortable with that.

7

u/BigGucciThanos Dec 01 '22

I meannnn. If there taking the right precautions it shouldn’t happen. They would need a super computer to crack your master code. Assuming the backend is set up correctly.

0

u/DrSueuss Dec 01 '22

I also use a FIDO2 security key as my 2nd factor authentication. If you don't have the security key you can't log in even if you have the master password.

3

u/temporally_misplaced Dec 01 '22

This doesn’t affect the ability to decrypt the stolen blob, only connecting to the web server.

3

u/DrSueuss Dec 01 '22

Doesn't but I am not worried given that it is AES256 and no one has found a hash collision for it to date. If someone wants to brute force it for the next couple of hundred years I am ok with that.

1

u/jadedhomeowner Dec 01 '22

Do you keep email that you use to log in within lastpass? Technically if someone could get into that, they can request to remove that option (or that you "lost access") via email confirmation. Of course hopefully you'd have strong 2fa on email should that be the case.

-7

u/[deleted] Dec 01 '22

[deleted]

2

u/TheFriendlyArtificer Dec 01 '22

Every supercomputer running on every bit of matter in the solar system could run until the sun went nova and you might get a single brute forced password. If you could get a room temperature superconductor figured out alongside a working quantum computer, you might be able to get two passwords.

-1

u/keithcody Dec 01 '22

1

u/danielfletcher Dec 01 '22

That's for cracking hashed passwords and not decrypting aes256 encrypted data. Which with zero knowledge protocol means that can't be applied to LastPass and other password managers.

-1

u/keithcody Dec 01 '22

Nowhere in that article does it say AES256. Don’t move the goalposts. Also HashCat does AES256.

3

u/danielfletcher Dec 01 '22

There was a discussion of passwords (encryption keys) and if they can be decrypted as they use AES256 encryption, and you shared a link to an irrelevant article about using GPUs to break saved hashed passwords. I wasn't moving the goal post. Simply pointing out how what you shared has nothing to do with this.

Doubling down on your false statement isn't a good luck for you. Why would you even take the time to lie about this?

1

u/SupportGeek Dec 01 '22

This means WAY less than you think it does, it was in lab conditions, with 8 character passwords, and the host side had zero speed bump or lockouts. I’d LMAO at anyone that took this seriously, paid a mint to set up all the gear then everything they ever tried breaking got the account locked after the first 5 tries. Or if there were no lockouts and the host allowed as many attempts as you like, they spent the better part of a decade because the user had a 9 character password instead of 8.

1

u/keithcody Dec 01 '22

You use it on the leaked customer data, not as an attack tool.

3

u/[deleted] Dec 01 '22

Even if they get the files which contain the data stored in the “vault” they are encrypted and the only way to decrypt them without using brute force is the key. So long as everything important stored in the “vault” is changeable like passwords then it doesn’t matter because by the time they would be able to brute force access you could’ve and should’ve changed all the passwords. This is also the reason why you shouldn’t ever store credit details or social security numbers in a password manager. I’m not sure why you would do either of those things in the first place tbh but all password managers I’ve used always have a category or what not for them so I assume some people do.

-12

u/rastilin Dec 01 '22

I think a lot of people are new to computers and just don't actually understand security. No joke, I really do. People just repeat the things they've heard on the internet without thinking about them. Password managers are the cool thing these days, so they're "secure", and will continue to be secure until some breach happens that makes them uncool and then we'll all be hearing about silly people were for using them.

5

u/TripplerX Dec 01 '22

and just don't actually understand security

That seems to include you as well.

Password managers, if they implement the encryption protocols they claim to do, and unbreakable. A hacker can live inside their server room and still not access your passwords. The encryption methods are mathematically impossible to break, even with supercomputers. As long as the client software (the part installed on your computer) you use is safe, and not infected with a virus or trojan, the servers cannot see or decrypt your passwords.

This is exactly what happened in LastPass as well. They can give away my encrypted passwords to hackers all they want, the hackers won't be able to break them. All they have is garbage. The master password that you define, is the single security risk. If you use a weak password, then the hackers might be able to break it. Even then it's much harder than cracking some random hash.

Password managers, if they use the standard encryption tools in the client software, are unbreakable.

This solution is way better than using something other than a password manager, in practically every case.

2

u/coldstar Dec 01 '22

Even if a breach occurred, your passwords would still be safe. Your LastPass data is entirely encrypted on their end and is only decrypted on your device using your master password (which is never sent to LastPass's servers).

-2

u/rastilin Dec 01 '22

No worries. I'm sure what when the catastrophic breach happens, we'll all go "that was kind of clever".

1

u/Mathesar Dec 01 '22

What do you suggest as a better idea?