LastPass Master Password Compromised?

Forumite Members General Topics Tech Security Talk LastPass Master Password Compromised?

Viewing 5 posts - 1 through 5 (of 5 total)
  • Author
    Posts
  • #69047
    Ed PEd P
    Participant
      @edps
      Forumite Points: 39

      If you use LastPass you MAY have a problem. This report from Bleeping indicates a possible break-in to LastPass Master Password storage, but it does not provide very much evidence that a break-in has happened. One to watch in terms of any attacks on your financial accounts.

      https://www.bleepingcomputer.com/news/security/lastpass-users-warned-their-master-passwords-are-compromised/

      On my part I distrust using Cloud based password systems. I prefer to keep a limited number of passwords in a little black book for mobile use, and the full list in KeePass2 for home use only.

      #69052
      JayCeeDeeJayCeeDee
      Participant
        @jayceedee
        Forumite Points: 230

        Just seen this explanation on their blog – HERE.

        Looks like it was an over protective monitoring system – preferable to a lax one!!

        #69054
        Ed PEd P
        Participant
          @edps
          Forumite Points: 39

          JCD, I think that may well be the explanation, as the reports did not have the hallmark of hacking everyone’s master password. That said, a lot of the web speculation around it does perhaps point to ways in which focussed attacks on an individual’s master password MAY be possible. Comfortingly such attacks usually require pwning the actual PC so they will only be of real value for long term attacks on the individual by a Nation State or criminal enterprise.

          All that said, the LastPass article had some useful general advice at the end. The only bit I thought needed a bit of explanation is their so-called ‘Dark Web’ monitoring. It struck me that this was just their fancy way of using https://haveibeenpwned.com/ , use of which does need a bit of tuition. For example I know that my email address has been previously  pwned a specific number of times due to failures by companies (such as Malwarebytes) not taking sufficient care to secure their databases. However each of these has emailed me concerning their failure, and I also know that I had used a throwaway password with them. HaveIbeenPwned shows that there have been no successful ‘paste-ins’ of these passwords – showing that there were actually unique. I’ll now only get very concerned if I learn that a new attack on a financially important company such as PayPal etc has leaked my current password!

          I’ll get a bit concerned/annoyed if the number of companies leaking my email increases and I have not already  been informed by the company concerned. If that ever happens, I will be sending a zinger, complaining about them to the UK’s Information Commissioners Office!

           

          #69055
          JayCeeDeeJayCeeDee
          Participant
            @jayceedee
            Forumite Points: 230

            HaveIbeenPwned shows that there have been no successful ‘paste-ins’ of these passwords – showing that there were actually unique. I’ll now only get very concerned if I learn that a new attack on a financially important company such as PayPal etc has leaked my current password!

             

            Too true!! Clear Score also perform a similar monitoring – also using it as an income stream for their Plus service @ £4.99 pm. There are probably others.

            #69056
            wasbitwasbit
            Participant
              @wasbit
              Forumite Points: 245

              I must have a hundred or more passwords yet have never seen the need to use a password manager.

              HaveIbeenpawned shows that my name has been compromised 5 times. One is dropbox which I have never used & the other 4 I’ve never heard of.

              IIRC my name dates back to registering on the Micromart forums back in the 90’s. In all that time I’ve only had to jump through Microsoft hoops to secure my email twice.

              --
              Regards
              wasbit

              Rig 1: Optiplex 3050 SFF
              Rig 2: Asus ROG G20CB (rebuilt wreck)
              Rig 3: HP Elitebook 8440P

              Dear Starfleet, hate you, hate the Federation, taking Voyager. - Janeway

            Viewing 5 posts - 1 through 5 (of 5 total)
            • You must be logged in to reply to this topic.