News: 1661461339

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

LastPass source code, blueprints stolen by intruder

(2022/08/25)


Internal source code and documents have been stolen from LastPass by a cyber-thief.

The password manager maker said on Thursday that someone broke into one of its developer's accounts, and used that to gain access to proprietary data.

The biz, a [1]big beast in the security world and based in Massachusetts, insisted that its users' passwords were still safe, adding that the theft took place about two weeks ago. GoTo-owned LastPass is said to have more than 25 million users and 80,000 business customers.

[2]

"We have determined that an unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information," CEO Karim Toubba said in a [3]statement .

[4]

[5]

"Our products and services are operating normally."

Toubba added:

After initiating an immediate investigation, we have seen no evidence that this incident involved any access to customer data or encrypted password vaults.

The break-in became apparent, we're told, after "some unusual activity" was detected in the development area of LastPass's computer network. The software house said it had contained the security breach, taken steps to prevent it happening again, and contacted outside infosec experts for help.

We can't believe people use browsers to manage their passwords, says maker of password management tools [6]READ MORE

The chief exec said his outfit may take further steps to shore up its network defenses.

LastPass offers a software vault that stores your username and password pairs for logging into websites, saving you from having to memorize lots of long complex strings: you can create unique and tough to crack passwords for each site account and have them saved in your vault. A master passphrase is needed to unlock and use these credentials. All you have to do is create and remember that secret phrase.

[7]

We're told that these master passwords are still safe, and haven't been compromised or accessed by the intruder, and the contents of people's vaults are also untouched. For one thing, LastPass doesn't know or keep a copy of your master password: that's for you to memorize and protect.

Sit back and relax is the message. "Our investigation has shown no evidence of any unauthorized access to customer data in our production environment," LastPass added in a statement. "At this time, we don't recommend any action on behalf of our users or administrators."

That said, LastPass has not been blunder free over the years. In 2019, it [8]fixed a bug websites could exploit to steal passwords for accounts on other sites, it had a serious password-leaking [9]flaw in its code in 2017, and so on. ®

Get our [10]Tech Resources



[1] https://www.theregister.com/2021/12/14/lastpass_spinout/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ywfw@rGzo0k2w6H68s0OQgAAAIk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ywfw@rGzo0k2w6H68s0OQgAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ywfw@rGzo0k2w6H68s0OQgAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/07/30/infosec_risky_behaviours_study/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ywfw@rGzo0k2w6H68s0OQgAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2019/09/16/lastpass_vulnerability/

[9] https://www.theregister.com/2017/03/21/lastpass_vulnerabilities/

[10] https://whitepapers.theregister.com/



Let me guess...

2+2=5

Let me guess... the hacker broke into the developer's account, navigated to their internal repo and Lastpass filled in the password for him?

"We're told that these master passwords are still safe"

LDS

Why should they have those master passwords?

Why should they have those master passwords?

diodesign

They don't, from the LastPass FAQ:

"We never store or have knowledge of your Master Password. We utilize an industry standard Zero Knowledge architecture that ensures LastPass can never know or gain access to our customers’ Master Password."

C.

Re: Why should they have those master passwords?

LDS

"Excusatio non petita, accusatio manifesta"

Why they had to tell those passwords were still safe, if they never store or have knowledge of such passwords? Hope it was just an overzealous PR...

Richard B. Johnson wrote:
> It's a "tomorrow" thing. Ten hours it too long to stare at a
> screen.

Sissy!

- Jens Axboe on linux-kernel