News: 1669901408

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Intruders gain access to user data in LastPass incident

(2022/12/01)


Intruders broke into a third-party cloud storage service LastPass shares with affiliate company GoTo and gained access to "certain elements" of customers' information, the pair have confirmed.

LastPass did not [1]define what it meant by "certain elements," saying it was unsure what data was looked at: "We are working diligently to understand the scope of the incident and identify what specific information has been accessed this morning."

Last night's statement also confirmed the attackers obtained the information to carry out the current intrusion using information stolen in an August attack, which we covered [2]here .

[3]

It did maintain, however, that services were unaffected and that customers' passwords remained "safely encrypted" – without ruling out that some of the data was stolen. The company is known to use a one-way salted hash for master passwords, with a fuller description in this technical [4]whitepaper . The master passwords are used to lock users' password vaults, where their logins for various websites etc. can be stored, with the passphrase only ever entered by the user on their browser or app and not sent to or stored by LastPass.

[5]

[6]

Users who lose their master passwords can lose access to their vaults, although there are some [7]recovery options .

The company [8]said it has hired infosec researchers from Mandiant to investigate the break-in and called the cops.

[9]

Remote access and collaboration company GoTo, meanwhile, which Reg readers said began emailing them yesterday, says the incident has not affected their products and services, and they remain fully functional.

The August break-in

LastPass's source code and blueprints were stolen by [10]an intruder several months ago. Back then, the criminals had access to LastPass's internal systems for four days, gaining access to portions of the LastPass development environment through a single compromised developer account, and taking sections of source code as well as some proprietary LastPass technical information.

The company pointed out at the time that its dev team did not have the ability to push source code from the development environment into production. During this period, Lastpass said it had contained the incident, and emphasized that the intruder had not gained access to customer data or encrypted password vaults. In last night's report, it made no such promise.

[11]LastPass source code, blueprints stolen by intruder

[12]1Password's Insights tool to help admins monitor users' security practices

[13]Lapsus$ back? Researchers claim extortion gang attacked software consultancy Globant

[14]Popular password manager LastPass to be spun out from LogMeIn

[15]1Password unsheathes Rusty key, hopes to unlock Linux Desktop world

[16]LastPass to limit fans of free password manager to one device type only – computer or mobile – from next month

Last night's breach notice added advice that customers follow best practice, including never reusing their master passphrases. We'd add that you should avoid storing these in the browser too. C'mon, using a password manager to look after your keys to a password manager? It's turtles all the way down. Most of the bigger browsers do have built in password managers and form fillers; they also sync across all your devices, and not everyone is great at logging out.

GoTo is the rebranded LogMeIn, which was acquired by the private equity arm of Paul Singer's hedge fund and Francesco Partners in 2019. They gave LogMeIn shareholders $4.3 billion in cash to take it private. LastPass had previously been acquired by LogMeIn for $110 million in October 2015. The owners then [17]spun off LastPass as an independent company late last year.

The password manager always had a freemium model, but after the 2019 acquisition moved to a model that pushed harder for punters to shift to the paid service, and was criticized for, among [18]other things , limiting the number of times free users could move from mobile device access to desktop access.

The unit also has its own-brand authenticator app as well as a dark web monitoring service which checks email addresses (up to 100) that users have placed in their vault against a database of breached credentials found on the unindexed hinterlands. The DB is maintained by Enzoic (formerly known as PasswordPing).

[19]

Rivals in the password manager game include 1Password, Bitwarden, Dashlane, Keeper, LogMeOnce, and NordPass.

Raf Los, head of Services GTM at infosec firm ExtraHop, commented: "I'll be eager to read the details of how the attacker(s) broke in, and take those lessons to customers and colleagues to strengthen their environments so they're not compromised in the same way. But the message here is vigilance... Understand your environment, implement controls that balance usability and security, monitor for threats and attacks, and be ready to respond when things go sideways at 2am on a Friday." ®

Get our [20]Tech Resources



[1] https://blog.lastpass.com/2022/11/notice-of-recent-security-incident/

[2] https://www.theregister.com/2022/08/25/lastpass_security/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y4jdr@MsP90J@qHz4xN-2QAAAIs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://support.lastpass.com/download/lastpass-technical-whitepaper

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4jdr@MsP90J@qHz4xN-2QAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y4jdr@MsP90J@qHz4xN-2QAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://support.lastpass.com/help/what-is-a-recovery-one-time-password-in-lastpass

[8] https://blog.lastpass.com/2022/11/notice-of-recent-security-incident/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4jdr@MsP90J@qHz4xN-2QAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2022/08/25/lastpass_security/

[11] https://www.theregister.com/2022/08/25/lastpass_security/

[12] https://www.theregister.com/2022/06/21/1password_trots_out_insights_tool/

[13] https://www.theregister.com/2022/03/30/lapsus_return_okta_fallout/

[14] https://www.theregister.com/2021/12/14/lastpass_spinout/

[15] https://www.theregister.com/2021/05/18/1password/

[16] https://www.theregister.com/2021/02/16/lastpass_pricing_changes/

[17] https://www.theregister.com/2021/12/14/lastpass_spinout/

[18] https://www.theregister.com/2021/02/16/lastpass_pricing_changes/

[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y4jdr@MsP90J@qHz4xN-2QAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[20] https://whitepapers.theregister.com/



OnePassword next?

Plest

My fear is that OnePassword will be next on the hitlist. I used to love using it when it was local and knew it was under my control, then they decided to move the data into online storage and it's like a spot you can never heal, just there not causing serious problems but bothering you that it might one day turn into a nasty boil! Ha ha!

My family loves it, the family ticket is cheap enough and my kids are useless with passwords so this stores them and auto-generates sensible complex, unique passwords for every site without any effort from them, so swings and roundabouts I guess.

Closed source password managment is too risky

Cybersaber

You can't trust a closed source password management solution. You can't trust someone else storing your passwords.

LastPass is both. Their response is full of equvocation:

'Devs can't push to prod' - This is a half truth designed as a full deception. They want you to hear 'they couldn't have modified prod' but that's not what they actually said. Just because a dev can't push to prod, doesn't mean that code can't enter prod. An attacker can slip stuff into Dev, and then *normal, authorized process* can push the hidden poison patch to prod.

Once the code is in prod, one of the unspoken assumptions they hope you don't notice in their whitepaper is the *assumption* that they can't see your password. If a bad actor can modify the code that you can't see or know what changed in, then yes, *it* can see what you're typing and can *certainly* sent your master password to an attacker.

What we have here is *both* the theft of the password database, *and* the potential for the key for it to have been captured. They're hoping you don't connect the dots there.

The reason I lead with 'can't trust a closed source password manager' isn't because we're all devs who would have the foggiest notion about what is contained in a given patch. It's that it is unlikely to be taken private and do what you say onepassword did because someone could just fork it and cut them off at the knees.

In short, I love KeePass, but whatever solution you use, I'd recommend it be open source and local-only. Online password managers are tasty targets that attackers can't resist, and it's only a matter of time before they're compromised, as the story of LastPass shows. Clever whitepapers with cute plans don't survive contact with stupid humans.

Re: Closed source password managment is too risky

BobV

Keeping the password vault on local storage only relies on your storage and backup system being at least as reliable as that provided by the cloud service (Lastpass or whatever). That may be true for many of the people who read The Register, but it is definitely not true for the vast majority of computer users.

I use Keepass with a hybrid storage system. The vault exists on my main computer (plus local backup) and also on pCloud. If either breaks I still have the vault.

The key file only exists on my computers, my phone and my tablets. The master password only exists in my head and in an envelope to be opened if I die.

So if someone breaks into my pCloud account and exploits a bug to see me type my password they still have to get hold of my key file.

This setup won't be perfect, but it's a good compromise that works for me.

Re: OnePassword next?

Lil Endian

Plest, flatten your OnePassword account if you're concerned. Burn it to the ground. Then nuke it from space.

Follow Cybersaber's advice, it's sound. (Local install, FOSS.) If you don't have a home server, you could probably stick USB storage in your router and share the database out from there. Others will know better about good password managers that can do this, mine's home grown.

It is only a matter of time. Of that I am certain.

Re: OnePassword next?

yetanotheraoc

Let's hear from Cybersaber whether his "local-only" recommendation is the same as your "Local install" recommendation.

"you could probably stick USB storage in your router and share the database out from there" -- I wouldn't try this myself, I'm not sure I could do it securely.

Re: OnePassword next?

Lil Endian

I've no particular reason to push the USB/router idea forward, but a least it's LAN-side. Certainly wouldn't be my go-to, I was throwing it out there as a non-super-techie option.

I'm pretty sure Cybersaber and I are of similar minds (poor Cybersaber!) - but I'm happy to be told otherwise.

Re: OnePassword next?

Cybersaber

It sounds like the same thing. The only compute that operates on my KeePass database is my local computer. It's a fair question, but yeah, I was referring to the database, input of the master key, and the compute that processes the two are right here on the computer I'm posting from. Nothing is bullet-proof, but in my personal risk asssessment, I reckon that if my machine were compromised such that an attacker could then get into my database, it wouldn't matter if I was using KeePass, LastPass, or AnyOtherPasswordManager - I'd be compromised. But I would know it, I would know the scope, and I would be incontrol of remedial actions. I can live with that.

As for data resliency? yes, I move the database copies to cloud storage, because that's how encryption at rest work. I'm OK with that security story. LastPass isn't wrong when they say that having access to an encrypted file without the key is pretty low-risk. That's not the weakness in their overall plan.

Re: OnePassword next?

Graham Cobb

Personally I use Password Safe. Actually I use a database in Password Safe format with various different apps - there are many, for all platforms. Some apps are FOSS if that is what you want, some are tightly integrated with Android and IoS (for example with "keyboards" for transferring passwords into apps), others are little more than databases.

I handle the sharing separately - outside the apps. I normally keep the master version of the database on my home PC. Devices sync by a variety of mechanisms, some of which only work at home, others are protected by OTP access so I can access them from anywhere if I have my phone.

However, all that is quite complicated. I normally recommend friends and family to use one of the commercial password managers. Even if it can be broken into, it is going to be more safe overall than using a word document!

Available + Convenient != Sane

Lil Endian

As was pointed out by some in the comments following the recent [1]NardPass password article , using an online service like this just creates another attack vector. And a tasty one too, for the vagabonds out there.

Why on Earth, if you're going to use a password manager, would you use a service like this? Convenience of sharing across devices? Can be done with a local store, but a little more techie to arrange the sharing - hence the 'convenience'.

Yep, your local machine is (almost certainly) connected to the net, so is somewhat vulnerable. But that probably requires a targetted attack on you rather than a, drive-by, or a huge neon sign hanging over the service provider saying "Go on then!".

Heck, you are better off writing your passwords on parchment and locking it in a drawer of your computer desk. No, we don't advise this! But if the crims can access that, they have access to your physical rig, and we know that's Game Over.

And defo screw browser based password storage. Do the devs really think they're helping here?

I do appreciate the pro/am divide, but sheesh!

[1] https://www.theregister.com/2022/11/25/infosec_roundup/

Re: Available + Convenient != Sane

yetanotheraoc

I like your title. The whole problem is, as you put it, the pro/am divide. In short, if you make access *reasonably* secure, the pros will look for ways to make it *more* secure, the ams won't use it *at all*. ExtraHop says "implement controls that balance usability and security". Balance, ha! It's like the pros and the ams are fighting over a thermostat, each one wanting to turn the dial all the way in a different direction.

Re: Available + Convenient != Sane

Cybersaber

Professionals are just as likely to make bad password security decisions as amateurs. I know this deep in my bones from long experience in the field. In the early parts of my quarter-century-long IT security I *was* one of those people. It doesn't take a genius to figure out jumping out of a moving plane at altitude is a potentially life-altering decision, yet skydivers exist, including actual geniuses. Characterizing it in simple terms referring to anyone who doesn't take security seriously an amateur is unhelpful. It is neither correctly characterizing the problem, nor helpful in pursuing solutions,

I get why it's tempting to think that everyone who is paid to do IT security work is a paragon and champion of password security, and anyone who doesn't 'get it' can't possibly be knowledgeable about it (and thus an amateur,) but I can tell you it's just not so. It's a problem that's millennia old. The ol' Mark I human is just not good at prioritizing actions that are annoying or uncomfortable unless the risk is made 'real' to them. We need a decade of the equivalent of the 'this is your brain on drugs' ads. Security never has been, nor ever will be something desirable to do in a vacuum where the risks aren't viscerally 'real' to people.

Re: Available + Convenient != Sane

Lil Endian

I do not disagree. As yetanotheraoc says, balance.

Admittedly when saying pro/am I was pointing out an outlook difference, rather than stating "anyone on a payroll in IT knows, or even cares, what they're doing". I'm expect we've all worked alongside to total arse-biscuits. So my apologies for that. I guess it'd be more accurate to say "those-that-give-a-toss/those-that-don't" but it's a bit windy!

I know some hugely knowledgable amateurs.

A cat has four legs. Your dog has four legs. Your dog is a cat. I try not to fall for fallacies.

[Icon: beers are on me!]

Fighting Over a Thermostat

Lil Endian

Lawl! Mind if I borrow that?

Re: Available + Convenient != Sane

Cybersaber

Actually, the 'don't store your password on a post-it' advice is another example of a good adage being repeated after the wisdom that underpins in not necessarily applying anymore.

Why is it a good idea not to write your passwords down on a post it? Well BEFORE when we all worked in an office it was because then they'd all be there in easily 'decrypted' form in an insecure and monitored place where your work mates could come by and unlock your computer to change your screen saver or do something slightly less harmless. Very much the 'all the passwords are here in one place you can grab all at once, so come at me, bro!' paradigm you correctly associated with LastPass.

At home though? Your physical security and ACL on who can be in your home are effective compensating controls in many cases. Do I do that? No, I still use keepass, but I would come down less hard on someone leaving post-its on their wfh 'office' desk than i would if I found it under a keyboard in pre-COVID days.

I could probably be persuaded, after a sit down with the person involved about why they're being given the TRUST and PRIVILEGE of doing so, and the ways it hedge against it going wrong. I mean yeah, there's risks, but for REAL security, where that user might just instead use Password123Aug2022 to defeat complexity checkers... eh, it's a devil's bargain I could maybe live with.

Dunno, maybe. Kills my soul, but maybe. Probably not, but... you know, there's this IT Benevolence fund we have, and donors get perks... ;)

...But humor aside the real take-away of this reply is: Always evaluate whether the basis of your good practices has changed, and if/how that affects the 'goodness' of the practice.

Re: Available + Convenient != Sane

Lil Endian

Agreed.

Summery: choose (a) make informed decisions or (b) don't.

Store your password/phrases:

(a) WAN side

(b) LAN side

(c) Off line

Re: Available + Convenient != Sane

Graham Cobb

Actually, browser password storage isn't a particularly bad idea. Sure it has weaknesses (device can be stolen or hacked, ..) but they are targetted weaknesses. The crim has to be either physically close or deliberately targetting you. Unless you are a prominent person, that is your best protection. Random hacker targetting company databases is unlikely to get your passwords.

Re: Available + Convenient != Sane

Lil Endian

Again, horses for courses.

Browser devs are fallible, users install third party, unaudited extensions, browsers leak. Each to their own, I prefer not to introduce an attack surface if possible, and don't recommend it generally.

Regular backups

Anonymous Coward

I take a backup of Lastpass data monthly to be squirreled away on a USB drive in a drawer.

Re: Regular backups

Cybersaber

That's a data resiliency plan, not a data security plan. What you have there is a system for protecting and recovering a database full of passwords that could be (and one should assume are) currently being sold in the usual places for such things.

Password Safe

DrXym

Use that instead - https://pwsafe.org/. It's free, open source, uses strong encryption and you can save your keys locally or in the cloud if you prefer through drive, dropbox etc. Obviously if you save the file to the cloud you want to use a strong passphrase on the file, and not share it with the cloud account.

Until they're not...

TheRealRoland

>credentials are safely encrypted

You know, if you really do not understand the implications of
running everything with permissions equivalent to root - get
the hell out of any UNIX-related programming until you learn.

- Al Viro explaining the merits of doing everything as root