News: 1671777307

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

LastPass admits attackers have a copy of customers’ password vaults

(2022/12/23)


Password locker LastPass has warned customers that the [1]August 2022 attack on its systems saw unknown parties copy encrypted files that contains the passwords to their accounts.

In a December 22nd [2]update to its advice about the incident, LastPass brings customers up to date by explaining that the August 2022 attack saw “some source code and technical information were stolen from our development environment and used to target another employee, obtaining credentials and keys which were used to access and decrypt some storage volumes within the cloud-based storage service.”

Those creds allowed the attacker to copy information “that contained basic customer account information and related metadata including company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service.”

[3]

The update reveals that the attacker also copied “customer vault” data – the file LastPass uses to let customers record their passwords.

[4]

[5]

That file “is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.”

Which means the attackers have users’ passwords. But thankfully those passwords are encrypted with “256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user’s master password”.

[6]

LastPass’ advice is that even though attackers have that file, customers who use its default settings have nothing to do as a result of this update as “it would take millions of years to guess your master password using generally-available password-cracking technology.”

One of those default settings is not to re-use the master password that is required to log into LastPass. The outfit suggests you make it a complex credential and use that password for just one thing: accessing LastPass.

Yet we know that users are often [7]dumfoundingly lax at choosing good passwords, while [8]two thirds re-use passwords even though they should know better.

[9]

So while LastPass is confident that the files copied from its cloud will resist brute force attempts to crack the master password, if that credential is already out there … you know how this one ends and it is not pleasant, as a LastPass account can store hundreds of passwords.

[10]LastPass source code, blueprints stolen by intruder

[11]1Password's Insights tool to help admins monitor users' security practices

[12]Lapsus$ back? Researchers claim extortion gang attacked software consultancy Globant

[13]Popular password manager LastPass to be spun out from LogMeIn

[14]1Password unsheathes Rusty key, hopes to unlock Linux Desktop world

[15]LastPass to limit fans of free password manager to one device type only – computer or mobile – from next month

Oh and let’s not forget that the LastPass customer vault can also store plenty of other sensitive personal information.

LastPass therefore offered the following advice to individual and business users:

If your master password does not make use of the defaults above, then it would significantly reduce the number of attempts needed to guess it correctly. In this case, as an extra security measure, you should consider minimizing risk by changing passwords of websites you have stored.

Enjoy changing all those passwords, dear reader.

LastPass’s update concludes with news it decommissioned the systems breached in August 2022 and has built new infrastructure that adds extra protections. ®

Get our [16]Tech Resources



[1] https://www.theregister.com/2022/08/25/lastpass_security/

[2] https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y6WKV@Zp0DIfHGWv69CSQwAAABU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y6WKV@Zp0DIfHGWv69CSQwAAABU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y6WKV@Zp0DIfHGWv69CSQwAAABU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y6WKV@Zp0DIfHGWv69CSQwAAABU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/11/25/infosec_roundup/

[8] https://www.theregister.com/2020/05/05/logmein_password_survey/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y6WKV@Zp0DIfHGWv69CSQwAAABU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2022/08/25/lastpass_security/

[11] https://www.theregister.com/2022/06/21/1password_trots_out_insights_tool/

[12] https://www.theregister.com/2022/03/30/lapsus_return_okta_fallout/

[13] https://www.theregister.com/2021/12/14/lastpass_spinout/

[14] https://www.theregister.com/2021/05/18/1password/

[15] https://www.theregister.com/2021/02/16/lastpass_pricing_changes/

[16] https://whitepapers.theregister.com/



Someone Else's Password

ChoHag

I'm sure everyone using the clown to keep their passwords safe is following strict security protocols and has nothing to worry about.

Re: Someone Else's Password

Joe W

Hard to say. I find these services appealing, I like password managers, and I dislike having to sync them manually between devices. I have not yet gotten around to get my own server up and running (well... internally it sort of works), so now I can sync in the house. Also note that this is beyond most people.

Using a password manager with a hard to guess master password is way superior to using weak passwords on all those websites that might have your payment information - or even the ability to order stuff tied to your name but then sent to strangers' homes. Good luck remembering a dozen or more strong passwords.

It is - as you imply - always problematic if malicious actors (and in fact, anybody but you) can access your password manager vault, but I still believe the risk is outweighed by the benefit to a normal user - IFF they use a strong master password.

Re: Someone Else's Password

billdehaan

Using a password manager with a hard to guess master password is way superior to using weak passwords

On a Windows PC, I've found using the AutoHotKey abbreviations function very useful to store strong passwords and assign them to keyboard strings.

So, a definition like

::bwpw::QchauTQ<[Mkzg[RPR8awsHjR[Kr<9XLJakyGZmKR!

Allows you to type "bwpw" (BitWarden password), and have it expand to the 64 password you need to get into the actual password manager.

Unfortunately, I haven't figured out how to manage long passwords like that on mobile devices.

Re: Someone Else's Password

elsergiovolador

Can you show us some more examples of your passwords?

Don't worry, it will show up to us as stars. For instance the bwpw you entered actually looks to us like that:

::bwpw::***************************************************************

One Password ...

Anonymous Coward

... to in the Darkness Bind them.

Private Equity Twats

sarusa

Seriously, it's been breach after breach since they got bought out by LogMeIn. Private Equity Twats are all about squeezing blood out of the turnip, never about improving the turnip. I know LastPass is super convenient, but if you actually care about any of your passwords and logins use something else.

Since they got the vaults of every LastPass customer, it's entirely worth their while to try bruteforce on all of them. Hope you used a super annoying master password!

Re: Private Equity Twats

wolfetone

" never about improving the turnip "

A turnip can't be bettered though.

Unless you make it a potato. Then it really would be peak vegetable.

The cloud is just someone else's computer

billdehaan

Unless 1Password is doing things line enforcing users to have different passwords (ie. warning them when they try to save a password for website X that it's already used in website Y), and I doubt such a thing is even possible without accessing the passwords themselves, people are going to continue to use, and re-use, weak passwords.

I've seen some websites which report things like "the password you entered is one of the 10,000 most commonly used passwords; please select another", but then all most people do is tack their pet's name or something in front of it (which is still better than nothing, but hardly ideal).

Personally, I've been using Keepass for literally decades. It may not be the most convenient thing to use, but it succeeds at the most important thing a password manager should be good at: it's secure.

For low-risk passwords (like, er, el Reg here), I use Bitwarden. It's a zero-knowledge system, I'm using a 48 byte master password, and frankly, if someone wants to take the effort to crack Bitwarden and my master password, they deserve to get my Register, Slashdot, and Ars Technica passwords, for all the good it will do them.

For things like banking, taxes, and online shopping accounts, they're all in a Keepass hive on a VeraCrypt volume that includes a portable browser instance with no plugins or extensions.

The funny/sad thing is, the effort I take with my low value accounts (hi, el Reg) on Bitwarden is actually more than many of my friends' SOs and family members use for their high value accounts. I had to resuscitate a PC with a nearly dead SATA drive a while back, and it came with a sticky note that had "USERNAME=xxx PASSWORD=yyy" for the windows login account. I cloned the drive, and when testing the replacement in the PC, I brought up the browser. There were a dozen tabs with various accounts, and sure enough, I was either already logged in to the owner's account, or the "yyy" password would get me in.

I've never been a big fan of the cloud, because of things like this 1Pass breach. But seeing how most people treat security on their own, it's a question of which is worse.

Re: The cloud is just someone else's computer

A Non e-mouse

Unless 1Password is doing things line enforcing users to have different passwords

1Password doesn't force unique passwords, but it does flag any passwords that are reused in your vaults.

A slightly worried 1Password user.

Re: The cloud is just someone else's computer

Roland6

>1Password doesn't force unique passwords

Be glad it doesn't.

For example, my Amazon US and UK accounts have now been merged into a single account. However, if I log in on the US site,I get my US profile andsimilarly on the UK site I get my UK profile. Hence my password manager has two sites that seemingly reuse credentials.

I have a few other entries the password manager also flags as being credential reuse, but which aren't.

Sigh . .

Zenubi

KeePass

Open source

Free

PW file can be stored in the "cloud" / central location.

https://keepass.info/

I honestly do not understand why people use / trust these online PW stores. That said I don't understand why people do lots of things.

So I pay for Lastpass ?

Anonymous Coward

How much do they pay me for the time it takes to change 1,000 password ?

Re: So I pay for Lastpass ?

Anonymous Coward

For what it's worth - they do have an "automatic" password change feature available for many websites (i.e. it opens a new tab of the site in question, then drives a click-select-click type action list to change your password).

The all eggs in one basket problem...

LDS

These systems became highly valuable targets. Even if they could decrypt just a part of the data, they will still have valuable info from one strike. It's funny that a system that was designed to be decentralized to sustain a nuclear attack went back to a mainframe mentality where all data should reside in a central location.

Nothing is Safe in the Cloud. Ever.

Reginald O.

There is nothing safe, secure or private in the cloud. I don't get why that's so hard to understand. Meanwhile, external high capacity plug in hard drives are dirt cheap. Seems like a no brainer to me for individuals even businesses to store and backup data to external encrypted drives then literally disconnect them when not in use.

Re: Nothing is Safe in the Cloud. Ever.

Roland6

>Seems like a no brainer to me for individuals even businesses to store and backup data to external encrypted drives

Only problem, whilst the data held on encrypted drives may be secure, removable USB drives do get lost and that is when you discover the only copy of some important file is on the lost drive...

2FA?

Hiya

Why no comment from LP on using 2FA at LP log-in to increase security of account?

Some things don't change...

Roland6

> Yet we know that users are often dumfoundingly lax at choosing good passwords, while two thirds re-use passwords even though they should know better.

I suspect, given the use of AES, if you can identify the vault, it would be worth doing a dictionary attack using the credentials obtained from previous web breeches.

The question we need to be asking is whether the source code facilitates the unwrapping of user vaults from the file format they are held in, decryption and the reading of useful data from the proprietary binary.

while two thirds re-use passwords even though they should know better.

Neil Barnes

Two thirds reuse passwords because they (I) don't see a need for the security that a password theoretically affords. Kudos to those websites - Ebay and Paypal spring to mind - who run two-factor authorisation, because they *do* need the security. But to comment on a story, as one might here? To even *look* at a price list for something you're considering purchasing? Not convinced...

parlei

Well, good thing we have a long weekend to change all our stored passwords!

At least all of mine are unique: servicename_Shortpw1

(If you believe this is my pattern I have an awesome deal you should not pass up!)

QOTD:
"I haven't come far enough, and don't call me baby."