Go to security school, GoTo – theft of encryption keys shows you need it
- Reference: 1674635288
- News link: https://www.theregister.co.uk/2023/01/25/goto_security_incident_update/
- Source link:
A third-party cloud storage service GoTo uses for its own products and affiliate company LastPass was attacked in August 2022. GoTo and LastPass revealed the incident in separate notifications that The Register covered after the companies 'fessed up in [1]November 2022 .
LastPass later [2]admitted that some of its source code was accessed, data stored in the cloud decrypted, and files containing customers' passwords copied. Thankfully those files were well encrypted, so customer data was likely not at risk unless they practised poor password hygiene.
[3]
Now GoTo has offered more information on the attack, revealing the attacker "exfiltrated encrypted backups from a third-party cloud storage service related to the following products: Central, Pro, join.me, Hamachi, and RemotelyAnywhere."
[4]
[5]
"We also have evidence that a threat actor exfiltrated an encryption key for a portion of the encrypted backups."
Thankfully the data was, again, decently protected.
[6]
"The affected information, which varies by product, may include account usernames, salted and hashed passwords, a portion of Multi-Factor Authentication (MFA) settings, as well as some product settings and licensing information," wrote GoTo CEO Paddy Srinivasan. "In addition, while Rescue and GoToMyPC encrypted databases were not exfiltrated, MFA settings of a small subset of their customers were impacted."
As the data was salted and hashed, Srinivasan expressed confidence that customers are safe.
He's nonetheless decided it's best to reset the affected users' passwords and/or reauthorize their MGA settings.
[7]LastPass admits attackers have a copy of customers’ password vaults
[8]LastPass source code, blueprints stolen by intruder
[9]Popular password manager LastPass to be spun out from LogMeIn
[10]Lawyers slam SEC for 'blatant fishing expedition' after Exchange mega-attack
"In addition, we are migrating their accounts onto an enhanced Identity Management Platform, which will provide additional security with more robust authentication and login-based security options," he wrote. Sounds like the right thing to do, but also suggests GoTo isn't confident in its existing systems.
That lack of confidence could be mutual for the company's customers. They have endured more than two months of secrecy about the incident, followed by updates two months apart.
[11]
There may be more unwelcome news to come: Srinivasan's post ends with "We appreciate your understanding while we continue to work expeditiously to complete our investigation." ®
Get our [12]Tech Resources
[1] https://www.theregister.com/2022/12/01/lastpass/
[2] https://www.theregister.com/2022/12/23/lastpass_attack_update/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y9EL0T2E3j9l7rE33mxtpgAAAEc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9EL0T2E3j9l7rE33mxtpgAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9EL0T2E3j9l7rE33mxtpgAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9EL0T2E3j9l7rE33mxtpgAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/12/23/lastpass_attack_update/
[8] https://www.theregister.com/2022/08/25/lastpass_security/
[9] https://www.theregister.com/2021/12/14/lastpass_spinout/
[10] https://www.theregister.com/2023/01/12/sec_covington_hafnium/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9EL0T2E3j9l7rE33mxtpgAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Persistent keys are the problem.....
SInce 1976, Alice and Bob have been able to use encryption WITH NO PERSISTENT KEYS, indeed with no transmitted keys and no public keys at all.
In the scheme they use (Diffie/Hellman) a secret key is calculated (briefly) at encryption time and is calculated (briefly) at decryption time, and in both cases the key is immediately destroyed.
(See refs below)
Maybe someone here can tell us why this scheme, or some similar scheme, cannot rid us of persistent keys......and rid us of the problem of key theft at the same time.
Ref: Applied Cryptography, Bruce Schneier --- Section 22.1
Ref: Cryptography Engineering, Ferguson/Schneier/Kohno -- Chapter 11
Re: Persistent keys are the problem.....
Because cryptography is hard ?
They coded and salted the hases, which is more than many do today. Not trying to find excuses, but they did better than most already.
You can always do more, especially where security is concerned. Maybe this "no persistent key" approach would break something else, or make everything more difficult ?
Re: Persistent keys are the problem.....
"Maybe someone here can tell us why"
The force is strong with this one. You are determined to make it difficult for the TLA agencies aren't you.
Re: Persistent keys are the problem.....
DH is an online protocol. Both parties send messages back and forth in order to agree on a shared temporary secret.
When you encrypt backups, you are sending an encrypted message to your future self. There is no way for future-you to send messages back to current-you, so the communication only goes one way and you can't implement protocols like DH.
LastPass
Why is it always LastPass?
"Password manager breached" - oh, it's LastPass again. Never anyone else.
I mean... are they the only ones being honest? Or the only ones being hacked?
Somebody else's computer
... and now some more somebodies computers - well at least the removes the risk of a single point of failure.