ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    LastPass Hacked, Change Your Master Password Now

    News
    hacking security
    10
    24
    7.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AmbarishrhA
      Ambarishrh
      last edited by

      http://lifehacker.com/lastpass-hacked-time-to-change-your-master-password-1711463571

      1 Reply Last reply Reply Quote 2
      • ?
        A Former User
        last edited by

        How can they say the passwords for other sites where not taken? if they have the master passwords they have everything.

        NicN 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          Wow, that is one significant hack!!

          1 Reply Last reply Reply Quote 1
          • AmbarishrhA
            Ambarishrh
            last edited by

            Not sure, as per Lastpass blog, "The investigation has shown, however, that LastPass account email addresses, password reminders, server per user salts, and authentication hashes were compromised."
            https://blog.lastpass.com/2015/06/lastpass-security-notice.html/

            So might be as a best practice, the advice for changing master password.

            One reason, I use 1Password, data is with me

            ? 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller
              last edited by

              An authentication hash does not give you access. You have to crack other parts of the system to be able to utilize that. A hash cannot be used instead of the password itself.

              ? 1 Reply Last reply Reply Quote 0
              • ?
                A Former User @scottalanmiller
                last edited by

                @scottalanmiller said:

                An authentication hash does not give you access. You have to crack other parts of the system to be able to utilize that. A hash cannot be used instead of the password itself.

                Yeah, but they still have the ability to crack them.

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • ?
                  A Former User
                  last edited by

                  In other news, the settings part (where you change the password) on the last pass site is now timing out for me.

                  1 Reply Last reply Reply Quote 1
                  • scottalanmillerS
                    scottalanmiller @A Former User
                    last edited by

                    @thecreativeone91 said:

                    @scottalanmiller said:

                    An authentication hash does not give you access. You have to crack other parts of the system to be able to utilize that. A hash cannot be used instead of the password itself.

                    Yeah, but they still have the ability to crack them.

                    Yes, it's a huge risk. But it hasn't been completely broken yet (as far as anyone knows.)

                    1 Reply Last reply Reply Quote 0
                    • ?
                      A Former User @Ambarishrh
                      last edited by

                      @Ambarishrh said:

                      https://blog.lastpass.com/2015/06/lastpass-security-notice.html/

                      This begs the question if it was found on Friday why did they wait so long to tell about it? Why where we not notified on Friday? @AmberLastPass

                      1 Reply Last reply Reply Quote 1
                      • ?
                        A Former User
                        last edited by

                        Got to the settings page then got this. Pretty annoying as a paying premium member.

                        password.PNG

                        ? 1 Reply Last reply Reply Quote 2
                        • ?
                          A Former User
                          last edited by

                          Others are saying that Servers are busy has been happening since 11am or so this morning. No signs of actually being able to change passwords yet, still getting the message.

                          1 Reply Last reply Reply Quote 0
                          • NicN
                            Nic @A Former User
                            last edited by

                            @thecreativeone91 said:

                            How can they say the passwords for other sites where not taken? if they have the master passwords they have everything.

                            Apparently the database where the master password hashes are stored was compromised, but not the database that stores all of your actual passwords that are used to log into sites. I'm assuming they are kept separate both for security reasons, and because the encryption on your site passwords has to be reversible whereas the master password they can just store a hash.

                            1 Reply Last reply Reply Quote 2
                            • ?
                              A Former User @A Former User
                              last edited by

                              @thecreativeone91 said:

                              Got to the settings page then got this. Pretty annoying as a paying premium member.

                              password.PNG

                              Still not working but, hey they added graphics to it now.

                              Capture.PNG

                              1 Reply Last reply Reply Quote 0
                              • gjacobseG
                                gjacobse
                                last edited by gjacobse

                                Ouch - I've been considering using Password Card - if they are still around...

                                Which they are....

                                1 Reply Last reply Reply Quote 0
                                • nadnerBN
                                  nadnerB
                                  last edited by

                                  Well, I'm changing my password. I even considered moving away from LastPass but I think that's a bit extreme.

                                  1 Reply Last reply Reply Quote 0
                                  • tonyshowoffT
                                    tonyshowoff
                                    last edited by

                                    I didn't even know lastpass existed until reading this and so nothing of significance was lost... for me. I feel bad for anyone who does suffer because of whatever the issue here was. Being able to take a bunch of hashes really almost always is a result of an SQL injection, probably UNION SELECT to just pull down all of the password hashes. For god's sake escape your queries.

                                    1 Reply Last reply Reply Quote 0
                                    • NicN
                                      Nic
                                      last edited by

                                      Everything I've read suggests that the encryption method LastPass uses means that even with the hashes and salts, brute forcing passwords would take a very long time, even with the weakest of passwords. As long as you change your password in the near future I'd say that you're safe.

                                      1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller
                                        last edited by

                                        Yes, cracking a good password hash is very non-trivial. Assuming that they have access to the Amazon cloud fleet, I'm guessing this is still quite some time to crack.

                                        1 Reply Last reply Reply Quote 0
                                        • DashrenderD
                                          Dashrender
                                          last edited by

                                          I agree with Nick and Scott - while this is not good, it's definitely not as bad as it sounds... the bad thing - non technical people won't understand why and they'll just crucify LastPass instead.

                                          If I mentioned this to my boss she would kill my desire to push out this service to our users.

                                          AmbarishrhA C 2 Replies Last reply Reply Quote 0
                                          • AmbarishrhA
                                            Ambarishrh @Dashrender
                                            last edited by

                                            @Dashrender said:

                                            I agree with Nick and Scott - while this is not good, it's definitely not as bad as it sounds... the bad thing - non technical people won't understand why and they'll just crucify LastPass instead.

                                            If I mentioned this to my boss she would kill my desire to push out this service to our users.

                                            Pushing last pass to users- is it as a suggestion to all users to manage their own pass or will it be used as a password manager for company use?

                                            DashrenderD 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post