Tihan and Zhou knew that the LastPass password was the MtGox API key. genjix' claim that no one else did is somewhat strange, it requires three persons where at least one of them claim to be a security expert not to recognize a clearly non-random string for what it is.
2. Keyrings like LastPass are great for fools who refuse to take responsibility for their own data/account security. But for a programmer or system administrator to provide one attack vector (externally sourced, no less!) that gives access to all parts of the system isn't just negligent, its deliberate and wilful.
LastPass does not contain your passwords. It contains an encrypted version of your passwords - and only you have the encryption key. Storing passwords in LastPass does not make them any more insecure than any other form of password storage you can use - while allowing you to use purely random and very long passwords, no duplicates, for all your other services.
Of course, it requires you to have a good master password (and/or use two factor authentication). LastPass go out of their way in making sure you understand the importance of that, and as I've already written before in a reply to Tihan, you have to be either completely unaware of any security practices or willfully ignorant to select something like an API key (a "known string") as password.
By "willfully ignorant" in this case I do mean that doing so creates a possibility where you can exploit that knowledge to claim a hack where no hack took place, later.
I'm still interested in why, and how, the source code got leaked. That provided the excuse needed for an inside job.
And LastPass didn't log the IP that reverted the master password. It's so weird.
LastPass.com
67.188.9.35
Master Password Changed
07/17/2012 08:30:52
LastPass.com
0.0.0.0
Master Password Reverted
Since you've referenced that email before. Zhou, what's the X-Originating-IP header in the email you got from the claimed hacker that referenced your LastPass account password? Does it match any IP listed in the LastPass log?
(I assume it will turn out to be a anon VPN or TOR exit node)
I believe the "LastPass" hack to be an inside job, from someone being fed up with having to deal with the Bitcoinica mess. I'm less sure the other hacks where.