Pages:
Author

Topic: LastPass Hacked (Read 1368 times)

legendary
Activity: 1736
Merit: 1006
December 23, 2022, 11:02:46 AM
#35
This thread aged quite nicely, and that's not sarcasm. Given the latest Lastpass hack revelation, criminals seem to have a copy of all your passwords. If you used a weak master password, you are in serious trouble.
legendary
Activity: 1148
Merit: 1014
In Satoshi I Trust
June 26, 2015, 01:36:55 PM
#34
It was bound to happen. I'm sure no one here was stupid enough to use them or any other online password manager. 


it is even more stupid than putting your wallet.dat in the cloud  Grin
hero member
Activity: 767
Merit: 500
June 26, 2015, 01:15:29 PM
#33
Such a dumb idea to let an online service hold your password. Thanks god for new advancements in this space. www.GetClef.com - passwordless login!

Doesnt sound like the best idea either. You are recognized by your fingerprint and then all your passwords are open? Fingerprints of that level can be faked so easily, its nearly funny. You only need to find or get a fingerprint on a glass or something and you already can authenticat as the owner of that fingerprint.

I would never put important passwords behind that.
fin

All you need is a sufficiently high resolution camera and a picture of someones fingertips to get their fingerprint, then from there you can easily reproduce it for scanners using standard office supplies.

http://www.theguardian.com/technology/2014/dec/30/hacker-fakes-german-ministers-fingerprints-using-photos-of-her-hands

Yes, or sellotape, superglue and a fingerprint someone would leave on a flat surface. Smiley Similar to crime scene investigation. So a thieve has every chance he wants. Cutting a finger is not even needed. Cheesy

going down the finger print lines, mythbusters even worked out a easy way to do it with basic stuff, but they refused to release that information to the public, and it worked with most fingerprint readers.
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
June 26, 2015, 08:56:29 AM
#32
Such a dumb idea to let an online service hold your password. Thanks god for new advancements in this space. www.GetClef.com - passwordless login!

Doesnt sound like the best idea either. You are recognized by your fingerprint and then all your passwords are open? Fingerprints of that level can be faked so easily, its nearly funny. You only need to find or get a fingerprint on a glass or something and you already can authenticat as the owner of that fingerprint.

I would never put important passwords behind that.
fin

All you need is a sufficiently high resolution camera and a picture of someones fingertips to get their fingerprint, then from there you can easily reproduce it for scanners using standard office supplies.

http://www.theguardian.com/technology/2014/dec/30/hacker-fakes-german-ministers-fingerprints-using-photos-of-her-hands

Yes, or sellotape, superglue and a fingerprint someone would leave on a flat surface. Smiley Similar to crime scene investigation. So a thieve has every chance he wants. Cutting a finger is not even needed. Cheesy
legendary
Activity: 3318
Merit: 2008
First Exclusion Ever
June 26, 2015, 05:22:27 AM
#31
Such a dumb idea to let an online service hold your password. Thanks god for new advancements in this space. www.GetClef.com - passwordless login!

Doesnt sound like the best idea either. You are recognized by your fingerprint and then all your passwords are open? Fingerprints of that level can be faked so easily, its nearly funny. You only need to find or get a fingerprint on a glass or something and you already can authenticat as the owner of that fingerprint.

I would never put important passwords behind that.

All you need is a sufficiently high resolution camera and a picture of someones fingertips to get their fingerprint, then from there you can easily reproduce it for scanners using standard office supplies.

http://www.theguardian.com/technology/2014/dec/30/hacker-fakes-german-ministers-fingerprints-using-photos-of-her-hands
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
June 26, 2015, 05:05:46 AM
#30
Such a dumb idea to let an online service hold your password. Thanks god for new advancements in this space. www.GetClef.com - passwordless login!

Doesnt sound like the best idea either. You are recognized by your fingerprint and then all your passwords are open? Fingerprints of that level can be faked so easily, its nearly funny. You only need to find or get a fingerprint on a glass or something and you already can authenticat as the owner of that fingerprint.

I would never put important passwords behind that.
legendary
Activity: 924
Merit: 1000
June 26, 2015, 01:11:01 AM
#29
im lol'ing on how many people dont understand how lastpass works..


What i know on how it works, is its not storing your passwords in the clear on their servers, its encrypted on your system, you can select how many times it hashes the password, and it hashes each and every password with a random salt, x amount of times you have told it, and then it blobs it into 1 single file, that it stores it online with your account, so when you sigh in on another system, using the main password and log in, it starts decrypting the blob, then once you go to a site it decrypts that file that is assigned to that site.

and just to add to it, they cannot reset your password online.

the hack may have scrapped the blobs for the accounts, but without them brute forcing each blob just to open it, only to find out and then brute forcing each file at who knows how many iterations its been encrypted, only to find that they have to work out which one is your email password.

if you have 2 factor authorisation (like yubikey), and never use your major password for anything website, guess what? you're safe, but just change your major password, for paranoia sake.

Thank you for clearing this up. I think nobody got hacked yet because of this incident, it would be all over the internet by now. Seems to me that lastpass did their homework wrt security!
hero member
Activity: 756
Merit: 502
CryptoTalk.Org - Get Paid for every Post!
June 25, 2015, 11:38:22 PM
#28
online password manager? what could possibly go wrong? Roll Eyes
newbie
Activity: 9
Merit: 0
June 25, 2015, 11:34:16 PM
#27
I know lots of you know about and use last pass, everytime the forum gets hacked more and more people from here begin to use it, well, im sorry but your account details have been hacked, email addresses, encrypted passwords and cleartext password reminder hints were all leaked,

http://cointelegraph.com/news/114652/lastpass-gets-hacked-time-for-passwordless-logins
Lesson learnt never use password managers
hero member
Activity: 767
Merit: 500
June 25, 2015, 11:04:39 PM
#26
im lol'ing on how many people dont understand how lastpass works..


What i know on how it works, is its not storing your passwords in the clear on their servers, its encrypted on your system, you can select how many times it hashes the password, and it hashes each and every password with a random salt, x amount of times you have told it, and then it blobs it into 1 single file, that it stores it online with your account, so when you sigh in on another system, using the main password and log in, it starts decrypting the blob, then once you go to a site it decrypts that file that is assigned to that site.

and just to add to it, they cannot reset your password online.

the hack may have scrapped the blobs for the accounts, but without them brute forcing each blob just to open it, only to find out and then brute forcing each file at who knows how many iterations its been encrypted, only to find that they have to work out which one is your email password.

if you have 2 factor authorisation (like yubikey), and never use your major password for anything website, guess what? you're safe, but just change your major password, for paranoia sake.
hero member
Activity: 588
Merit: 500
Will Bitcoin Rise Again to $60,000?
June 25, 2015, 03:54:56 PM
#25
Such a dumb idea to let an online service hold your password. Thanks god for new advancements in this space. www.GetClef.com - passwordless login!
hero member
Activity: 584
Merit: 500
June 24, 2015, 02:21:42 PM
#24
It was bound to happen. I'm sure no one here was stupid enough to use them or any other online password manager. 

What he said.  I think it's pretty common knowledge -- don't store your passwords online with a 3rd party.  That's a bad idea. Smiley

KeepassX works great.


Yes, its an incredible stupid idea to use a online password manager. If you use keepass2 then you can still use the cloud. Only your passwords are encrypted and no hacker can get them.

You will have your password file, which is encrypted with your pass, you can drop that in, for example your dropbox directory, then you can install the keepass app for android and dropbox app and you can use your passwords on your android phone too.

If you really want make 2 different password files if you have more risky passwords to protect. So that you dont need to open them all the time with the normal forum passwords and so on.
staff
Activity: 3500
Merit: 6152
June 24, 2015, 07:05:52 AM
#23
Wasen't that like 8 days ago or something ? anyway that's why I never use this password manager .
I personally use KeePass and I recommend it for a lot of people and they won a lot of awards : http://keepass.info/ , basically all your informations are stored in a simple file on your PC and not online , you need to remember one unique password and it's also Open source .
sr. member
Activity: 252
Merit: 250
Look My eyes
June 24, 2015, 06:55:53 AM
#22
I know lots of you know about and use last pass, everytime the forum gets hacked more and more people from here begin to use it, well, im sorry but your account details have been hacked, email addresses, encrypted passwords and cleartext password reminder hints were all leaked,

http://cointelegraph.com/news/114652/lastpass-gets-hacked-time-for-passwordless-logins

I use it on mozilla but not for bitcoin site, only use for some social media, i use 2fa to make secure my acc , if he can acces my lastpass im not sure he can login to my acc Smiley
legendary
Activity: 1386
Merit: 1000
English <-> Portuguese translations
June 24, 2015, 06:20:18 AM
#21
An online service to hold your passwords?
That's more stupid than keeping a file in your computer with all your passwords.
legendary
Activity: 3472
Merit: 10611
June 24, 2015, 06:14:17 AM
#20
i can never understand the need for services like lastpass.

it is not like i have 1000 different passwords that i need remembering. there is only a handful of important passwords that i can remember and write down on a piece of paper just in case i forgot.

besides, what i don't encrypt myself is not gonna be safe on the cloud anyways.
legendary
Activity: 2296
Merit: 1014
June 24, 2015, 04:57:54 AM
#19
Never store your passwords in other place than head, except not important password that you can store OFFLINE not online.
legendary
Activity: 3248
Merit: 1070
June 24, 2015, 02:32:42 AM
#18
another reason why i'll never trust any service like, that i'm in fact saving all my password on paper, no hacker ccan even dream of hacking that  Cheesy

Surprising its only posted here now, as the hack already happened last week.. Guess most people here use KeePass to have it all in their own control?

they will hack that too one day, it is only a matter of time

they should build a decentralized lastpass with cold storage for password, pretty much like a bitcoin cold storage wallet
full member
Activity: 196
Merit: 100
June 24, 2015, 02:29:38 AM
#17
I know lots of you know about and use last pass, everytime the forum gets hacked more and more people from here begin to use it, well, im sorry but your account details have been hacked, email addresses, encrypted passwords and cleartext password reminder hints were all leaked,

I do not know why people buy the software to store the important email addresses, key, and passwords. They could use Note pad to note everything and then zip it with 7zip and protect with the strong encrypted passwords. This way they will keep their secret things with themselves in their pocket, laptop or mobile phones.
hero member
Activity: 700
Merit: 500
June 24, 2015, 02:20:42 AM
#16
The last password you will ever need as its the golden goose for all the accounts once hacked into and a persons Achilles Heel.
That said remembering a lot of unique sets of passwords is complicated so it does seem like an inevitable outcome, but like Bitcoin wallets best to keep passwords offline.
Pages:
Jump to: