Author

Topic: LastPass Hacked (Read 1353 times)

legendary
Activity: 1708
Merit: 1006
December 23, 2022, 12:02:46 PM
#35
This thread aged quite nicely, and that's not sarcasm. Given the latest Lastpass hack revelation, criminals seem to have a copy of all your passwords. If you used a weak master password, you are in serious trouble.
legendary
Activity: 1148
Merit: 1014
In Satoshi I Trust
June 26, 2015, 02:36:55 PM
#34
It was bound to happen. I'm sure no one here was stupid enough to use them or any other online password manager. 


it is even more stupid than putting your wallet.dat in the cloud  Grin
hero member
Activity: 767
Merit: 500
June 26, 2015, 02:15:29 PM
#33
Such a dumb idea to let an online service hold your password. Thanks god for new advancements in this space. www.GetClef.com - passwordless login!

Doesnt sound like the best idea either. You are recognized by your fingerprint and then all your passwords are open? Fingerprints of that level can be faked so easily, its nearly funny. You only need to find or get a fingerprint on a glass or something and you already can authenticat as the owner of that fingerprint.

I would never put important passwords behind that.
fin

All you need is a sufficiently high resolution camera and a picture of someones fingertips to get their fingerprint, then from there you can easily reproduce it for scanners using standard office supplies.

http://www.theguardian.com/technology/2014/dec/30/hacker-fakes-german-ministers-fingerprints-using-photos-of-her-hands

Yes, or sellotape, superglue and a fingerprint someone would leave on a flat surface. Smiley Similar to crime scene investigation. So a thieve has every chance he wants. Cutting a finger is not even needed. Cheesy

going down the finger print lines, mythbusters even worked out a easy way to do it with basic stuff, but they refused to release that information to the public, and it worked with most fingerprint readers.
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
June 26, 2015, 09:56:29 AM
#32
Such a dumb idea to let an online service hold your password. Thanks god for new advancements in this space. www.GetClef.com - passwordless login!

Doesnt sound like the best idea either. You are recognized by your fingerprint and then all your passwords are open? Fingerprints of that level can be faked so easily, its nearly funny. You only need to find or get a fingerprint on a glass or something and you already can authenticat as the owner of that fingerprint.

I would never put important passwords behind that.
fin

All you need is a sufficiently high resolution camera and a picture of someones fingertips to get their fingerprint, then from there you can easily reproduce it for scanners using standard office supplies.

http://www.theguardian.com/technology/2014/dec/30/hacker-fakes-german-ministers-fingerprints-using-photos-of-her-hands

Yes, or sellotape, superglue and a fingerprint someone would leave on a flat surface. Smiley Similar to crime scene investigation. So a thieve has every chance he wants. Cutting a finger is not even needed. Cheesy
legendary
Activity: 3318
Merit: 1958
First Exclusion Ever
June 26, 2015, 06:22:27 AM
#31
Such a dumb idea to let an online service hold your password. Thanks god for new advancements in this space. www.GetClef.com - passwordless login!

Doesnt sound like the best idea either. You are recognized by your fingerprint and then all your passwords are open? Fingerprints of that level can be faked so easily, its nearly funny. You only need to find or get a fingerprint on a glass or something and you already can authenticat as the owner of that fingerprint.

I would never put important passwords behind that.

All you need is a sufficiently high resolution camera and a picture of someones fingertips to get their fingerprint, then from there you can easily reproduce it for scanners using standard office supplies.

http://www.theguardian.com/technology/2014/dec/30/hacker-fakes-german-ministers-fingerprints-using-photos-of-her-hands
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
June 26, 2015, 06:05:46 AM
#30
Such a dumb idea to let an online service hold your password. Thanks god for new advancements in this space. www.GetClef.com - passwordless login!

Doesnt sound like the best idea either. You are recognized by your fingerprint and then all your passwords are open? Fingerprints of that level can be faked so easily, its nearly funny. You only need to find or get a fingerprint on a glass or something and you already can authenticat as the owner of that fingerprint.

I would never put important passwords behind that.
legendary
Activity: 924
Merit: 1000
June 26, 2015, 02:11:01 AM
#29
im lol'ing on how many people dont understand how lastpass works..


What i know on how it works, is its not storing your passwords in the clear on their servers, its encrypted on your system, you can select how many times it hashes the password, and it hashes each and every password with a random salt, x amount of times you have told it, and then it blobs it into 1 single file, that it stores it online with your account, so when you sigh in on another system, using the main password and log in, it starts decrypting the blob, then once you go to a site it decrypts that file that is assigned to that site.

and just to add to it, they cannot reset your password online.

the hack may have scrapped the blobs for the accounts, but without them brute forcing each blob just to open it, only to find out and then brute forcing each file at who knows how many iterations its been encrypted, only to find that they have to work out which one is your email password.

if you have 2 factor authorisation (like yubikey), and never use your major password for anything website, guess what? you're safe, but just change your major password, for paranoia sake.

Thank you for clearing this up. I think nobody got hacked yet because of this incident, it would be all over the internet by now. Seems to me that lastpass did their homework wrt security!
hero member
Activity: 756
Merit: 502
CryptoTalk.Org - Get Paid for every Post!
June 26, 2015, 12:38:22 AM
#28
online password manager? what could possibly go wrong? Roll Eyes
newbie
Activity: 9
Merit: 0
June 26, 2015, 12:34:16 AM
#27
I know lots of you know about and use last pass, everytime the forum gets hacked more and more people from here begin to use it, well, im sorry but your account details have been hacked, email addresses, encrypted passwords and cleartext password reminder hints were all leaked,

http://cointelegraph.com/news/114652/lastpass-gets-hacked-time-for-passwordless-logins
Lesson learnt never use password managers
hero member
Activity: 767
Merit: 500
June 26, 2015, 12:04:39 AM
#26
im lol'ing on how many people dont understand how lastpass works..


What i know on how it works, is its not storing your passwords in the clear on their servers, its encrypted on your system, you can select how many times it hashes the password, and it hashes each and every password with a random salt, x amount of times you have told it, and then it blobs it into 1 single file, that it stores it online with your account, so when you sigh in on another system, using the main password and log in, it starts decrypting the blob, then once you go to a site it decrypts that file that is assigned to that site.

and just to add to it, they cannot reset your password online.

the hack may have scrapped the blobs for the accounts, but without them brute forcing each blob just to open it, only to find out and then brute forcing each file at who knows how many iterations its been encrypted, only to find that they have to work out which one is your email password.

if you have 2 factor authorisation (like yubikey), and never use your major password for anything website, guess what? you're safe, but just change your major password, for paranoia sake.
hero member
Activity: 588
Merit: 500
Will Bitcoin Rise Again to $60,000?
June 25, 2015, 04:54:56 PM
#25
Such a dumb idea to let an online service hold your password. Thanks god for new advancements in this space. www.GetClef.com - passwordless login!
hero member
Activity: 584
Merit: 500
June 24, 2015, 03:21:42 PM
#24
It was bound to happen. I'm sure no one here was stupid enough to use them or any other online password manager. 

What he said.  I think it's pretty common knowledge -- don't store your passwords online with a 3rd party.  That's a bad idea. Smiley

KeepassX works great.


Yes, its an incredible stupid idea to use a online password manager. If you use keepass2 then you can still use the cloud. Only your passwords are encrypted and no hacker can get them.

You will have your password file, which is encrypted with your pass, you can drop that in, for example your dropbox directory, then you can install the keepass app for android and dropbox app and you can use your passwords on your android phone too.

If you really want make 2 different password files if you have more risky passwords to protect. So that you dont need to open them all the time with the normal forum passwords and so on.
staff
Activity: 3500
Merit: 6152
June 24, 2015, 08:05:52 AM
#23
Wasen't that like 8 days ago or something ? anyway that's why I never use this password manager .
I personally use KeePass and I recommend it for a lot of people and they won a lot of awards : http://keepass.info/ , basically all your informations are stored in a simple file on your PC and not online , you need to remember one unique password and it's also Open source .
sr. member
Activity: 252
Merit: 250
Look My eyes
June 24, 2015, 07:55:53 AM
#22
I know lots of you know about and use last pass, everytime the forum gets hacked more and more people from here begin to use it, well, im sorry but your account details have been hacked, email addresses, encrypted passwords and cleartext password reminder hints were all leaked,

http://cointelegraph.com/news/114652/lastpass-gets-hacked-time-for-passwordless-logins

I use it on mozilla but not for bitcoin site, only use for some social media, i use 2fa to make secure my acc , if he can acces my lastpass im not sure he can login to my acc Smiley
legendary
Activity: 1386
Merit: 1000
English <-> Portuguese translations
June 24, 2015, 07:20:18 AM
#21
An online service to hold your passwords?
That's more stupid than keeping a file in your computer with all your passwords.
legendary
Activity: 3472
Merit: 10611
June 24, 2015, 07:14:17 AM
#20
i can never understand the need for services like lastpass.

it is not like i have 1000 different passwords that i need remembering. there is only a handful of important passwords that i can remember and write down on a piece of paper just in case i forgot.

besides, what i don't encrypt myself is not gonna be safe on the cloud anyways.
legendary
Activity: 2296
Merit: 1014
June 24, 2015, 05:57:54 AM
#19
Never store your passwords in other place than head, except not important password that you can store OFFLINE not online.
legendary
Activity: 3248
Merit: 1070
June 24, 2015, 03:32:42 AM
#18
another reason why i'll never trust any service like, that i'm in fact saving all my password on paper, no hacker ccan even dream of hacking that  Cheesy

Surprising its only posted here now, as the hack already happened last week.. Guess most people here use KeePass to have it all in their own control?

they will hack that too one day, it is only a matter of time

they should build a decentralized lastpass with cold storage for password, pretty much like a bitcoin cold storage wallet
full member
Activity: 196
Merit: 100
June 24, 2015, 03:29:38 AM
#17
I know lots of you know about and use last pass, everytime the forum gets hacked more and more people from here begin to use it, well, im sorry but your account details have been hacked, email addresses, encrypted passwords and cleartext password reminder hints were all leaked,

I do not know why people buy the software to store the important email addresses, key, and passwords. They could use Note pad to note everything and then zip it with 7zip and protect with the strong encrypted passwords. This way they will keep their secret things with themselves in their pocket, laptop or mobile phones.
hero member
Activity: 700
Merit: 500
June 24, 2015, 03:20:42 AM
#16
The last password you will ever need as its the golden goose for all the accounts once hacked into and a persons Achilles Heel.
That said remembering a lot of unique sets of passwords is complicated so it does seem like an inevitable outcome, but like Bitcoin wallets best to keep passwords offline.
legendary
Activity: 1946
Merit: 1007
June 24, 2015, 02:30:44 AM
#15
Surprising its only posted here now, as the hack already happened last week.. Guess most people here use KeePass to have it all in their own control?
legendary
Activity: 1904
Merit: 1074
June 24, 2015, 02:17:16 AM
#14
I cannot believe that there are still people who would trust online password managers.  Shocked

Write it down on a piece of paper and laminate it. Keep it in a burnproof safe, if you are really paranoid. I used to use a standard password with different formats, and I remembered the standard password, but as you get older Alzimers Lite kicks in, and you start to forget the simple things.

Now I use different passwords for every site and I write it down / laminate it / store it in a safe place.  {Never store the site and the passwords together... Give the site a number and write this number and password together... then you write the site and the number on a seperate piece of paper, and store it in a different place.}

This way, nobody could get into your safe and figure out, what password is for what site. {The site is not on the list, only the number}
legendary
Activity: 924
Merit: 1000
June 24, 2015, 02:08:07 AM
#13
thanks for the news
i will never going to use a password manager again Sad

An offline password manager with a decent encryption like keepass2 is a good thing, but don't give out your master password only because it's convenient for you.
sr. member
Activity: 336
Merit: 251
June 24, 2015, 02:06:16 AM
#12
Never trusted LastPass.

Never trust anything online i.e. the cloud and never upload anything there unless I encrypted it myself.

If you want better password security just get KeePass. You have control over the encryption and the database is always under your own control.
hero member
Activity: 490
Merit: 500
37iGtdUJc2xXTDkw5TQZJQX1Wb98gSLYVP
June 24, 2015, 02:00:39 AM
#11
thanks for the news
i will never going to use a password manager again Sad
hero member
Activity: 812
Merit: 1000
June 24, 2015, 12:26:50 AM
#10
It was bound to happen. I'm sure no one here was stupid enough to use them or any other online password manager.  

What he said.  I think it's pretty common knowledge -- don't store your passwords online with a 3rd party.  That's a bad idea. Smiley

KeepassX works great.


Yup, KeepassX works great, but I only use it for websites which are not too important for me, for other sites I prefer to write the password down in a notebook in a way that only I can decrypt the message, the only way to steal the password from that would be if there was a robbery and the thief stole the book, which is very unlikely because a thief would generally look for things more precious than a note-book and even then S/He would not be able to understand the message.
full member
Activity: 164
Merit: 100
Im not 1FfmbHfnpaZjKFvyi1okTjJJusN455paPH
June 24, 2015, 12:17:31 AM
#9
I know lots of you know about and use last pass, everytime the forum gets hacked more and more people from here begin to use it, well, im sorry but your account details have been hacked, email addresses, encrypted passwords and cleartext password reminder hints were all leaked,

http://cointelegraph.com/news/114652/lastpass-gets-hacked-time-for-passwordless-logins

“An attacker could try to guess your master password, then use your per-user-salt and authentication hash to determine if their guess was correct. […] If your master password is weak or if your password reminder makes it easy-to-guess, then the attacker could significantly reduce the number of attempts needed to guess it correctly.”

im not use lastpass im use excel on local storage but this is seriously problem i hope all user read this news and change his password

 i want to ask if you have lastpass acc and you delete all your data in lastpass are hacker can't aces your data ? (because your data has been removed) ?
sr. member
Activity: 504
Merit: 250
June 24, 2015, 12:13:49 AM
#8
I've always had a shady feeling about lastpass, one entity with access to all of those passwords because lazy people simply volunteer them over due to convenience... Shame. 
legendary
Activity: 1036
Merit: 1000
Thug for life!
June 23, 2015, 08:57:50 PM
#7
Having a password manager is like getting married with a gold digger just for your money she's bound to cash out any time, the article does point to a good path which is passwordless logins.
hero member
Activity: 854
Merit: 1000
June 23, 2015, 08:48:40 PM
#6
I have never used a password manager because of this reason,I would be screwed if manager password is hacked,and they show they can hack it...
hero member
Activity: 910
Merit: 530
$5 24k Gold FREE 4 sign-up! Mene.com/invite/h5ZRRP
June 23, 2015, 08:32:51 PM
#5
I'll have to read the article, but that's exactly why I don't and wouldn't use that site, or any 3rd party password keepers. It was just bound to happen and there's too much to lose. Either by hackers, or the gov. possibly somehow, I don't know.

I use a different password for everything now and the only copies I keep are written on paper and safely stashed away.
hero member
Activity: 728
Merit: 500
June 23, 2015, 08:18:43 PM
#4
Online password manager?

Cool stuff.

 Cool
sr. member
Activity: 318
Merit: 251
June 23, 2015, 08:10:24 PM
#3
It was bound to happen. I'm sure no one here was stupid enough to use them or any other online password manager.  

What he said.  I think it's pretty common knowledge -- don't store your passwords online with a 3rd party.  That's a bad idea. Smiley

KeepassX works great.
legendary
Activity: 1090
Merit: 1000
June 23, 2015, 08:07:01 PM
#2
It was bound to happen. I'm sure no one here was stupid enough to use them or any other online password manager. 
hero member
Activity: 1498
Merit: 502
👉bit.ly/3QXp3oh | 🔥 Ultimate Launc
June 23, 2015, 07:35:38 PM
#1
I know lots of you know about and use last pass, everytime the forum gets hacked more and more people from here begin to use it, well, im sorry but your account details have been hacked, email addresses, encrypted passwords and cleartext password reminder hints were all leaked,

http://cointelegraph.com/news/114652/lastpass-gets-hacked-time-for-passwordless-logins
Jump to: