Lastpass leak again

Hmmmm if it is encrypted. All that the hacker will get is garbage. Although sha256 isn’t the best algo anyway..

read more about it

https://crypto.stackexchange.com/questions/35639/is-sha-256-safe-and-difficult-to-crack#35642
That answer mentions “PBKDF” as more secure. Funnily, lastpass uses PBKDF as far as I know. But it wasn’t the encryption algo that was vulnerable, though.


All said, I would still be confident to even host that encrypted file openly. It’s secure enough for what it is being used for…
Totally agree there, while having sha256 is better than not encrypted at all, but let's also consider the facts of getting around that encrption.

Firstly, MS has access to all those keys to read your files though which itself isn't safe already, granted that it may be reading billions and billions of files on a daily to weekly basis but surely, there is some sort of metadata linking 1 data to another account as that's how it takes automated actions against fenders too right.
Now, where is those data stored in.
To make it worse, their "Paid azure services" Azure have these exploits every other year, so just imagine the "Free one" you people are using.
Literally no different than icloud storage being leaked ever year
And like this article states (In August 2021, One of the biggest hacks of all time happened, and the world barely noticed.)
Why the world barely notice, it's because they are able to cover most of it up with security update news and what not.
- https://www.theregister.com/2022/10/19/azure_service_fabric_vulnerability
https://www.theverge.com/2021/8/27/22644161/microsoft-azure-database-vulnerabilty-chaosdb- https://www.techradar.com/news/new-azure-exploit-could-let-hackers-create-a-skeleton-key

So yeah, most privacy-centric people will be sketchy to store anything of value in icloud nor MS.
Let's not forget, your account is also your key and accounts are constantly bruteforced on a daily basis.

giphy.gif


My Lastpass email is [email protected]

And my Lastpass master password is 123456789

I don't think the hacker's will guess my master password.

it's too obvious
Password must meet complexity requirements !!!
 
why you guys not save password in a text, excel or word file. If you want to access it from any where then make it password protected rar archive then upload it in mega or gdrive. May be it is safest method to save password and user name
 
Totally agree there, while having sha256 is better than not encrypted at all, but let's also consider the facts of getting around that encrption.

Firstly, MS has access to all those keys to read your files though which itself isn't safe already, granted that it may be reading billions and billions of files on a daily to weekly basis but surely, there is some sort of metadata linking 1 data to another account as that's how it takes automated actions against fenders too right.
Now, where is those data stored in.
To make it worse, their "Paid azure services" Azure have these exploits every other year, so just imagine the "Free one" you people are using.
Literally no different than icloud storage being leaked ever year
And like this article states (In August 2021, One of the biggest hacks of all time happened, and the world barely noticed.)
Why the world barely notice, it's because they are able to cover most of it up with security update news and what not.
- https://www.theregister.com/2022/10/19/azure_service_fabric_vulnerability
https://www.theverge.com/2021/8/27/22644161/microsoft-azure-database-vulnerabilty-chaosdb- https://www.techradar.com/news/new-azure-exploit-could-let-hackers-create-a-skeleton-key

So yeah, most privacy-centric people will be sketchy to store anything of value in icloud nor MS.
Let's not forget, your account is also your key and accounts are constantly bruteforced on a daily basis.

giphy.gif



Password must meet complexity requirements !!!
True. There is more to it than just the algo. The biggest example of that is Lastpass itself. Agreed :)
 
why you guys not save password in a text, excel or word file. If you want to access it from any where then make it password protected rar archive then upload it in mega or gdrive. May be it is safest method to save password and user name
Because that's actually not practical, imagine having thousands of passwords.
Scrolling through them all you will also risk the on-lookers who may see your pw or even record them down.
What if you are using a public/work device (how are you sure they are going to "safely delete that file?
Gdrive & mega are on par with MS drive in terms of security as @Gogol and i discussed earlier with Mega being alot worse (just take a read at this for example https://www.cloudwards.net/mega-security-flaw/)
And lastly, that password better a strong one which most likely it won't be since you won't be able to remember it, as "weak" ones can be easily brute force through through various online tools. and those same tools can be used to break through "stronger ones".
 
Last edited:
They updated their plugin recently and it's been affecting a lot of sites I visit - basically the overlay they wrote creates an iframe/invisible div positioned absolutely over things.

Lastpass was a great idea, but they've been extremely sloppy and clawing back at features to get people to upgrade to pro.

Easier to port over to Google, where it gets synced and a bit more secure.
 
No it isn't
Onedrive is not E2EE for starters, don't delude yourself thinking it is.
Second of all, MS File contents is encrypted in transit ONLY just like your outlook & gmail emails, they are NOT E2EE.
Ontop of that, MS has your keys to unlock shit and they also reserves the right to review files to ensure compliance with their policies and law enforcement etc.
Just like MS has keys to your "BitLocker" keys you generated, if you ever lose yours, there has been cases reported when you can actually call them up and get it unlocked.
How fucked is that?
I don't think you understood me correctly.

The KeyPass key file is encrypted, you are the only one with access to said key file. You can stick it on OneDrive or any private server for the convenience of cloud synching. Or you can keep it offline.
 
One Drive?
MS gets fucked and hacked every other week
Not to mention, they will scan your shit and read your data.
lmfao
That's like purposely bending over
Linux user here:
Microsoft... What? Where? What?
*moves along*
 
This is an update on what they discovered, not a new leak.
 
I don't even understand why you people use this kind of apps :confused:
 
I started using it years many years ago....although now I wish I didn't :(

Are there any good alternatives?
BitWarden. I think you can self-host it as well. Importing from LastPass is also possible, but I am tense about changing 600+ passwords. :D
 
Hmmmmmmmmm
LastPass admitted
What We’ve Learned

Based on our investigation to date, we have learned that an unknown threat actor accessed a cloud-based storage environment leveraging information obtained from the incident we previously disclosed in August of 2022. While no customer data was accessed during the August 2022 incident, some source code and technical information were stolen from our development environment and used to target another employee, obtaining credentials and keys which were used to access and decrypt some storage volumes within the cloud-based storage service.
So even if it's encrypted do you REALLY trust LastPass with your keys ? :p
 
Back
Top