LastPass' breach update was full of lies, omitted damning info, tried to present the August 2022 incident and the data leak as two separate events, and more
Context & Ripple Effects
LastPass initially said the August intrusion had not shown access to customer data or encrypted vaults, but its later disclosure tied customer-data access to information taken in that incident. The latest critique centers on whether the company presented that connected sequence as separate events.
The arc sharpened days earlier when LastPass said attackers obtained a backup copy of encrypted and unencrypted vault data using cloud-storage keys taken from an employee. That makes the framing of the August compromise central to customers’ understanding of their exposure.
First-order effects
- LastPass faces an immediate credibility problem: customers must reconcile its earlier assurance that customer data had not been accessed with disclosures that the August breach enabled later access to cloud-stored data.
- Customers and organizations using LastPass have to assess the incidents as a linked attack chain rather than rely on the narrower initial description of the August intrusion.
Second-order effects
- Password-manager competitors gain a clear trust and communications contrast as LastPass customers evaluate whether its disclosures gave them a complete basis for risk decisions.
- Security teams that use LastPass must account for the cloud-storage compromise and vault-data theft together when reviewing vendor notifications and internal response records.
Third-order effects
- If vendors continue to describe connected compromises as discrete events, breach disclosure will be judged increasingly on whether it explains the full attack path, not simply whether each individual statement is technically bounded.
- The episode points to trust becoming a durable competitive factor for credential-management providers, alongside the security of their systems.
The trend: Cybersecurity vendors are being judged not only on breach containment but on whether their incident disclosures accurately connect the stages of an attack.
Related: LastPass · LastPass discloses customer data access via cloud storage · LastPass says vault backup data was stolen · LastPass’s August breach disclosure
Related Coverage
- LastPass Tries To Bury The Full Scope Of Its Disastrous Privacy Breach Behind The Christmas Holiday Techdirt
- Security researcher weighs in on LastPass' security breach and it's not good Phandroid
- Security analyst: LastPass statement on breach includes ‘half-truths and outright lies’ 9to5Mac
- LastPass Breached, Customers' Password Vaults Stolen Pixel Envy
- I recently wrote a post detailing the recent #LastPass breach from a #password cracker's perspective, and for the most part it was well-received and widely boosted. … @epixoip@infosec.exchange
- I'm on break and trying not to pay tooooo much attention but do we know anything about who was behind the LastPass beach? Crypto thieves? APT? Whodunnit? Also, here's a photo of our local beach that I took this morning... just had to share because it's beautiful. @riskybusiness@infosec.exchange
- I just wanted to provide an update on the #LastPass debacle. Many people have reported that they've found their accounts had the default password iteration count of 5000. This is a screenshot of my mom's account, and I kid you not, it was set to 1. @particles@treehouse.systems
- @particles@treehouse.systems So before #LastPass increased the iteration count to 100,100 they had 5,000. Before they increased the iteration count to 5,000 they had 500. And before they increased the iteration count to 500 they had 1. … @WPalant@infosec.exchange
- I have a person comment on my blog that their #LastPass account was set to 500 (in words: five hundred) PBKDF2 iterations. That's factor 620 (!!!) less than what OWASP currently recommends. … @WPalant@infosec.exchange
- I'm sure that Lastpass setting the delete account div to display: none was a perfectly coincidental defect @chiesennegs@infosec.exchange
- @WPalant this is an excellent analysis! I'd like to add that their wording around “Secure Notes” created a huge amount of confusion, where many of us assumed what Lastpass was doing was *less secure* than what they were actually doing. … @sawaba@infosec.exchange
- Around the same time, I reported a different cryptographic issue in 1Password. The 1Password timeline went like this: 2022-04-07: Issue reported 2022-04-07: Issue analyzed, determined to be dead code that needs to be removed anyway. … @soatok@furry.engineer
- As with many BugCrowd triages, they didn't understand the severity of the cryptographic issue I had disclosed. Naturally, I had thought the developers of an password manager (which heavily uses cryptography) would care more about this class of issue if they noticed it post-triage. … @soatok@furry.engineer
- @epixoip No, the server-side iterations were a joke. They only applied that to the hash used to verify correct logins, but the encryption key was still derived with 5000 iterations and it was used to encrypt pretty much everything. … @WPalant@infosec.exchange
- @epixoip Yeah. Back in 2018 I urged them to check their logs for suspicious referrers on requests to that script. Just to see whether anybody was already stealing this data. Because the vulnerability was way too obvious. … @WPalant@infosec.exchange
- Interesting detail from the #LastPass announcement: “Since 2018, we have required a twelve-character minimum for master passwords.” My test account from 2018 still has an eight-characters password. … @WPalant@infosec.exchange
- A brief history of #LastPass security research: November 2015: URLs and metadata are not encrypted. https://www.blackhat.com/... (page 67) January 2017: URLs and metadata are not encrypted. https://hackernoon.com … @WPalant@infosec.exchange
- Here's what I want from a password manager: 1. Stores my passwords in the caldera of an active volcano. 2. I can access it with a 6-digit PIN from any computer on the Internet. I don't understand why this is so hard for the industry to get right. @matthew_d_green@ioc.exchange
- Writing more about #LastPassBreach feels like beating a dead horse. But I had a look at the official statement again and it is highly misleading. I felt the need to provide some context that #LastPass is willingly omitting. … @WPalant@infosec.exchange
- @epixoip Absolutely. In my latest blog post I take apart their public statement and show how many issues have been known and ignored for a long time. And #LastPass continues to ignore and downplay them even now, when they've put people at risk. … @WPalant@infosec.exchange
- Maybe all along the real password was the non-expiring token in the password reset URL that was generated along the way ❤️ @DaveFlater@infosec.exchange
- Imagine how many customers Lastpass has Now imagine how many employees are using it at each of those customers Now imagine how many passwords each of those employees have Now imagine how many of those employees … @sawaba@infosec.exchange
- Why wouldn't you encrypt the URLs and username field of a password vault. Honestly what even was going on over at LastPass. @matthew_d_green@ioc.exchange
- @sawaba for everyone spinning their wheels over Secure Notes being in plaintext - they look to be encrypted, see Idx 4: https://github.com/... @Opalsec@infosec.exchange
- I published an article on the #LastPassBreach: https://palant.info/... This is very serious, no matter what #LastPass says. From the article: “This makes it sound like decrypting the passwords you stored with LastPass is impossible. … @WPalant@infosec.exchange
- Another point of clarification— I am not saying all of these values are stored in the vault in the clear, I am only analyzing what is transmitted to LastPass' servers. … @eric_capuano@infosec.exchange
- This is so messed up. If the announcement was made at any other time, I'd be saying “imagine the impact to productivity and business value, just to change all these passwords” Because it was announced today … @sawaba@infosec.exchange
- If you're looking to switch away from #Lastpass, I really enjoy and recommend 1Password. The UX is great and it has an awesome option for devs - the 1Password #CLI tool: “With 1Password CLI … @signalblur@infosec.exchange
- Quick clarification on what I mean by “transmitted encrypted” or “transmitted in the clear” ALL of this traffic is sent over TLS (encrypted), I am referring to the data itself inside the payload, whether or not it is encrypted client side before be transmitted to LastPass servers. @eric_capuano@infosec.exchange
- If you are a #LastPass user and a #journalist, here is a completely random reminder that you're likely eligible to use 1Password at no charge. https://1password.com/... @zak@infosec.exchange
- Just switched to 1Password after 7 years of LastPass. The 50% off link @troyhunt@infosec.exchange posted last year still worked for me. https://www.troyhunt.com/... #1password #lastpass @callum_mckenna@hachyderm.io
- Ok, I was tired of rumors speculating about which #LastPass fields appear to be encrypted client-side before being sent to LastPass, so I ran some tests of my own. For a basic “Password” item, here is what I can tell so far. … @eric_capuano@infosec.exchange
- I have found the first of will likely be many non-expiring password reset URLs that you may have had stored in #LastPass If you had a ‘maxmind.com’ URL in LastPass that included ‘set-password?token=’ in the parameters … @eric_capuano@infosec.exchange
- This is a great breakdown of LastPass's blogpost about their security breach and everything left unsaid. Even if you don't blame them for being breached given how much of a high value target they are … @carnage4life@mas.to
- Many of you have been asking for my thoughts on the #LastPass breach, and I apologize that I'm a couple days late delivering. Apart from all of the other commentary out there, here's what you need to know from a #password cracker's perspective! … @epixoip@infosec.exchange
Discussion
-
@LukaszOlejnik@mastodon.social
Lukasz Olejnik
on mastodon
LastPass breach is much more serious than the official Breach Notice wants you to know. It is, however, very cleverly crafted. Essentially cybersecurity/privacy PR. Decrypted here @WPalant@infosec.exchange — so have a look. …
-
@joshbressers@mastodon.social
Josh Bressers
on mastodon
There will be time for smug comments about LastPass later Actually useful information is to first migrate to a different service. LastPass shouldn't be trusted at this time. Do not use the same master password Once migrated. …
-
@kennwhite@mastodon.social
Kenn White
on mastodon
The painful thing for LastPass users who did unfortunately reuse their master password on other sites is that this case is now an *offline* attack - which means 2FA or changing one's LastPass web password …
-
@kennwhite@mastodon.social
Kenn White
on mastodon
For the vast majority of people, having some kind of secure centralized (yes, cloud-based) password management with straightforward recovery & trusted family/guardian delegation is the probably the best option. …
-
@networkchuck
@networkchuck
on x
This bad boy can crack into your LastPass vaults in 3 seconds. 😜 https://twitter.com/...
-
@saradietschy
@saradietschy
on x
Not too freaked out by the LastPass hack since my Master Password was insane however it was the last straw for me re: LastPass — I spent yesterday figuring out a new password manager and changing a lot of important passwords / making sure they all have 2factor set up
-
@gcluley
Graham Cluley
on x
This analysis by @WPalant of LastPass's PR statement about its data breach is pretty damning... :( I do hope LastPass users who need to take action haven't missed what's going on amid all this Christmas/New Year malarkey https://palant.info/...
-
@woonomic
Willy Woo
on x
The more I learn about the @LastPass breach the more pissed their customers should be. They did not encrypt your URLs or your last use of a password. So basically they could monitor your web activity. They reduced your security for their own benefit. https://twitter.com/...
-
@0xfoobar
@0xfoobar
on x
Done using any sites which require a private key signature to simply connect a wallet. It's absurd authentication overreach, and explicitly training users to get hacked. Goodbye to @opensea, @1inch, and many more. Do better
-
@0xfoobar
@0xfoobar
on x
@opensea @1inch Much like LastPass arguing in past years that unencrypted URL info was “nothing to worry about”, sites which push this feature plainly reveal they don't care one bit about user safety, and are destined for even worse privacy breaches in the future
-
@j0hnnyxm4s
@j0hnnyxm4s
on x
Extremely important, and generally overlooked: the LastPass breach included UNENCRYPTED URLs, which may mean your intranet URLs and perhaps external URLs you generally don't want crawled have been leaked: https://www.seroundtable.com/ ...