LastPass denies claims that master passwords may have been compromised

Discussion in 'other security issues & news' started by guest, Dec 28, 2021.

  1. guest

    guest Guest

    December 28, 2021
     
  2. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,692
    Location:
    South Wales, UK
    Worth changing the master password immediately...even if that does not help in the long term...will at least add complications for whom ever is behind this.
     
    Last edited: Dec 29, 2021
  3. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    5,257
    Location:
    .
    I did it as soon as I read the first post.
     
  4. JasonUK

    JasonUK Registered Member

    Joined:
    Nov 24, 2017
    Posts:
    112
    Location:
    UK
    Lastpass response/comment appears at:
    https://www.howtogeek.com/wp-content/uploads/2021/12/lastpass-logo-zoomed.jpg?height=200p&trim=2,2,2,2
    LastPass Says It Didn’t Leak Your Master Password
    Several LastPass users claim that they’re receiving emails from the company about unauthorized login attempts using their master passwords. Fortunately, LastPass has responded to the issue, and the password manager says it hasn’t leaked any user information.
    www.howtogeek.com

    It's also worth noting that LastPass cannot leak Master Passwords as, in their own words from their website;

    "Local-only encryption.
    Your data is encrypted and decrypted at the device level. Data stored in your vault is kept secret, even from LastPass. Your master password, and the keys used to encrypt and decrypt data, are never sent to LastPass’ servers, and are never accessible by LastPass."
     
  5. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,166
    Location:
    UK
  6. ProTruckDriver

    ProTruckDriver Registered Member

    Joined:
    Sep 18, 2008
    Posts:
    1,461
    Location:
    "An Apple a Day, Keeps Microsoft Away"
    Same here. I'll probably change the master password every few days for a while if that will help. :mad:
     
  7. zapjb

    zapjb Registered Member

    Joined:
    Nov 15, 2005
    Posts:
    5,675
    Location:
    USA still the best. But barely.
    Why do they have the master passwords?
     
  8. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,237
    Location:
    USA
    Last edited: Dec 29, 2021
  9. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,145
    Location:
    USA
    This. I thought they claimed to not have the master password, just an encrypted blob. I guess they lied. Makes me more happy I dropped this a few months ago and deleted my account. Which I hope actually happened and that they weren't storing my data without my knowledge or consent.
     
  10. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,237
    Location:
    USA
    When you say "they have the master passwords" who are you referring to? LogMeIn/LastPass states:

    "Your data is encrypted and decrypted at the device level. Data stored in your vault is kept secret, even from LastPass. Your master password, and the keys used to encrypt and decrypt data, are never sent to LastPass’ servers, and are never accessible by LastPass."
     
  11. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,277
    Location:
    Canada
    I think they are referring to the master password that you create to log into the program. I do not think they"have' them as per Victek's post.
     
  12. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,100
    Location:
    Canada


    https://support.logmeininc.com/lastpass/help/recover-your-lost-master-password-lp020010

     
  13. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,145
    Location:
    USA
    That is what they have always claimed. I'm still having to wonder how these accounts are being exploited when for most people this password will be unique. Somebody found a way somewhere.
     
  14. ClaytonThomas

    ClaytonThomas Registered Member

    Joined:
    Feb 4, 2018
    Posts:
    20
    Location:
    Sofia, Bulgaria
    I'm no longer a fan of Lastpass after switching to KeepassXC years ago. But here's an update:
    https://www.howtogeek.com/776614/lastpass-says-security-alerts-were-sent-in-error/

    LastPass Says Security Alerts Were Sent in Error
    It turns out, these alerts were sent in error, according to a statement from the company. After further investigation, however, the company found that the warnings were sent to users in error.
    From LastPass: Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. As a result, we have adjusted our security alert systems and this issue has since been resolved. These alerts were triggered due to LastPass’s ongoing efforts to defend its customers from bad actors and credential stuffing attempts. It is also important to reiterate that LastPass’ zero-knowledge security model means that at no time does LastPass store, have knowledge of, or have access to a users’ Master Password(s).
     
  15. guest

    guest Guest

    Updated article (and title):
     
  16. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    In other words, the master password can only be stolen on your device like smartphone, desktop or laptop. This also means that infostealing malware can in theory still do serious damage once they get access to your master password, but that's why you should be using 2FA to protect all of your most important online accounts.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.