news.volyx.in

Ask HN: How did my LastPass master password get leaked?

877 points by gregsadetsky · 1726 days ago · 515 comments on HN

Article summary

The author's LastPass master password was allegedly used in a login attempt from Brazil, despite being stored in a local encrypted KeePassX file. The author is concerned about how this happened and is seeking explanations. LastPass support confirmed the login attempt, and two other users reported similar incidents from the same IP range. The author is considering alternative password managers, such as Bitwarden.

Main themes

  • password security
  • LastPass security incident
  • alternative password managers
  • cloud-based vs local password management
  • browser extension security
  • malware and clipboard scraping risks

What commenters say

  • Malware or a compromised browser extension may have accessed the master password.
  • A clipboard scraper could have obtained the password if it was copied and pasted.
  • LastPass may have a security issue that allowed the master password to be compromised.
  • Using a cloud-based password manager may not be necessary and could introduce security risks.
  • Bitwarden is a trustworthy alternative to LastPass due to its open-source nature.
  • Hosting one's own password manager server can provide additional security and control.
  • Some users prefer to use local password managers like KeePass to avoid relying on third-party providers.
  • The incident may indicate a larger issue with LastPass's security practices.