We want to notify our community that on Friday, our team discovered and blocked suspicious activity on our network. In our investigation, we have found no evidence that encrypted user vault data was taken, nor that LastPass user accounts were accessed. The investigation has shown, しかしながら, that LastPass account email addresses, password reminders, server per user salts, and authentication hashes were compromised.
We are confident that our encryption measures are sufficient to protect the vast majority of users. LastPass strengthens the authentication hash with a random salt and 100,000 rounds of server-side PBKDF2-SHA256, in addition to the rounds performed client-side. This additional strengthening makes it difficult to attack the stolen hashes with any significant speed.
それにもかかわらず, we are taking additional measures to ensure that your data remains secure. We are requiring that all users who are logging in from a new device or IP address first verify their account by email, unless you have multifactor authentication enabled. As an added precaution, we will also be prompting users to update their master password.
An email is also being sent to all users regarding this security incident. We will also be prompting all users to change their master passwords. You do not need to update your master password until you see our prompt. しかしながら, if you have reused your master password on any other website, you should replace the passwords on those other websites.
Because encrypted user data was not taken, you do not need to change your passwords on sites stored in your LastPass vault. いつものように, we also recommend enabling multifactor authentication for added protection for your LastPass account.
Security and privacy are our top concerns here at LastPass. Over the years, we have been and continue to be dedicated to transparency and proactive measures to protect our users. In addition to the above steps, we’re working with the authorities and security forensic experts.
We apologize for the extra steps of verifying your account and updating your master password, but ultimately believe this will provide you better protection. Thank you for your understanding and support.
ジョーSiegrist
& LastPassのチーム
よくある質問
Why haven’t I been notified by email? Emails are being sent to all users regarding the security incident. While this takes a bit longer than posting on the blog, we are working to notify users as fast as possible.
Do I need to change my master password right now? LastPass user accounts are locked down. You can only access your account from a trusted IP address or device – そうでなければ, verification is requested. We are confident that you are safe on your LastPass account regardless. If you’ve used a weak, dictionary-based master password (eg: robert1, mustang, 123456799, password1!), or if you used your master password as the password for other websites you need to update it.
I would like to understand better what I should do!
In the message it says that I have to wait to change my master password and change it when prompted.
Suggestions needed:
Should I remove the OTP ( I have 50) and change the 2FA key code?
感謝
R
If the email address and password reminders were compromised then is it not possible for the attackers to hack into our email accounts and reset the master password? Could you explain exactly how the password reminders were compromised and what was compromised and how it could be used or not used? thanks.
それは “古いコメント” link does not work in the latest Firefox browser. Do I have to change all my passwords? They got the “Hash?” What is a “Hash?”
ハイ
Can somebody please explain how and why changing master pasword now would help. If the encrypted vaults were accessed, the stolen copies would still be using the old password. If my old master password were “123456”, changing it now to a strong one would be pointless.
While I understand the point of regularly changing password, I don;’t see how changing it now would prevent potential stolen copies to be opened. 乾杯.
“In our investigation, we have found no evidence that encrypted user vault data was taken, nor that LastPass user accounts were accessed.”
Later: “Because encrypted user data was not taken, you do not need to change your passwords on sites stored in your LastPass vault.”
Cheers :)
I confess that I am not tech savvy, so I can’t claim to fully understand the consequences of the Friday incident. I just received an email notification this evening. Since Friday, しかし, I’ve received two phone calls about my computer being compromised. They sounded like scam calls and I refused to cooperate, but I was perplexed about how the scammer might have gotten my phone number. Is it possible that it derives from the problem outlined in the security notice?
The possibility that they are related is about 0%.
Are the OTP master keys save, or I should generate new one. Thanks for reply.
Well that’s just ducky.
If I have a strong password and use 2 factor authentication, do I need to reset my master password? It seems like I shouldn’t be affected, but I just want to make sure.
I also use a strong (very strong) password and 2FA. I doubt that we are compromised fully, but we should indeed change our master passwords. Once the password wall is gone, there only remains the 2FA to bypass….
The answer is yes… The hashes were taken. That is your password encrypted. It will take time but what can be encrypted can be unencrypted… someday… somehow.
Also worth pointing out that your ‘Older Comments’ link doesn’t work (at least on Chrome and Safari on OSX). Clearly you have some justifiably angry and knowledgable clients posting here and I would like to be able to read what they have said about this security notice, as well as any responses you may have made.
I don’t see why some of these comment are so rude. I got this notification on monday. The incident took place on friday…. I have no problems with that and will continue to support this great software.
Looks like we have trolls in the comments. Don’t feed them
How about you go into detail of how you were hacked and how you plan on preventing that in the future?
Maybe you should be transparent.
同意して. Where is the like buttons.
Post attack, what authentication components/systems have been VERIFIED to not have been compromised? This is key to understanding the true level of risk exposure.
1) Multi factor authentication matrix keys?
2) Client trust enforcement for first time login from a different client and/or IP address?
3) Out of band multi factor authentication (text message, Eメール, etc)?
4) Others?
同意する, auto-translation is awful. Furthermore I don’t really understand why this post is so vaguely worded:
– You have been hacked which means you either have security issues or it is just a bad day for you. I guess it is not the latter. I would like to hear something about how this was even possible and what are you doing for making it impossible to happen again.
– Don’t try to make your responsibility seem smaller. It is mostly your fault something like this can happen.
– What does compromised mean? Are they (email addresses, etc) stolen?
– I think it is a shame that you are trying to confuse people by using words like ‘PBKDF2-SHA256′ and trying to make them feel false sense of security. It is good that you are providing information about your security, but don’t try to explain why you are good in such a blog post.
– Be much MUCH more clear: “Your master password has been stolen. Change it!”
People trust you, and you don’t honour it with this post. うん, it is not good marketing but much more honest. I hope these comments do not get lost.
The master passwords WERE NOT STOLEN IDIOT!
They were indeed… They were just encrypted. In time (a long time) those passwords could be uncovered and should in turn be changed.
I think the only mistake LastPass has really made here is the lack of information on what EXACTLY happened. The details they might think insignificant may help some of us to feel more secure and in the light on the issue. I went elsewhere (other than LastPass) to get more details because I did not feel full after reading the security release by LastPass. I learned little bits of information like that it was some Russian hacker group, 等. It’s not that I needed to know that (I really only need to hear “change your master pass”) but knowing more put me more at ease.
Everyone should change their master pass regardless of how encrypted LastPass hashes the passwords. It might take time but it would be worth trying to get someone’s bank login info. ;)
They told you to change your master password, if you can read.
only hashes have been stolen. are we discussing cryptography with non tech people, here? or are they just trolls trying to take profit from lastpass incident in favor of some other solution? uhmmm…
実際に, they said they would notify you if your master password is weak. You should also change your master password if you have used it on another site (along with the password used on the other site).
If you have multifactor authentication enabled (as you should), then even if they have your master password, you’d need the multiple authentication codes to authenticate.
No site is going to be perfect. The only thing you can do is make it harder to steal your info than the next person’s.
if you can’t live with that reality, then perhaps you’d best disconnect your computer from the Internet for the rest of your life.
Why did I have to find out about this problem through a third-party site? The least you guys could have done is sent an email notification to those who use your service. The severity or lack thereof, of the security issue is irrelevant. Your customers put a lot of trust in this service. It seems like you guys only care about protecting your company’s image as a safe service for people to use and would rather mitigate the damage by burying the issue.
Why isn’t this blog post on the top of your website? Instead its buried near the bottom of the page. Why is that? I think its so you can continue to sell your product with having to worry people who want to sign up. What your company is basically saying is that you don’t care about your existing customers base. “We already have their money, screw ’em.”
All you care about is growth and since adequately informing people about a security problem would scare off potential customers, you’ve chose not to do it.
They did send out an e-mail. I got one at 5:19pm PST.
I have not received an email. And I did not find any notice when I signed in to my vault. And the notice on the main page is indeed way down at the bottom and not made particularly prominent. The only way I found out was thru a ZDNET story.
I expect better. しかし, その後, I’ve been disappointed before.
I get a lot for my money. Your passwords weren’t compromised. Stop whining.
私, 危険にさらしています, found out through my RSS reader and the Lifehacker post.
While we use 2-factor and master passwords with good entropy, our LastPass vaults contain so much stuff that I’d probably jump off a bridge if it got breached (yeah, that’s a bit melodramatic, but accurate).
So even though my trust-level for LastPass is about as high as it gets with any provider I use, finding this out *today* when it happened on *Friday* and not from *you* but from *Lifehacker* is unacceptable.
I must have inadverdently ordered two Last Pass memberships last year. I had cancelled the renewal for the next year . Now I have found that I have been charged for another year which I do not want. Please cancel this subscription and credit my account. 感謝.
Nan Smith
99% of the post made here reflect users who lack any critical thinking skills. Play Devil’s Advocate, what could have possibly gone wrong if within 15 seconds of this event you had received a notice and you had rushed here to changed your password? What confidence would you have had that ‘someone’ was not still within the network capturing the changes?
I was trying to access my account from my work computer. While I appreciate your vigilance, I never was able to get in, even with verification. Nor do I know how to contact you.
ヘイ, guys! Turn off you fucking auto translation crap. It makes texts quite shity.
Take a look at it:
– “The investigation has shown, однако, その”,
– “Тем не менее, we are taking additional measures”,
– “Однако, if you have reused your master password”
et cetera.
It rewrites comments too. Not only template (like “someone says” -> “someone говорит”) but comment itself also.
clean tup your language and maybe someone would listen to you.