LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

The password manager service LastPass is now forcing some of its users to pick longer master passwords. LastPass says the changes are needed to ensure all customers are protected by their latest security improvements. But critics say the move is little more than a public relations stunt that will do nothing to help countless early adopters whose password vaults were exposed in a 2022 breach at LastPass.

LastPass sent this notification to users earlier this week.

LastPass told customers this week they would be forced to update their master password if it was less than 12 characters. LastPass officially instituted this change back in 2018, but some undisclosed number of the company’s earlier customers were never required to increase the length of their master passwords.

This is significant because in November 2022, LastPass disclosed a breach in which hackers stole password vaults containing both encrypted and plaintext data for more than 25 million users.

Since then, a steady trickle of six-figure cryptocurrency heists targeting security-conscious people throughout the tech industry has led some security experts to conclude that crooks likely have succeeded at cracking open some of the stolen LastPass vaults.

KrebsOnSecurity last month interviewed a victim who recently saw more than three million dollars worth of cryptocurrency siphoned from his account. That user signed up with LastPass nearly a decade ago, stored their cryptocurrency seed phrase there, and yet never changed his master password — which was just eight characters. Nor was he ever forced to improve his master password.

That story cited research from Adblock Plus creator Wladimir Palant, who said LastPass failed to upgrade many older, original customers to more secure encryption protections that were offered to newer customers over the years.

For example, another important default setting in LastPass is the number of “iterations,” or how many times your master password is run through the company’s encryption routines. The more iterations, the longer it takes an offline attacker to crack your master password.

Palant said that for many older LastPass users, the initial default setting for iterations was anywhere from “1” to “500.” By 2013, new LastPass customers were given 5,000 iterations by default. In February 2018, LastPass changed the default to 100,100 iterations. And very recently, it upped that again to 600,000. Still, Palant and others impacted by the 2022 breach at LastPass say their account security settings were never forcibly upgraded.

Palant called this latest action by LastPass a PR stunt.

“They sent this message to everyone, whether they have a weak master password or not – this way they can again blame the users for not respecting their policies,” Palant said. “But I just logged in with my weak password, and I am not forced to change it. Sending emails is cheap, but they once again didn’t implement any technical measures to enforce this policy change.”

Either way, Palant said, the changes won’t help people affected by the 2022 breach.

“These people need to change all their passwords, something that LastPass still won’t recommend,” Palant said. “But it will somewhat help with the breaches to come.”

LastPass CEO Karim Toubba said changing master password length (or even the master password itself) is not designed to address already stolen vaults that are offline.

“This is meant to better protect customers’ online vaults and encourage them to bring their accounts up to the 2018 LastPass standard default setting of a 12-character minimum (but could opt out from),” Toubba said in an emailed statement. “We know that some customers may have chosen convenience over security and utilized less complex master passwords despite encouragement to use our (or others) password generator to do otherwise.”

A basic functionality of LastPass is that it will pick and remember lengthy, complex passwords for each of your websites or online services. To automatically populate the appropriate credentials at any website going forward, you simply authenticate to LastPass using your master password.

LastPass has always emphasized that if you lose this master password, that’s too bad because they don’t store it and their encryption is so strong that even they can’t help you recover it.

But experts say all bets are off when cybercrooks can get their hands on the encrypted vault data itself — as opposed to having to interact with LastPass via its website. These so-called “offline” attacks allow the bad guys to conduct unlimited and unfettered “brute force” password cracking attempts against the encrypted data using powerful computers that can each try millions of password guesses per second.

A chart on Palant’s blog post offers an idea of how increasing password iterations dramatically increases the costs and time needed by the attackers to crack someone’s master password. Palant said it would take a single high-powered graphics card about a year to crack a password of average complexity with 500 iterations, and about 10 years to crack the same password run through 5,000 iterations.

Image: palant.info

However, these numbers radically come down when a determined adversary also has other large-scale computational assets at their disposal, such as a bitcoin mining operation that can coordinate the password-cracking activity across multiple powerful systems simultaneously.

Meaning, LastPass users whose vaults were never upgraded to higher iterations and whose master passwords were weak (less than 12 characters) likely have been a primary target of distributed password-cracking attacks ever since the LastPass user vaults were stolen late last year.

Asked why some LastPass users were left behind on older security minimums, Toubba said a “small percentage” of customers had corrupted items in their password vaults that prevented those accounts from properly upgrading to the new requirements and settings.

“We have been able to determine that a small percentage of customers have items in their vaults that are corrupt and when we previously utilized automated scripts designed to re-encrypt vaults when the master password or iteration count is changed, they did not complete,” Toubba said. “These errors were not originally apparent as part of these efforts and, as we have discovered them, we have been working to be able to remedy this and finish the re-encryption.”

Nicholas Weaver, a researcher at University of California, Berkeley’s International Computer Science Institute (ICSI) and lecturer at UC Davis, said LastPass made a huge mistake years ago by not force-upgrading the iteration count for existing users.

“And now this is blaming the users — ‘you should have used a longer passphrase’ — not them for having weak defaults that were never upgraded for existing users,” Weaver said. “LastPass in my book is one step above snake-oil. I used to be, ‘Pick whichever password manager you want,’ but now I am very much, ‘Pick any password manager but LastPass.’”

Asked why LastPass isn’t recommending that users change all of the passwords secured by the encrypted master password that was stolen when the company got hacked last year, Toubba said it’s because “the data demonstrates that the majority of our customers follow our recommendations (or greater), and the probability of successfully brute forcing vault encryption is greatly reduced accordingly.”

“We’ve been telling customers since December of 2022 that they should be following recommended guidelines,” Toubba continued. “And if they haven’t followed the guidelines we recommended that they change their downstream passwords.”

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Ryan Reynolds’ Maximum Effort is part of an upcoming 1.2 million-square-foot studio in Markham thumbnail

Ryan Reynolds’ Maximum Effort is part of an upcoming 1.2 million-square-foot studio in Markham

The space is being described as a fully integrated production studio for film, scripted and unscripted reality television, drama series, live-action, and animated feature films Canada’s own Ryan Reynolds, alongside his production and advertising company Maximum Effort, is set to establish a new 1.2 million-square-foot studio in Canada. Maximum Effort, which Reynolds co-founded with George
Read More
The Samsung Galaxy S22 Ultra has got new, revised renders of the main camera thumbnail

The Samsung Galaxy S22 Ultra has got new, revised renders of the main camera

29.09.2021 16:39 | Mobile Prošle nedelje su se pojavili prvi renderi Samsung Galaxy S22 serije, iz pouzdanih izvora. Standardni i Plus modeli izgledaju u najvećoj meri kao Galaxy S21 i Galaxy S21 Plus. Međutim, Ultra model je na tim renderima izgledao veoma drugačije.Sada je originalni izvor rendera (Steve Hemmerstoffer, odnosno @OnLeaks), objavio revidirane i prerađene…
Read More
Monster Hunter Rise landed on the Steam platform, October 14th, early access thumbnail

Monster Hunter Rise landed on the Steam platform, October 14th, early access

Capcom 宣佈《Monster Hunter Rise》將於 2022 年 1 月 12 日推出 Steam 平台,讓 PC 玩家也可以感受屠龍的快感 ! 而且 PC 版的遊戲會支援 4K 畫質,畫面中質感和紋理會有更好的處理,更會有高幀率顯示,讓玩家可以配合高配置的電競電腦或筆電,享受更流暢的遊戲體驗。操作方面,除了可以使用 Xbox 遊戲手掣,更可以配合鍵盤和滑鼠來操作,相信要出連續技或儲力技會更得心應手。而且 PC 版的《Monster Hunter Rise》更支援寬屏幕顯示,相信遊戲體驗會比目前 Nintendo Switch 更豐富。 《Monster Hunter Rise》 將登陸 Steam 平臺,並支援 4K 畫質《Monster Hunter Rise》的擴充內容 Sunbreak 預計會在 2022 年推出,屆時 Switch 及 PC 會同步更新。另外,為滿足一班心急的玩家,Capcom 會於 10 月 14 日率先推出 《Monster Hunter Rise》的體驗版。內容會包括遊戲中所有 14 種武器,讓未接觸過 Switch 版的玩家可以率先熟習並了解有關的系統及不同武器的操作。值得一提是遊戲對於電腦系統的要求並不高,建議配備…
Read More
Cyren: 300% rise in phishing attacks on bank customers thumbnail

Cyren: 300% rise in phishing attacks on bank customers

October 5, 2021 2:20 PM The Transform Technology Summits start October 13th with Low-Code/No Code: Enabling Enterprise Agility. Register now! Cyren detected a 300% increase in Chase Bank-related phishing URLs from mid-May to mid-August. This was unusual since it was a significant and sustained increase, not just a spike that lasted a few days. Launching…
Read More
Index Of News
Total
0
Share