Users Of This Password Manager Aren’t Convinced Of Claims It Wasn’t Hacked
Users of LastPass reportedly received emails from the company alerting them to unauthorized login attempts with their master passwords. However, LastPass has since publicly said that it hasn’t been hacked or leaked user information, which has confused many of the app’s users.
One user, Greg Sadetsky, who shared the email he had received with Hacker News, told Input that he thinks of himself as “pretty paranoid.” He had been alerted that someone had tried to enter his account, with the message reading, “Someone just used your master password to try to log in to your account from a device or location we didn’t recognize.”
According to Sadetsky, he found the notification concerning because he had only used the password once—in LastPass—and had stored it in a secondary encrypted password manager called KeePassX. He had last accessed the password back in 2017, when he copied it from the second generator to use it on LastPass.
At first, he thought it could be malware, such as a clipboard sniffer, that got hold of his password when he copied and pasted it over from KeePassX years ago. Though, when he found out he wasn’t the only one who had received the emails from LastPass, it became more and more unlikely.
One clue that could point back to the culprit is that the multiple login attempts shared similar IP addresses. In the email notification, LastPass included the IP address from which someone had tried to access the account.
After discussing with other users, Sadetsky found that at least five users had attempts coming from foreign IP address beginning with the 160.116 range, though not all users saw their attempts starting with the same numbers.
LastPass told Input in an email statement that it still has no reason to believe its security system was bypassed or hacked into. It said: “It’s important to note that, at this time, we do not have any indication that accounts were successfully accessed or that the LastPass service was otherwise compromised by an unauthorized party. We regularly monitor for this type of activity and will continue to take steps designed to ensure that LastPass, its users, and their data remain protected and secure.”
It’s unsurprising that many of the affected users aren’t buying the company’s stance, especially in the case of Sadetsky, who hadn’t reused the same password for any other site. So how could a bad actor have gotten the information any other way?
Input noted that this could be a “false positive,” in which LastPass sent out these alert emails even though its security system had not been breached. It’s equally possible the firm is keeping the real reason or actual hacking attempt close to its vest.
“There’s an unknown floating in the air,” said Sadetsky. “There’s something going on that we can’t figure out.”