The best Hacker News stories from All from the past day

Go back

Latest posts:

The purpose of DRM is not to prevent copyright violations (2013)

A Review of the Zig Programming Language (Using Advent of Code 2021)

LastPass users warned their master passwords are compromised

Please don't use Discord for FOSS projects

Prince of Persia in JavaScript

“Play-to-Earn” and Bullshit Jobs

“Play-to-Earn” and Bullshit Jobs

The state of external retina displays

The state of external retina displays

Takeaways from looking for a new senior role in tech

Takeaways from looking for a new senior role in tech

The absurdity of renting a car will no longer be tolerated

Ontario bans non-competes and creates right to disconnect from work

Italian Courts Find Open Source Software Terms Enforceable

Italian Courts Find Open Source Software Terms Enforceable

Ubisoft deleted account with hundreds of dollars’ worth of games for inactivity

Ask HN: How did my LastPass master password get leaked?

Hi,<p>I've just had a bizarre thing happen and wanted to see if the HN community could come up with some theories as to what happened.<p>LastPass blocked a login attempt from Brazil (it wasn't me). According to an email I received from LastPass, this login was using the LastPass account's master password. The email doesn't look like it's a phishing attempt.<p>What troubles me is that the master password was stored in a local encrypted KeePassX file.<p>I can imagine that someone has my KeePassX file and the (completely different) password to this file. If that's the case, I'm in a world of hurt.<p>But are there any other possibilities? Is the email from LastPass accurate i.e. was the login attempt actually using my master password? Is there some LastPass extension installed on some computer still having a valid auth token allowing them to login as me to LastPass..?<p>I'm really confused, and scared.<p>Thanks for your help.<p>P.S. The LastPass account had 2FA set up, but I was able to simply remove it (since I didn't have access to the token anymore). That's scary too -- what's the point of a 2FA you can remove...??<p>---<p>Update:<p>- the email was truly not phishing -- the same information regarding the login attempt appears in my LastPass dashboard. I also talked to LastPass support over the phone, and they confirmed seeing the same information.<p>- There are 2 separate users in the thread below confirming that the same exact same thing happened to them, from the exact same IP range as me.<p>Either the 3 of us had the same malware/Chrome extension or somehow had our master passwords compromised...? Or...? Is this a LastPass issue?

Ask HN: What is your spiritual practice?

Your day-to-day one?

Buy a coal mine, drive a gas guzzler, and other uses of reverse logic

DIY Off-Grid Solar Power

< 1 2 3 ... 638 639 640 641 642 ... 823 824 825 >