32 Followers
64 Following
479 Posts
Open Source developer. Electronic musician. Single parent. Widower. Politically neutral.
Bloghttps://samiam.org/blog/
My musichttps://caulixtla.com/music
GitHubhttps://github.com/samboy

Many of you have been asking for my thoughts on the #LastPass breach, and I apologize that I'm a couple days late delivering.

Apart from all of the other commentary out there, here's what you need to know from a #password cracker's perspective!

Your vault is encrypted with #AES256 using a key that is derived from your master password, which is hashed using a minimum of 100,100 rounds of PBKDF2-HMAC-SHA256 (can be configured to use more rounds, but most people don't). #PBKDF2 is the minimum acceptable standard in key derivation functions (KDFs); it is compute-hard only and fits entirely within registers, so it is highly amenable to acceleration. However, it is the only #KDF that is FIPS/NIST approved, so it's the best (or only) KDF available to many applications. So while there are LOTS of things wrong with LastPass, key derivation isn't necessarily one of them.

Using #Hashcat with the top-of-the-line RTX 4090, you can crack PBKDF2-HMAC-SHA256 with 100,100 rounds at about 88 KH/s. At this speed an attacker could test ~7.6 billion passwords per day, which may sound like a lot, but it really isn't. By comparison, the same GPU can test Windows NT hashes at a rate of 288.5 GH/s, or ~25 quadrillion passwords per day. So while LastPass's hashing is nearly two orders of magnitude faster than the < 10 KH/s that I recommend, it's still more than 3 million times slower than cracking Windows/Active Directory passwords. In practice, it would take you about 3.25 hours to run through rockyou.txt + best64.rule, and a little under two months to exhaust rockyou.txt + rockyou-30000.rule.

Keep in mind these are the speeds for cracking a single vault; for an attacker to achieve this speed, they would have to single out your vault and dedicate their resources to cracking only your vault. If they're trying 1,000 vaults simultaneously, the speed would drop to just 88 H/s. With 1 million vaults, the speed drops to an abysmal 0.088 H/s, or 11.4 seconds to test just one password. Practically speaking, what this means is the attackers will target four groups of users:

1. users for which they have previously-compromised passwords (password reuse, credential stuffing)
2. users with laughably weak master passwords (think top20k)
3. users they can phish
4. high value targets (celebs, .gov, .mil, fortune 100)

If you are not in this list / you don't get phished, then it is highly unlikely your vault will be targeted. And due to the fairly expensive KDF, even passwords of moderate complexity should be safe.

I've seen several people recommend changing your master password as a mitigation for this breach. While changing your master password will help mitigate future breaches should you continue to use LastPass (you shouldn't), it does literally nothing to mitigate this current breach. The attacker has your vault, which was encrypted using a key derived from your master password. That's done, that's in the past. Changing your password will re-encrypt your vault with the new password, but of course it won't re-encrypt the copy of the vault the attacker has with your new password. That would be impossible unless you somehow had access to the attacker's copy of the vault, which if you do, please let me know?

A proper mitigation would be to migrate to #Bitwarden or #1Password, change the passwords for each of your accounts as you migrate over, and also review the MFA status of each of your accounts as well. The perfect way to spend your holiday vacation! Start the new year fresh with proper password hygiene.

For more password insights like this, give me a follow!

โลกเราไม่เคยสงบ
---
RT @DavidHe11952876
December 23, 2022, ~ Explosion ~ Popocatepetl Volcano, Mexico 19:21 CDT #volcano #popocatepetl #mexico Thank you to Webcamsdemexico.
https://twitter.com/DavidHe11952876/status/1606486618428575745
Volcano Time-Lapse on Twitter

“December 23, 2022, ~ Explosion ~ Popocatepetl Volcano, Mexico 19:21 CDT #volcano #popocatepetl #mexico Thank you to Webcamsdemexico.”

Twitter

RT @[email protected]

It's surreal to watch financial news talk about regular people having money to spend and job security as a negative thing. If you ever needed convincing that the health of "the economy" is a conspiracy against working people, watch this clip from CNBC that just aired.

🐦🔗: https://twitter.com/paleofuture/status/1605938647139852288

Matt Novak on Twitter

“It's surreal to watch financial news talk about regular people having money to spend and job security as a negative thing. If you ever needed convincing that the health of "the economy" is a conspiracy against working people, watch this clip from CNBC that just aired.”

Twitter

This blew my mind: In 1614, the #Indigenous #Nahua noble and #historian Chimalpahin Messenger with Shield, documented (in Nahuatl!) the arrival of the Japanese embassy in Mexico on their way to Spain.

Chimalpahin writes out the dates using the Mexica calendar as well, staring with 1-Tochtli (1-Rabbit) and goes into great detail about how the Japanese dressed and acted. Amazing.

If you read Spanish, Miguel León-Portilla translated the diaries. You can find them here, with ample background: https://sci-hub.se/10.2307/40312014

#Japan #Mexico #Native #Aztec

A San Franciscan

When you lose a sock in the dryer, it gets reincarnated as a tupperware lid that doesn't fit anything.

I see a lot of newer people looking for jobs or hires around the fediverse, and I just wanted to let y'all know we have a hashtag for that: #GetFediHired

You will have more success if you're using it :)

if you run into anyone trying to discount the severity of the lastpass breach by saying the master keys are impossible to crack, ask them how lastpass' key derivation works, what a credential stuffing attack is, and how well PBKDF2 scales on GPUs.

given the details, it looks like anyone whose data was in the breach and who also reused their master password elsewhere is in imminent danger of having all their passwords compromised, as is anyone who used a relatively common password.

 Hello and a good meowing everyone!  A new day has begun, make the most of it and stay safe  Have a most wonderful day! ❤️

Washington Post will be creating their own instance. They will add #mastodon accounts to journalist profiles.

Institutional #journalism embracing the #fediverse is important.

UPDATE 07.54 AM: WaPo is *discussing* instance, first messaging about this was too definitive. Seeing level of support, hoping they decide in favour [END]

#commodon #journodon @communicationscholars

Today's White Evangelicalism is seen as hatred, racism, white rage, violence, bigotry, white supremacy, oppression, greed, hypocrisy, and immoral. Jesus was the opposite. He is loving, & kind, cares for the sick & poor. He was unselfish & advocated for the marginalized. To follow Christ means you love everyone, care about the marginalized, you serve, & give. That's Christianity. #christians #evangelicals #christian #blackmastodon