New details on the 2nd LastPass incident are fun:
- got into Sr DevOp's home via vuln media software
- installed keylogger
- got master pass to corp vault (seemingly because it was being accessed from home computer)
Cool to see that LastPass is sharing support.lastpass.com/help/incident-…
Conversation
Seems plausible. I wonder if we will know for sure.
1
4
90
It was Plex. They exploited Plex to get into the home network, installed a keylogger on a home laptop, and got the corp vault password because the home laptop was logging into it.
Targeted high value employee shortly after the arstechnica.com/information-te…
15
156
390
4 people who have access to “the keys to the kingdom”. At least 1 of them was accessing them from a home computer. For how long without anyone noticing? If that didn’t raise flags, then it won’t for an attacker either.
Helping them harden their home network is nice, but there needs to be some big cultural improvements & better controls/detections.
Seeing a lot of people ask “why didn’t 2FA stop this?”
Well, I know of no password manager where 2FA protects anything but the account that is used to download your vault. Once you have the vault (which was probably on the home computer) all you need is the vault password.
And…
3
6
36
Plex told that they are unaware of any unfixed vulns and LastPass hasn’t contacted them. So I’d guess this was an out of date Plex install.
2
3
12
Getting your historical vault contents is something that will likely happen eventually. But it’s not the only risk to be concerned about:
1
7
Show replies
Show replies
For years now if, I require production access at home, I ask for a dedicated work machine I leave at home. Or a floater we share with non call support.
1
That’s great but what Lastpass really needs to do is overnight that DevOps engineer a corporate laptop ASAP.
1
7






