Daily Shaarli
December 27, 2022
Moz in Oz • December 26, 2022 8:35 PM
Writing down the master password is all but essential if there’s anything important in your password database. The lawyer who did my wills (living and dead) was adamant about that. There are fun crypto system to let you distribute bits of a password around so that it’s harder for people who have other things to think about to make it work at all. Meanwhile you’re in a coma and the bailiffs are selling your house, “comes with a ready-made family for the lucky buyer”. Write the bloody thing down, put it in a safe place. My lawyer has half the password plus a list of people who each have a copy of the other half. And they have a copy of the file from ~2 years ago, and know how to get the latest one off my website(s), and that my work has a copy of it.
Security is always a balance, and I’ve been around long enough to have seen a few too many “Bob died so his website is gone forever”, not to mention seen families wandering lost in technology wondering whether Bob really had investments at all, or were they concealing a gambling problem (trick question, it was both: they invested in cryptocurrency). If no-one knows where you invested they can’t use your death to access those funds.
Last August, LastPass reported a security breach, saying that no customer information—or passwords—were compromised. Turns out the full story is worse: //
To date, we have determined that once the cloud storage access key and dual storage container decryption keys were obtained, the threat actor copied information from backup that contained basic customer account information and related metadata including company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service.
The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.
That’s bad. It’s not an epic disaster, though.
These encrypted fields remain secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user’s master password using our Zero Knowledge architecture. As a reminder, the master password is never known to LastPass and is not stored or maintained by LastPass. //
John Thurston • December 26, 2022 1:31 PM
“I think the question of why everything in the credentials store was not encrypted is interesting. What possible advantage is there of not just encrypting the whole thing under your master password.”
Because this is how Lastpass is able to offer to supply uid:pwd values when you have not unlocked your vault. If this information was kept encrypted, then the browser extensions would not know when to prompt you to unlock to supply the creds.
I’ve never liked this ‘feature’, but there’s nothing I can do about it. //
Wladimir Paöant • December 27, 2022 6:56 AM
I would have been less problematic had LastPass not messed up. They:
- Failed to upgrade many accounts from 5,000 to 100,100 iterations.
- Didn’t keep up with cracking hardware improvements (100k iterations are really on the lower end today).
- Didn’t bother existing their new password complexity rules for existing accounts.
- Didn’t bother encrypting URLs despite being warned about it continuously, allowing attackers to determine which accounts are worth the effort to decrypt.
Their statement is misleading, they downplay the issues. I’ve summed it up on my blog here: https://palant.info/2022/12/26/whats-in-a-pr-statement-lastpass-breach-explained/ //
Conex Energy Liberia has announced the shortage of jet fuel in the country.
Last year, the African distribution business acquired the Liberia and Sierra Leone businesses of French petroleum refining company Total Energies for an undisclosed sum.
Cherif Abdallah is the company’s Chief Executive Officer.
In a statement issued in Monrovia on Tuesday, December 26, the company disclosed that the arrival of jet fuel in Liberia will be delayed as a result of the shortage on the global market. //
“Based on the above, Conex Energy Liberia informs the public that there is a delay in the arrival of the next Jet Fuel vessel, causing low fuel stock at Roberts International Airport (“RIA”). The vessel should have arrived on December 14, 2022. We are now being informed that the vessel will not be in Liberia until January 13, 2023.”
The company disclosed that during this period, airlines will use alternative methods / locations for fueling.