The archive · Consumer Apps · Technical decision · 2022
LastPass loses trust after stolen vault backups expose unencrypted site URLs
In Dec 2022 LastPass disclosed vault backups were stolen with unencrypted site URLs; HN read it as worse than the company let on (614 points).
LastPass
What the business is
LastPass sells a cloud password manager: users keep passwords, notes and identities in a vault unlocked by one master password and synced across devices and browsers; passwords are encrypted client-side, but website URLs are kept as readable metadata so autofill can match sites.
How it started
The product bet was convenience plus encryption: sync every password to the cloud, unlock it anywhere with one master password, and never let the server see that password — all encryption happens client-side, as commenters summarized the company's model. The December 2022 incident notice made the seam visible: website URLs were never encrypted, because the client needs them readable to match autofill entries.
What happened
The HN thread assembled the timeline from earlier coverage: an August 2022 notice of a security incident, September reporting of internal access for several days, a November incident thread, and December disclosures that the attacker had copied vault data. The 22 December notice, quoted in the thread, said the threat actor copied basic account information and metadata (company names, end-user names, billing addresses, email addresses, phone numbers, IP addresses) plus a backup of customer vault data including unencrypted data such as website URLs. Commenters argued the framing was too reassuring: encrypted passwords sit behind one master password that can be attacked offline indefinitely, 2FA does not protect vault copies once stolen, and the URL map alone tells attackers which banks, exchanges and employers each user belongs to.
How it ended up
No successful decryption was claimed by 23 Dec 2022; the immediate result was a crisis of trust. The 614-point, 414-comment discussion treated LastPass's description as understating the risk and pointed users toward Bitwarden, 1Password and local KeePass-style vaults. LastPass itself kept operating, with the full extent of the disclosure still being debated.
Background
LastPass is a cloud password manager: passwords, notes and identities live in a vault unlocked by one master password, encrypted on the client and synced across devices and browsers so autofill works everywhere. Website URLs are kept as readable metadata because the client has to match them to login pages.
In December 2022 LastPass disclosed that a threat actor had copied backups holding basic account information and metadata — company names, end-user names, billing addresses, email addresses, phone numbers and IP addresses — along with a backup of customer vault data that included unencrypted data such as website URLs. The HN front-page thread (614 points, 414 comments on 2022-12-23) read the disclosure as worse than the company was letting on.
Commenters argued that an offline copy of encrypted vaults can be attacked forever once the attacker has them, that 2FA protects logins but not stolen copies, and that unencrypted URLs alone reveal which banks, exchanges and employers a user belongs to — a ready-made phishing map. No successful decryption was claimed by the thread's date, but the trust damage was immediate, with migration advice to rival managers spreading through the discussion.
What has to be true
- LastPass's convenience design left site URLs unencrypted, so even an encrypted vault leaks which accounts a user holds.
- A stolen vault backup can be brute-forced offline forever, and 2FA stops logins, not offline attacks on copies.
- The disclosure's reassuring framing collided with the fact that metadata was plaintext, so the company read as minimizing.
- A password manager concentrates the most sensitive account map a person owns, making any leak — encrypted or not — a severe trust event.
What can be applied
Unencrypted metadata is still secret: readable site URLs in a 'zero-knowledge' vault hand attackers a map of users' banks and exchanges, so metadata deserves the same protection as passwords.
Aftermath
As of 23 Dec 2022 LastPass was still operating and no vault decryption had been shown, but it was mid-trust-crisis: its December notice confirmed theft of vault backups and plaintext URL metadata, and HN's dominant read was that the situation was understated. Users weighed whether master-password strength and 2FA were enough, or whether cloud-sync convenience was no longer worth the concentration risk, with KeePass, Bitwarden and 1Password cited as alternatives. Longer-term consequences were not yet visible in the source discussion.
Sources
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card