EN
返回档案库

档案库 · 消费应用 · 技术决策 · 2022

LastPass失守信任:被盗保险库备份暴露未加密网站URL

2022年12月,LastPass披露保险库备份被盗,包含未加密的网站URL;Hacker News读者认为情况比公司所述更糟(614分)。

LastPass

它在赌什么云保险库能在便利性与零知识宣称之间取得平衡——网站URL可读用于自动填充,密码加密——并保证即使被入侵,用户仍安全。已上线

做的是什么生意

LastPass sells a cloud password manager: users keep passwords, notes and identities in a vault unlocked by one master password and synced across devices and browsers; passwords are encrypted client-side, but website URLs are kept as readable metadata so autofill can match sites.

起因

The product bet was convenience plus encryption: sync every password to the cloud, unlock it anywhere with one master password, and never let the server see that password — all encryption happens client-side, as commenters summarized the company's model. The December 2022 incident notice made the seam visible: website URLs were never encrypted, because the client needs them readable to match autofill entries.

经过

The HN thread assembled the timeline from earlier coverage: an August 2022 notice of a security incident, September reporting of internal access for several days, a November incident thread, and December disclosures that the attacker had copied vault data. The 22 December notice, quoted in the thread, said the threat actor copied basic account information and metadata (company names, end-user names, billing addresses, email addresses, phone numbers, IP addresses) plus a backup of customer vault data including unencrypted data such as website URLs. Commenters argued the framing was too reassuring: encrypted passwords sit behind one master password that can be attacked offline indefinitely, 2FA does not protect vault copies once stolen, and the URL map alone tells attackers which banks, exchanges and employers each user belongs to.

结果

No successful decryption was claimed by 23 Dec 2022; the immediate result was a crisis of trust. The 614-point, 414-comment discussion treated LastPass's description as understating the risk and pointed users toward Bitwarden, 1Password and local KeePass-style vaults. LastPass itself kept operating, with the full extent of the disclosure still being debated.

背景

LastPass是云端密码管理器:密码、笔记和身份信息存放在主密码解锁的保险库中,在客户端加密并与设备和浏览器同步以实现自动填充。网站URL作为可读元数据保留,因为客户端必须匹配登录页面。

2022年12月,LastPass披露威胁行为者复制了备份,包含基本账户信息和元数据——公司名、终端用户姓名、账单地址、电子邮件地址、电话号码和IP地址——以及包含未加密数据(如网站URL)的客户保险库备份。Hacker News首页讨论(2022-12-23获614分、414条评论)认为披露比公司所说更严重。

评论者指出,攻击者获得加密保险库副本后可无限期离线破解,2FA保护登录但不保护窃取的副本,且仅凭未加密的URL就能看出用户与哪些银行、交易所和雇主有关系——一张自动生成网络钓鱼地图。截至讨论日期,无成功解密宣称,但信任损害立即显现,转向其他管理器的建议在讨论中蔓延。

这件事要成立,得有什么

  • LastPass便利性设计使网站URL未加密,因此即使保险库加密,也会泄露用户拥有哪些账户。
  • 被盗的保险库备份可被无限期离线暴力破解,而2FA阻止登录,不阻止对副本的离线攻击。
  • 披露声称安抚人心,但事实是元数据为明文,公司显得在淡化问题。
  • 密码管理器集中了一个人最敏感的账户图谱,任何泄露——无论是否加密——都是严重信任事件。

可借鉴之处

未加密的元数据同样是秘密:在“零知识”保险库中,可读的网站URL等于向攻击者交出用户银行和交易所的地图,因此元数据应与密码同样受保护。

后续进展

截至2022年12月23日,LastPass仍在运营,尚未显示任何保险库被解密,但正处于信任危机之中:其12月通知确认保险库备份和明文URL元数据被盗,HN主流观点认为情况被低估。用户权衡主密码强度和2FA是否足够,或云同步便利是否已不值得集中风险,KeePass、Bitwarden和1Password被提及为替代品。更长期的后果在源讨论中尚未显现。

资料来源

发现哪里写错了?告诉我们。

轮到你了

你刚读完一家。说说你在做什么,看看谁在赌同一件事。

免费账号 · 3 次免费提问 · 不用绑卡

相关案例