Skip to main content
MANIFOLD
Will the LastPass hackers attempt to brute force vaults?
17
Ṁ350Ṁ646
resolved Jan 13
Resolved as
80%

Resolves YES if by 2024 evidence emerges that the LastPass hackers are attempting to brute force user vaults instead of or in addition to non-brute force methods such as phishing, otherwise resolves NO.

Close date updated to 2023-12-31 5:59 pm

Market context
Get
Ṁ1,000
to start trading!

🏅 Top traders

#TraderTotal profit
1Ṁ28
2Ṁ10
3Ṁ3
4Ṁ1
5Ṁ0
Sort by:
predictedNO

I'm inclined to resolve this to 80%. The evidence seems strong, but circumstantial (there's no evidence that the people were hacked *because* they had LastPass accounts). Also, all the articles seem to point to only one source for the investigation, which is suspicious, because I would expect there to be many more investigations into this theory if the cybersecurity community deemed it likely.

So there was an attack targetting a significant amount of LastPass users, probably more than would be possible if passwords were only cracked by phishing. There is a specific victim interviewed who presumably got hacked because his password was only 8 characters or because of some lacking settings which would also enable a brute force attack.
https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/

Would apparent credential stuffing attacks (i.e. using leaked passwords to fish for cases where they were reused as master passwords) qualify?

@nfd Yes