Pelican Parts Forums

Pelican Parts Forums (http://forums.pelicanparts.com/)
-   Off Topic Discussions (http://forums.pelicanparts.com/off-topic-discussions/)
-   -   LastPass Data Breach (http://forums.pelicanparts.com/off-topic-discussions/1130972-lastpass-data-breach.html)

Jandrews 12-04-2022 03:32 PM

LastPass Data Breach
 
Anyone hear about this? Saw notification of it in an email from Last Pass

They are saying "certain customer information" was compromised, but password info is safe due to their zero knowledge architecture

Is there anything actually secure? I was considering a LastPass account, but never went ahead with it for this specific reason

Now, sure enough, they have been compromised

An app to store all of your passwords

What could go wrong

Well, this

A930Rocket 12-04-2022 05:21 PM

I read it was the second time in so many months for them.

That’s not good.

LWJ 12-04-2022 05:36 PM

I am hoping this is a big nothing. As I use LP.

Por_sha911 12-04-2022 05:57 PM

https://www.zdnet.com/article/lastpass-hacked/
Quote:

LastPass, the popular password management service, recently announced that it was hacked. Specifically, LastPass's CEO Karim Toubba wrote that an "unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information."

This isn't the first time LastPass has had security problems. In 2021, it appeared that some users' LastPass Master Passwords may have been revealed. LastPass replied that it hadn't been breached, but users who had gotten emails warning them that an unknown person was trying to log into their accounts weren't convinced. Nevertheless, LastPass insisted that it was just the result of a credential stuffing attack.

In 2020, LastPass had a major outage, and users reported they couldn't log into their accounts or autofill passwords.

In 2019, a significant LastPass security problem was uncovered by security researchers as well.

Willie Sutton when asked why he robbed banks: "because that's where the money is". You gotta think that LastPass is a prime target of hackers because it is the bank of passwords.

KFC911 12-05-2022 01:33 AM

I don't keep information in the cloud or on other people's servers if I can avoid it. I'd rather have all my assets invested in Bitcoins and have no such worries....

But that's just me :D

sc_rufctr 12-05-2022 02:12 AM

I'm getting impression that a lot of (most?) online resources are open to getting hacked.

There must be an army of hackers out there that do nothing else.

svandamme 12-05-2022 03:04 AM

Quote:

Originally Posted by sc_rufctr (Post 11864816)
I'm getting impression that a lot of (most?) online resources are open to getting hacked.

There must be an army of hackers out there that do nothing else.

Russians have state sponsorred companies for that

GH85Carrera 12-05-2022 05:36 AM

I know the FBI, the CIA, Apple and Microsoft have all been hacked, and data stolen. I have never been hacked.

I looked at the password apps and almost pulled the trigger and signed up, but I decided to just keep using a password list on my own computer, in a hidden file. Not as convenient as an auto-fill password manager, but it has worked for me since the early 1980s.

It is tedious to use the two factor authentication for a lot of sites, but is is more secure.

Way back in in the 1980s one of my friends was THE head of email for all of SW Bell. He had a business card sized gizmo with a text string of a lot of numbers that changed regularly. It was his password generator that he had to enter the numbers from that card into a portal, and only then was he able to access a login page to enter his convoluted username and password. He did say his username was nothing at all to do his actual name and the password back then was long and had upper and lower case, special characters, and even some ASCII code characters. Since he was in charge of millions of email accounts he had to be 100% secure.

stealthn 12-05-2022 06:40 AM

Yup this is their second breach this year. This one was done through GoTo as they share some servers/databases.

We use Passportal which is excellent, although I’m not concerned about the passwords getting decrypted, once they get the source code, I get nervous.

Reminds me of the Solarwinds supply chain breach, we lost a lot of customers on that one.

Any company can be breached….


All times are GMT -8. The time now is 10:09 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website


DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.