nhose.blogg.se

Lastpass data breach
Lastpass data breach









That’s where your passwords are stored.įortunately, those passwords are encrypted, so the attackers can’t get or use them immediately. Last but not least, the attack stole a backup of customer vault data. The compromised data includes company names, billing and email addresses, phone numbers, end-user names, and customer IP addresses. The storage in question is in use by LastPass to store archived backups of their data. So what happened, anyway?Īccording to the LastPass announcement, an attacker accessed third-party cloud-based storage. However, let’s remember that prevention is the best security policy, so even if you have no reason to believe that the government is after you, you should adopt a few measures to prevent any problems. If you are an average, low-profile user, it’s unlikely that somebody will use more resources to get your passwords. So take a moment to consider if your online activities could be of interest to that type of organization. So who should be worried? Should you? While it remains unclear who was behind the data breach, the evidence suggests it was a state-level actor. If you are a LastPass user, you should be concerned about the latest data breach and do something about it as soon as possible. Let’s get something clear: it’s exceedingly difficult and expensive to decrypt the passwords, but it’s not impossible at all, as LastPass wants to imply.

lastpass data breach

After all, if somebody cracks your passwords, you are to blame because you obviously ignored the recommendations to set good passwords. Even worse, it’s the first step in shifting the blame to the user. It states that guessing a user’s master password would take millions of years with the currently available tools. There is a statement in the LastPass blog which is particularly troubling. The wording and the lack of additional information are deliberate. Above everything else, the question that every LastPass user needs to be answered is: should I change all my passwords? But make no mistake. While the wording seems transparent on the surface, it fails to give the users all the information they need. Are you a LastPass user? If you are, you should already know about the breach it suffered because the company sent an email to its users attempting to update the situation concerning the data breach.











Lastpass data breach