[ad_1]
People involved in financial technology, software programming, cybersecurity and cryptocurrencies spoke about the Lastpass data breach that was disclosed two days ago. The password management company said a breach earlier this year allowed hackers to obtain a backup of customer vault data.
Lastpass reveals that “Threat Actor was also able to copy a backup of client vault data”
On December 22, 2022, password management company Lastpass revealed that an unknown malicious actor had managed to break into the company’s cloud-based storage environment around August 2022. As soon as the news was published, the Lastpass data leak has been a topical discussion on social media and forums. A lot of people think Lastpass’s situation may be worse than they let on.
LastPass attackers now know all websites you have stored passwords for and blobs, encrypted only by your master password https://t.co/Wdbt6mWe8C https://t.co/HldcJ8DYkK
— SwiftOnSecurity (@SwiftOnSecurity) December 22, 2022
Based on our investigation to date, we have learned that an unknown malicious actor gained access to a cloud-based storage environment by exploiting information obtained from the incident we previously disclosed in August 2022, revealed Lastpass. The password management company added:
The threat actor was also able to copy a backup of the Client Vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as site URLs web, as well as fully encrypted sensitive fields such as website usernames. and passwords, secure notes and form filled data.
Lastpass insists that encrypted fields are secured with 256-bit AES encryption and information can only be decrypted by leveraging each user’s master password using the zero-knowledge architecture of Lastpass. the company. As a reminder, the master password is never known to Lastpass and is neither stored nor maintained by Lastpass, the company detailed.
lastpass is hacked and immediately after a ton of crypto wallets were hacked and emptied
be your own bank
nah go break into a brick and mortar establishment if you want my nerd funds good luck
— gainzy (@gainzy222) December 24, 2022
Lastpass security doesn’t seem to convince a number of critics
However, a number of reports believe that the situation is worse than Lastpass suggests. Reviewgeek.coms Andrew Heinzman points out in his report to stop using Lastpass. Even if you use a strong master password, there’s a chance hackers will try to trick you into certain information, Heinzman wrote. The author added:
To be clear, Lastpass is still investigating this data breach. And after four months of forgiveness, it’s worse than we thought, customers are rightly worried that Lastpass doesn’t have all the details. As far as we know, things could get even worse. We asked our readers to stop using Lastpass in July 2020.
Crypto proponent Udi Wertheimer also warned people that if they’re using Lastpass, attackers likely have a copy of your vault. Wertheimer’s recommendation is the same as Heinzmans’, as the digital currency proponent insisted that users stop using Lastpass.
We don’t know how bad things are going, Wertheimer added. Attackers may have continued access, so don’t just change your passwords and put them back into Lastpass. Additionally, a Twitter user who claims to have worked as an engineer for the company seven years ago also noted that the Lastpass breach situation is a big deal.
I worked at Lastpass as an engineer a long time ago. Over 7 years ago. My 2 cents on the situation, said the individual. This is the worst breach Lastpass has had. Greatly. The main difference is that client vaults were accessed this time, which are kept in a completely separate database.
Tags in this story AES 256-bit encryption, Andrew Heinzman, Crypto, Digital Assets, encrypted fields, former engineer, Lastpass, Lastpass data breach, password management company, Passwords, Reviewgeek.com, passwords secrets, Security, Seeds, Udi Wertheimer, architecture without knowledge
What are your thoughts on the Lastpass data breach and the speculation that it’s worse than Lastpass suggests? Let us know what you think about this topic in the comments section below.
Jamie Redman
Image credits: Shutterstock, Pixabay, Wiki Commons
Disclaimer: This article is provided for informational purposes only. This is not a direct offer or the solicitation of an offer to buy or sell, or a recommendation or endorsement of any product, service or company. Bitcoin.com does not provide investment, tax, legal or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.
More popular newsIn case you missed it
|
Sources 2/ https://news.google.com/__i/rss/rd/articles/CBMicmh0dHBzOi8vbmV3cy5iaXRjb2luLmNvbS9sYXN0cGFzcy1kYXRhLWJyZWFjaC1mcmlnaHRlbnMtdXNlcnMtc29tZS1zYXktaGFjay1tYXktYmUtd29yc2UtdGhhbi10aGV5LWFyZS1sZXR0aW5nLW9uL9IBAA?oc=5 The mention sources can contact us to remove/changing this article |
[ad_2]