[ad_1]
Cybercrime, fraud management and cybercrime
Class-action lawsuit says security firm failed to protect customer data Mihir Bagwe (MihirBagwe) • January 5, 2023
A class action lawsuit against LastPass alleges that a data breach in August resulted in the theft of $53,000 in bitcoins. An anonymous complainant alleges negligence in the password management company’s data security practices led to the Thanksgiving weekend theft.
See also: Live Webinar | 6 Steps to Mastering the OT Patch
The claimant, using the pseudonym “John Doe”, claims to have purchased the bitcoin over a three-month period beginning in July 2022. He then updated the master password for his LastPass account in order to store the bitcoin private keys highly sensitive. This meets the company’s standard “best practices”, the lawsuit says.
The lawsuit says LastPass initially disclosed the breach in August and said users were at no significant risk, and the plaintiff deleted his private information from the customer’s vault. But it seems that his actions are a little too late. “On or about Thanksgiving weekend, 2022, Plaintiff’s Bitcoin was stolen using private keys he stored with LastPass,” the lawsuit states.
The lawsuit claims that the plaintiff is at continuing risk and that the loss is due to the company’s negligent data security practices. He also alleges breach of contract, breach of implied contract, unjust enrichment and breach of fiduciary duty.
LastPass did not immediately respond to a request for comment from Information Security Media Group.
The complaint also alleges that LastPass’ “stronger than normal” implementation of 100,100 iterations of the PBKDF2 algorithm is actually less than the standard 310,000 iterations recommended by the Open Web Application Security Project.
In cryptography, PBKDF1 and PBKDF2 are sliding computational cost key derivation functions used to reduce vulnerabilities to brute force attacks, according to the standard definition of PBKDF2.
But LastPass has propagated to the use of a 12-character master password that “significantly minimizes the possibility of successfully guessing a password by brute force,” the lawsuit claims.
The plaintiff counters that “many password managers have solved this problem either by adding a truly random factor to the encryption – a secret key – or by switching to key generation methods much harder to force than PBKDF2”.
LastPass breach timeline
In August, an anonymous hacker gained unauthorized access to LastPass, compromising the password management service’s source code and proprietary technical information. At the time, a LastPass spokesperson told Information Security Media Group that there was “no evidence” that the attacker gained access to customer data or encrypted password vaults ( see: Hacker Steals Source Code, Proprietary Data From LastPass).
In September, LastPass disclosed that the threat actor had had unauthorized access to its development environment for four days, but maintained that no customer data had been accessed (see: Hacker Accessed LastPass Internal System for 4 Days).
In November, the company disclosed that “some elements of our customers’ information” had been compromised (see: LastPass Breach Exposes Customer Data).
In December, the company further expanded the scope of the breach to its encrypted password vaults and enterprise cloud storage backup environment (see: LastPass Breach: Attacker Stole Encrypted Password Vaults).
|
Sources 2/ https://news.google.com/__i/rss/rd/articles/CBMiYGh0dHBzOi8vd3d3LmJhbmtpbmZvc2VjdXJpdHkuY29tL2xhd3N1aXQtY2xhaW1zLWxhc3RwYXNzLWJyZWFjaC1jYXVzZWQtNTNrLWJpdGNvaW4tdGhlZnQtYS0yMDg2N9IBAA?oc=5 The mention sources can contact us to remove/changing this article |
[ad_2]