The Lastpass hack was worse than the company first reported | Engadget

[ad_1]

After being hacked for the second time in as many years this August, password manager app Lastpass announced on Thursday the most recent intrusion was much more damaging than initially reported with the attackers having made off with users’ password vaults in some cases. That means the thieves have people’s entire collections of encrypted personal data, if not the immediate method to unlock them.

“No customer data was accessed during the August 2022 incident,” LastPass CEO Karim Toubba, explained. However, some of the app’s source code was lifted and then used to spearphish a Lastpass employee into giving up their access credentials, then used those keys to decrypt and copy off, “some storage volumes within the cloud-based storage service.”

Among the encrypted data obtained by the hackers included basic customer account information like company names, billing, email and IP addresses; and telephone numbers, Toubba continued. “These encrypted fields remain secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user’s master password using our Zero Knowledge architecture,” Toubba said. “As a reminder, the master password is never known to LastPass and is not stored or maintained by LastPass.” 

Still, you’re going to take the company’s word for it? I’m not. It’ll be a pain but swapping out all of your various existing site passwords for new ones — as well as picking a new master password — might ultimately prove necessary to regain your online security. Or you could just tell Lastpass to go kick rocks and switch over to 1Password or Bitwarden.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission. All prices are correct at the time of publishing.

[ad_2]

Source link

Related Posts

How to share a TikTok video to another app

[ad_1] TikTok has captured a massive swathe of the social media landscape in recent years thanks to its addictive algorithm and bite-sized clips that just beg to…

Better late than never: Epic Games reveals free games for March 23

[ad_1] Running a little late, Epic Games finally revealed the free games we can expect in its store on March 23. Usually, the company reveals its next…

The Shazam Sequel Sparks and Fizzles at the Box Office

[ad_1] Image: Warner Bros. Superhero fatigue seems to be hitting both Marvel and DC hard. Alongside a kind of mid-level audience response to Quantumania (it did good,…

US authorities arrest alleged BreachForums owner and FBI hacker Pompompurin | Engadget

[ad_1] US law enforcement authorities this week arrested the person allegedly responsible for . As reported by (via ), FBI agents on Wednesday arrested Conor Brian Fitzpatrick…

2 Ways to Use Google Magic Eraser on Your iPhone and iPad

[ad_1] Google Pixel’s native magic eraser feature has finally made its way to iOS devices, but it comes with a catch. Users with Google One subscription can…

Best mirrorless cameras 2023: Top interchangeable lens cameras from Sony, Fujifilm, Panasonic and more

[ad_1] Mirrorless cameras are where it’s at for both photographers and video makers alike, if you want to learn more about the top options available, you’re in…

Leave a Reply

Your email address will not be published. Required fields are marked *

%d bloggers like this: