Davey 민선 · @daveyk
147 followers · 101 posts · Server sfba.social

Thanks to I finally migrated my passwords from to and updated/altered most of them. Liking it so far. Especially the break down and color coding of password characters. Lastpass made me deliberately avoid using upper case i and lower case L, or letter O versus zero etc. I liked Lastpass for the longest time but now I think it's fallen off the rails.

#LastPassHack #lastpass #1password

Last updated 2 years ago

Landsil · @Landsil
10 followers · 84 posts · Server infosec.exchange
Simon Migliano · @simonmigliano
160 followers · 188 posts · Server infosec.exchange

After being a user for around 10 years, I've shifted over to due to the shameful way they handled the and it's superior product by far. Should have done this ages ago.

#lastpass #1password #LastPassHack

Last updated 2 years ago

suburban yam · @suburbanyam
18 followers · 63 posts · Server nerdculture.de

@leo
People complain that it's tedious to change all passwords because it's different on all websites?

Try deleting your account. Rarely is that something you can achieve without getting into lengthy email battles with their support. And more often than not it takes ages to even reach a human.

#securitynow #LastPassHack #lastpassbreach #privacy #rant

Last updated 2 years ago

BreakingBadness · @BreakingBadness
51 followers · 15 posts · Server infosec.exchange
Tarnkappe.info · @tarnkappeinfo
1801 followers · 4023 posts · Server social.tchncs.de
Kirsty · @adminkirsty
154 followers · 4989 posts · Server infosec.exchange

@Barnacules
Pardon the impertinence, but is “funny” not your often stock in trade…? (Funny haha, rather than funny peculiar).
If anyone sees anything funny peculiar would be more of a concern worth raising.
Good luck with the recovery.

#hacked #lastpassbreach #LastPassHack #lastpass #barnacules

Last updated 2 years ago

Alan K. Martinez · @akmartinez
23 followers · 124 posts · Server infosec.exchange

What sucks, as a security student and advocate, I tell people that using any password manager is better than nothing... now something like this happens and a lot of us have to explain and re-assure people...

A lot of security people might be taking a hit in their credibility when things like this happen and have to deal with people who are skeptics/doubters to begin with...


youtube.com/watch?v=SoyYpq4y6X

#lastpass #LastPassHack #lastpassbreach #cybersecuritynews

Last updated 2 years ago

Alex · @alexaral
1 followers · 4 posts · Server infosec.exchange

I use keepassxc for my password management because I consider it the safest option and to avoid kerfuffles like the

#LastPassHack

Last updated 2 years ago

Chris · @Kubiac
8 followers · 383 posts · Server mastodontech.de

LastPass soll bei Bekanntgabe des Sicherheitslecks gelogen haben. Ich habe nicht ohne Grund meinen Freunden und Bekannten immer gesagt einen offline Safe zu nutzen. Wer nicht hören will muß eben fühlen.

winfuture.de/news,133810.html

#LastPassHack #datenschutz

Last updated 2 years ago

Keith D :qr: · @Tazdrumm3r
7 followers · 13 posts · Server infosec.exchange

I see so many talking about the and never see anyone mention as an alternative. I’ve been using for a few years and have totally loved it.

#LastPassHack #enpass

Last updated 2 years ago

leafwind :verified: · @leafwind
200 followers · 546 posts · Server liker.social

youtube.com/watch?v=SciDoKHTKa
TL;DR
1. 小心釣魚攻擊,特別是公司用戶,因為駭客取得了所有 metadata,包含公司 email、公司用什麼服務、公司帳單資訊、ip 等等。

2. 請改密碼,因為密碼 vault 也被拿走了,雖然有加密,但如果 master password 很爛(e.g. qwer123)大概也會被破解。

#LastPassHack

Last updated 2 years ago

rencosch · @rencosch
45 followers · 79 posts · Server infosec.exchange

"Problems With Passphrases
To say it one more time: Your passphrases need to be randomly generated! (As well as your passwords, of course.) Do not generate your own “good” passphrase by just looking around in the room you are sitting in and concatenating the things you see to generate a passphrase."
SOURCE: weberblog.net/password-strengt

#password #passphrase #passwords #passwordmanager #lastpass #LastPassHack #infosec

Last updated 2 years ago

Tarnkappe.info · @tarnkappeinfo
1728 followers · 3963 posts · Server social.tchncs.de
Hatchet · @hatchet
2 followers · 5 posts · Server infosec.exchange

Worst case scenario for the :

  1. Website developers save server passwords in LastPass.
  2. Those developers are storing their user's passwords insecurely on their servers.
  3. Ergo, all of THOSE passwords are compromised.

How many devs were using LastPass?? 😳

#LastPassHack

Last updated 2 years ago

Franchot Tonebender · @franchot
104 followers · 793 posts · Server mas.to

Very much enjoying spending xmas eve closing the barn door and preparing to move the whole menagerie to a different farm.

#LastPassHack

Last updated 2 years ago

"Forbes is the self consciousness of the bourgeois class" - TGoTJ

Major manager - ! I stayed up late last night changing passwords to "GFY" and then deleting their entries in lastpass. Because I migrated to already, but did not entirely delete my

forbes.com/sites/daveywinder/2

#password #hacked #bitwarden #lastpass #lastpassbreach #LastPassHack

Last updated 2 years ago

Waseem · @iamwaseem
6 followers · 47 posts · Server mas.to

I would suggest to update every account password which had information stored in

#lastpassbreach22 #LastPassHack #lastpass

Last updated 2 years ago

Eric Capuano · @eric_capuano
2075 followers · 338 posts · Server infosec.exchange

Ok, I was tired of rumors speculating about which fields appear to be encrypted client-side before being sent to LastPass, so I ran some tests of my own.

For a basic "Password" item, here is what I can tell so far.

When saving the item, the following primary fields are transmitted encrypted:

  • Name
  • Extra (Notes field)
  • Username
  • Password
  • TOTP (not in this screenshot, but did test)

However, I also observed the following fields having a cleartext (hex) version in the payload as well:

  • Name
  • Username
  • URL
  • Folder Name (not hex)

So in other words, there is more than just the URL being transmitted to LastPass in the clear, which makes sense because LastPass' Admin console reveals login activity for all users which includes Name, Username, and URL of the login event; so naturally, these things must be transmitted and kept server-side outside of the vault. However, this once again does go against their "zero-knowledge of anything in your vault" marketing...

Screenshots of this test below. I have omitted the encrypted data to prevent revealing enough for a "Known Plaintext Attack" to derive a key, but the relevant pieces are visible.

If I am missing anything here, do let me know.

#lastpass #LastPassHack #lastpassbreach

Last updated 2 years ago