[SECURITY ALERT] Lastpass Nailed

Discussion in 'Bits & Bytes' started by Biker, Jun 16, 2015.

  Biker

    Biker

    Received via email:

    Their forums are full of rage at the moment from the clueless. I'd be very interested to know what the attack vector was. I have a sneaky hunch it was not a direct server attack, but a compromised password from someone within the company.
  ethics

    ethics

    Probably. I am not worried though. Just change your master password.
  Biker

    Biker

    Yep. Changed the email address on it as well (which is something I've needed to do for ages anyway).
  dsl987

    dsl987

    Thanks for the heads up, will change mine as well
  SixofNine

    SixofNine

    I also have two-factor authentication set up on my LastPass account.
  ethics

    ethics

    Don't you have Yubico? If so, you have 0 to worry about.
  Biker

    Biker

    Yubico only secures your machine and sites that support Yubico. Does nothing to prevent someone from getting into the servers where your stuff is stored and cracking the passwords obtained from there.
  ethics

    ethics

    I don't think you realize how lastpass works.
  Sir Joseph

    Sir Joseph

    That's why I was wary of it and use KeePass with a keyfile stored in DropBox. I'm already too invested in it to switch, even though I would prefer a fully web based solution.
  ethics

    ethics

    According to LastPass, the authentication hashes should be sufficiently encrypted to prevent anyone from using them to access your account. However, the company is still prompting all users to update their master password that they use to log in to their LastPass account. If you use LastPass, you should do this immediately. If you share that master password with any other services, you should change it there, too. Finally, if you haven’t enabled two-factor authentication you should do that immediately here.
  Allene

    Allene

    Thanks. I need to do that.
  dsl987

    dsl987

    Right now just running Lastpass
