If You Use LastPass, You Need to Change All Your Passwords ASAP


LastPass, one of the world’s most popular password managers, suffered a major data breach in December, putting customers’ online passwords at risk and their personal data at risk.

On December 22, LastPass CEO Karim Touba acknowledged in a blog post that a security incident first disclosed by the company in August ultimately led to an “unauthorized party” stealing customer account information and sensitive Vault data. Did. The breach is the latest in a long and troubling string of security incidents involving LastPass that date back to 2011.

It is also the most dangerous.

According to Toubba, an unauthorized party was able to gain access to unencrypted subscriber account information such as LastPass usernames, company names, billing addresses, email addresses, phone numbers and IP addresses. The same unauthorized party was also able to steal customer vault data, which includes unencrypted data such as website URLs as well as encrypted data such as usernames and passwords that customers have stored in their vaults.


If you are a LastPass member, the seriousness of this breach should cause you to seek a different password manager, as there is a serious risk of your passwords and personal data being exposed.

What Should LastPass Subscribers Do?

The company did not specify how many users were affected by the breach, and LastPass did not respond to CNET’s request for additional comment on the breach. But if you’re a LastPass subscriber, you need to operate under the assumption that your user and Vault data is in the hands of an unauthorized party with ill intentions. Although the most sensitive data is encrypted, the problem is that a threat actor can run “brute force” attacks on those stolen local files. LastPass estimates that it would take “millions of years” to guess your master passwordif you followed its best practices.

If you haven’t — or if you just want complete peace of mind — then you’re going to need to put in some serious time and effort to change your personal password. And while you’re at it, you’ll probably want to ditch LastPass, too.

With that in mind, here’s what you need to do now if you’re a LastPass subscriber:

1. Find a New Password Manager, Given LastPass’ history with security incidents and the seriousness of this latest breach, now is a better time than ever to explore alternatives.

2. Change your most important site-level passwords immediately, This includes passwords for anything like online banking, financial records, internal company logins, and medical information. Make sure these new passwords are strong and unique.

3. Change every single password you use online, Here too it is a good idea to change your password in order of importance. Start with changing passwords for accounts like email and social media profiles, then you can start working your way backwards to other accounts that may not be as important.

4. Enable Two-Factor Authentication Wherever Possible, Once you’ve changed your password, be sure to enable 2FA on any online account that offers it. This will provide you with an extra layer of security by alerting you and requiring you to authorize each login attempt. This means that even if someone gets your new password, they won’t be able to access any sites without your secondary authenticating device (usually your phone).

5. Change your master password, While this doesn’t change the threat level in Stolen Vaults, it’s still prudent to help mitigate the dangers of any potential future attacks that is, if you decide you want to stick with LastPass.

LastPass Alternatives to Consider

  • bitwarden: CNET’s top password manager is the highly secure and open-source LastPass alternative. Bitwarden’s free tier allows you to use the password manager across an unlimited number of devices across device types. read our bitwarden review,
  • 1password: Another great password manager that works seamlessly across all platforms. 1Password doesn’t offer a free tier, but you can try it for free for 14 days.
  • icloud keychain: Apple’s built-in password manager for iOS, iPadOS, and MacOS devices, it’s an excellent LastPass alternative available at no extra cost to Apple users. iCloud Keychain is secure and easy to set up and use across all your Apple devices. It also offers a Windows client with support for Chrome and Edge browsers.

How did it come to this?

In August 2022, LastPass published a blog post written by Toubba stating that the company “determined that an unauthorized party gained access to portions of the LastPass development environment through a compromised developer account and source Took portions of the code and some proprietary LastPass technical know-how.”

At the time, Tuba said the threat was contained after LastPass “engaged a leading cybersecurity and forensics firm” and implemented “advanced security measures.” But that blog post will be updated several times over the coming months as the scope of the breach gradually widens.

On September 15, Toubba updated the blog post to inform customers that the company’s investigation into the incident was complete.

“Our investigation has shown that the threat actor’s activity was limited to a four-day period in August 2022. During this time frame, the LastPass security team detected the threat actor’s activity and then contained the incident,” Tuba said. “There is no evidence of any threat actor activity beyond the established timeline. We can also confirm that there is no evidence that this incident involved any access to customer data or encrypted password vaults.”

Toubba assured customers at the time that their passwords and personal data were safe in the care of LastPass.

However, it turned out that the unauthorized party was in fact able to access customer data. On November 30, Toubba updated the blog post once again to alert customers that the company “determined that an unauthorized party, using information obtained at the August 2022 event, may have accessed certain elements of our customer information.” was able to access.”

Then, on December 22, Tubbs issued a lengthy update to the blog post, outlining unnecessary details about the customer data the hackers were able to access in the breach. It was then that the full gravity of the situation finally surfaced and the public learned that LastPass customers’ personal data was in the hands of a dangerous actor and that all their passwords were at serious risk of being exposed.

Nevertheless, Toubba assured customers who follow LastPass’ best practices for passwords and enable the latest default settings that at this time their “sensitive Vault data, such as usernames and passwords, secure notes, attachments, and Form-fill fields stay securely encrypted based on LastPass’ zero knowledge architecture.”

Tuba warned, however, that people who don’t have LastPass’ default settings enabled and don’t follow password manager best practices are at a higher risk of having their master passwords cracked. Toubba suggested that those users should consider changing the passwords for the websites they have stored.

What does all this mean for LastPass subscribers?

The initial breach allowed an unauthorized party to access sensitive user account data as well as Vault data, meaning that LastPass customers must be extremely concerned for the integrity of the data stored in their Vaults and the ability of LastPass to maintain The question should be raised. Their data is secure.

If you are a LastPass subscriber, an unauthorized party may have access to personal information such as your LastPass username, email address, phone number, name and billing address. IP addresses used when accessing LastPass were also exposed in the breach, meaning an unauthorized party could also see the locations from where you accessed your account. And because LastPass doesn’t encrypt users’ stored website URLs, an unauthorized party can view all the websites for which you’ve saved login information with the password manager (even if the passwords themselves are encrypted).

Such information gives a potential attacker plenty of ammunition for launching a phishing attack and socially engineering your account password. And if you have any password reset links stored that may still be active, an attacker could easily go ahead and create a new password for themselves.

LastPass says that encrypted Vault data such as usernames and passwords, secure notes and form-filled data that was stolen remains secure. However, if an attacker were to crack your master password at the time of the breach, they would be able to access all of that information, including usernames and passwords for all of your online accounts. If your master password was not strong enough at the time of the breach, your password is at particular risk of being exposed.

Changing your master password now, unfortunately, won’t help solve the problem because attackers already have a copy of your vault that was encrypted using the master password you had at the time of the breach. This means that attackers have essentially an unlimited amount of time to crack that master password. That’s why the safest course of action is to do a site-by-site password reset for all of your LastPass-stored accounts. Once changed at the site level, this would mean attackers would be getting your old, old passwords if they managed to crack the stolen encrypted vaults.

For more on staying safe online, here are the data privacy tips digital security experts want you to know and the browser settings you should change to better protect your information.

Source


Related News

Premiären av Sons of the Forest – spelet som har tagit över önskelistorna på Steam [Aktualizacja]

Sons of the Forest är nu tillgängligt på Steam i Early Access. Du kan köpa spelet för PLN 138.99. Intresset i starten var så stort att för ett ögonblick

Lenovo Legion 5 med RTX 3070 till en rabatt på 500 €! Att köpa NU!

Om du brinner för tv-spel vet du hur viktigt det är att ha en bärbar dator av hög kvalitet för att bättre kunna njuta av spelupplevelsen, vilket då också

Den nya civilisationen är under utveckling, nu officiell

Det var den 21 oktober 2016 när Civilization 6 debuterade på marknaden. Mer än sex år efter det spelet, som fick en oförutsägbar framgång

Mest pålitliga bilmärken, 2023 års ranking

Bland parametrarna att ta hänsyn till innan du fortsätter med köpet av en bil finns det utan tvekan tillförlitlighet. I avsaknad av detta