TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

LastPass says hackers stole customers' password vaults

69 pointsby fariszrover 2 years ago

8 comments

mekokaover 2 years ago
<i>Hackers stole...</i><p>Often when these things happen, the reports make it sound like some amazing feat of technical engineering. But...<p><i>&gt; LastPass CEO Karim Toubba said the intruders took a copy of a backup of customer vault data by using cloud storage keys stolen from a LastPass employee.</i><p>Ah, there you have it, the good ol&#x27; careless human vulnerability! I understand such breaches from ordinary companies, with employees roaming around coffee shops with their work laptops full of these keys, nicely shielded from the world with unbreakable secrets like &quot;Password1&quot;, but I&#x27;m baffled that security focused ones would also be caught with their pants down like this. Keys stolen from an employee? How? Were they mugged? Why didn&#x27;t they think this was a possibility? Their entire business revolves around them being ten times as paranoid about this sort of things as the rest of us.
评论 #34101327 未加载
StopHammoTimeover 2 years ago
LastPass gets hacked so often that I’m not surprised. I stopped using them about three years ago and I’m happy that I did.<p>I just don’t understand how they can be so consistently bad at this when they are a <i>security</i> company. I can understand why “Farmer Joes Potatoes” gets hacked, but LastPass? Bruh.
rcarrover 2 years ago
Just checked my LastPass account, I never store any passwords in there that are too important given the multiple breaches they&#x27;ve had. I did however notice that my HN password was in there. I&#x27;ve changed it to be on the safe side, but is it not about time we got 2FA on here?
Havocover 2 years ago
That’s deeply concerning.<p>Once available offline things are easier to brute force at speed
评论 #34101284 未加载
gillesjacobsover 2 years ago
LastPass is disingenuous with their security notice blog post to save their own skin: SENSITIVE INFORMATION IS LEAKED. The &quot;threat actor&quot; (and anyone else the info is shared with on the hacker forums) now has copies of:<p>- Customer Names &#x2F; Company Names<p>- Email Address of main LastPass account<p>- Billing Address<p>- Telephone Numbers<p>- IP addresses (from where customers accessed the service)<p><i>Unencrypted fields</i> in password vault include:<p>- *Website URLs* saved in LastPass vaults<p>- Password creation time<p>- Last password modification time<p>- Last password access time (great to guess which accounts might be used more often!)<p>- Whether you added this account to favorites<p>- Whether or not the password was auto-generated (great to figure out which passwords might be more vulnerable!) ... and a lot more, which might contain a good amount of data about your usage habits as they concern specific sites (e.g. whether you enabled auto-logon)<p>- <i>Encrypted vaults</i> secured by only the master password of the time of backup. Weak master passwords are probably readily crackable with current password hashing&#x2F;guessing techniques. For stronger password it is only a matter of time until hardware becomes powerful enough. See [&#x2F;u&#x2F;dschwarz&#x27;s post on bruteforce time estimates for your password](<a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Lastpass&#x2F;comments&#x2F;zt6h1t&#x2F;zxcvbn_can_help_you_estimate_how_long_itll_take&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Lastpass&#x2F;comments&#x2F;zt6h1t&#x2F;zxcvbn_can...</a>).<p>I also have a bone to pick with LastPass communication here:<p>- LastPass lied in their marketing about Zero Knowledge vaults: website URLs are UNENCRYPTED, this is sensitive information and exposes you to large-scale automated targeted phishing, doxing, social engineering and blackmail attacks.<p>- LastPass waited 5 MONTHS after the August breach to warn us. They waited the day before Christmas to announce this with obfuscating language to minimize reach of this bad news.<p>- LastPass will unlikely survive the litigation, class action lawsuits and customer exodus that will follow. This will result in decreased operational security as whole teams are fired during bankruptcy, processes deteriorate and disgruntled employees head for the door.
评论 #34109384 未加载
评论 #34108967 未加载
asimpleusecaseover 2 years ago
From previous article “ Assuming the worst, LastPass has about 33 million customers. GoTo has 66 million customers as of its most recent earnings in June.”
TheTaurus0514over 2 years ago
Use a PWM that lets you choose where your data is stored. Personally, I like Enpass. The others with this kind of choice aren&#x27;t as user-friendly.
levinjohnsonover 2 years ago
With Enpass App you don’t have to worry about it being hacked, because your data isn’t on their servers.