Close Menu
Beverly Hills Examiner

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Bring on 2027 I mean 2026 I mean Happy Easter

    December 31, 2025

    ‘I opened her door and the wind caught me, and I went flying’: The U.S. Arctic air surge is sweeping northerners off their feet

    December 31, 2025

    The Trump Regime Threatens Artists As The Kennedy Center Will Be Empty On New Year’s Eve

    December 31, 2025
    Facebook X (Twitter) Instagram
    Beverly Hills Examiner
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    Beverly Hills Examiner
    Home»Technology»LastPass Data Breach: It’s Time to Ditch This Password Manager
    Technology

    LastPass Data Breach: It’s Time to Ditch This Password Manager

    By AdminDecember 29, 2022
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    LastPass Data Breach: It’s Time to Ditch This Password Manager


    You’ve heard it again and again: You need to use a password manager to generate strong, unique passwords and keep track of them for you. And if you finally took the plunge with a free and mainstream option, particularly during the 2010s, it was probably LastPass. For the security service’s 25.6 million users, though, the company made a worrying announcement on December 22: A security incident the firm had previously reported (on November 30) was actually a massive and concerning data breach that exposed encrypted password vaults—the crown jewels of any password manager—along with other user data. 

    The details LastPass provided about the situation a week ago were worrying enough that security professionals quickly started calling for users to switch to other services. Now, nearly a week since the disclosure, the company has not provided additional information to confused and worried customers. LastPass has not returned WIRED’s multiple requests for comment about how many password vaults were compromised in the breach and how many users were affected. 

    The company hasn’t even clarified when the breach occurred. It seems to have been sometime after August 2022, but the timing is significant, because a big question is how long it will take attackers to start “cracking,” or guessing, the keys used to encrypt the stolen password vaults. If attackers have had three or four months with the stolen data, the situation is even more urgent for impacted LastPass users than if hackers have had only a few weeks. The company also did not respond to WIRED’s questions about what it calls “a proprietary binary format” it uses to store encrypted and unencrypted vault data. In characterizing the scale of the situation, the company said in its announcement that hackers were “able to copy a backup of customer vault data from the encrypted storage container.”

    “In my opinion, they are doing a world-class job detecting incidents and a really, really crummy job preventing issues and responding transparently,” says Evan Johnson, a security engineer who worked at LastPass more than seven years ago. “I’d be either looking for new options or looking to see a renewed focus on building trust over the next few months from their new management team.”

    The breach also includes other customer data, including names, email addresses, phone numbers, and some billing information. And LastPass has long been criticized for storing its vault data in a hybrid format where items like passwords are encrypted but other information, like URLs, are not. In this situation, the plaintext URLs in a vault could give attackers an idea of what’s inside and help them to prioritize which vaults to work on cracking first. The vaults, which are protected by a user-selected master password, pose a particular problem for users seeking to protect themselves in the wake of the breach, because changing that primary password now with LastPass won’t do anything to protect the vault data that’s already been stolen.

    Or, as Johnson puts it, “with vaults recovered, the people who hacked LastPass have unlimited time for offline attacks by guessing passwords and attempting to recover specific users’ master keys.”



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleThe Best New Year’s Resolution Might Be to Just Let Go of an Unfulfilled Life Goal
    Next Article National Guard Checks Homes In Buffalo For Blizzard Victims

    RELATED POSTS

    The phone is dead. Long live . . . what exactly?

    December 31, 2025

    Commodore 64 Ultimate Review: An Astonishing Remake

    December 30, 2025

    Meta just bought Manus, an AI startup everyone has been talking about

    December 30, 2025

    iMP Tech Mini Arcade Pro Review: A Nintendo Switch Arcade Cabinet

    December 29, 2025

    Sauron, the high-end home security startup for “super premium” customers, plucks a new CEO out of Sonos

    December 29, 2025

    How Much Melatonin Should You Be Taking? (2026)

    December 28, 2025
    latest posts

    Bring on 2027 I mean 2026 I mean Happy Easter

    Liam Gallagher has stoked rumours by teasing possible Oasis activity for next year. Earlier this month, the frontman appeared to confirm that the band would…

    ‘I opened her door and the wind caught me, and I went flying’: The U.S. Arctic air surge is sweeping northerners off their feet

    December 31, 2025

    The Trump Regime Threatens Artists As The Kennedy Center Will Be Empty On New Year’s Eve

    December 31, 2025

    Treat yourself: Save up to 50% on tech from Apple, Bose and more

    December 31, 2025

    The phone is dead. Long live . . . what exactly?

    December 31, 2025

    Star that seemed to vanish more than 130 years ago is found again

    December 31, 2025

    Bowie: The Final Act review – revisiting the…

    December 31, 2025
    Categories
    • Books (968)
    • Business (5,876)
    • Film (5,810)
    • Lifestyle (3,913)
    • Music (5,878)
    • Politics (5,880)
    • Science (5,222)
    • Technology (5,809)
    • Television (5,495)
    • Uncategorized (2)
    • US News (5,861)
    popular posts

    For the first time since 1989, the Super Bowl will feature alcohol ads not made by Anheuser-Busch

    Anheuser-Busch is ending its more-than-33-year-old exclusive deal with the Super Bowl. Other alcohol brands are…

    Make This Short Rib Ragu Recipe for a Cozy Night In

    November 15, 2024

    Jack White Joins SNL’s Five-Timers Club with Epic Rock Show

    February 26, 2023

    Is this idea big enough? • TechCrunch

    September 17, 2022
    Archives
    Browse By Category
    • Books (968)
    • Business (5,876)
    • Film (5,810)
    • Lifestyle (3,913)
    • Music (5,878)
    • Politics (5,880)
    • Science (5,222)
    • Technology (5,809)
    • Television (5,495)
    • Uncategorized (2)
    • US News (5,861)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    Star that seemed to vanish more than 130 years ago is found again

    December 31, 2025

    Bowie: The Final Act review – revisiting the…

    December 31, 2025

    ’90 Day Fiance’ Debbie Johnson Shares Devastating Family Death

    December 31, 2025
    © 2025 Beverly Hills Examiner. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT