home.social

#lastpassbreach — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lastpassbreach, aggregated by home.social.

fetched live
  1. Since I’m writing a lot about #LastPass and #LastPassBreach lately, I realized that maybe I should disclose my financial ties to the company. I’ve received $20,500 via the LastPass bug bounty program for 9 security issues reported between 2016 and 2018. Another 3 reported security issues received no monetary reward.

    Also, following my findings about LastPass’ inadequate account data protection in 2018 (palant.info/2018/07/09/is-your), there was a discussion about a consulting agreement allowing me to do a more thorough review of the code. This agreement never materialized, and I suspect that it was part of their overall delay tactics or intended to make me write more favorably about them.

  2. Ich möchte mich endlich von #LastPass trennen, wenn ich schon all meine Passwörter ändern muss, wegen #lastpassbreach. Welche Alternativen schlagt Ihr vor? #Geräteübergreifend, #Opensource und #authenticator wären toll...

    #feditips

  3. Interesting point on this week's @riskybusiness: the Plex attack that allowed hackers to gain access to a LastPass employee's home network had all the hallmarks of North Korean TTPs.

    Hmm.

    #LastPass #LastPassBreach #NorthKorea #Plex

  4. More on the #LastPassBreach . I had no idea the threat actor used a vulnerability in #plex in the supply chain attack. It still seems a little incredulous that a security company gets exposed like this. itpro.co.uk/security/informati #cybersecurity #devops

  5. If you are or have been a user, we recommend changing the email addresses you had used for the accounts affected, and replacing them with SimpleLogin aliases. This way, even if it turns out a particular account of yours was compromised, at least you don't need to change your main email address too.

    thehackernews.com/2023/03/last

  6. @alrowell

    People don't realize the importance of simple updates that are made to the #apps they use.

    We often delay updates, because there are no real "new features" or "functionality", but often these updates are only for #security reasons and zero-day exploits!

    #Security #Infosec #Lastpass #Lastpassbreach

  7. Wait. Seine Passwörter in Internet speichern war vielleicht doch keine so gute Idee?!?! #LastPassBreach

  8. Realized that my ssh keys' passwords were in my #LastPass vault, along with fingerprints and randomart images. The actual keys were not in my LastPass vault.

    I'm planning to eventually generate new keys.

    Assuming a fairly strong, unique, LastPass password, is this a "do it when you get time" situation or a "do it right now" emergency? Or maybe a "doesn't matter, don't worry" situation?

    #LastPassBreach #SSH #linux

  9. Been working with the #LastPass tool that Steve Gibson publicized on the latest #SecurityNow podcast (episode 905). But ran into an issue with shared folders, and covered it in this blog post.

    boojit.com/blog/2023-01-13.1+L

    #LastPassBreach #LastPassHack

  10. What sucks, as a security student and advocate, I tell people that using any password manager is better than nothing... now something like this happens and a lot of us have to explain and re-assure people...

    A lot of security people might be taking a hit in their credibility when things like this happen and have to deal with people who are skeptics/doubters to begin with...

    #lastpass #LastPassHack #LastPassBreach #cybersecuritynews
    youtube.com/watch?v=SoyYpq4y6X

  11. I keep hearing from people about #LastPass accounts configured with one iteration. At the same time people point out that super admin accounts hold the keys to decrypting all of the users’ vaults. And that Federated Login doesn’t apply to super admin accounts – these are still only protected by their master password.

    Guess it’s only a matter of time until the attackers find a weakly protected super admin account and use that to compromise a company?

    #LastPassBreach

    palant.info/2022/12/28/lastpas

  12. After the #LastPassBreach, I of course (almost) immediately changed financial #passwords (and where possible security question answers), but just realized - also need to prioritize changing email passwords.

    Someone gets control of email, they can easily reset financial passwords.

    Maybe 2FA stops them, maybe not, but ... excuse me while I go change some more passwords.

    #PasswordSecurity

  13. @Mikal Its not so much _your_ password that counts when the DJI data vault gets hacked despite their glib assurances of "security", b/c then all you can do is reset your pwd again (and again). Assuming they detected the breach.

    If you have not already done it, use HaveIBeenPwned.com to see where your emails/phones show up in hacks.

    I was reading about the #LastPass #LastPassBreach #LastPassHack and decided since my vault had been exposed, even tho' encrypted, that since LastPass didn;t reveal all details, they aren't to be trusted, so I switched pw managers to another popular one.

  14. I've got some more stuff to share on the topic no one is tired of at all!

    All of my LastPass entries were imported into my 1Password database years ago, so I thought it would be interesting to compare identical entries for a dead website.

    LastPass
    aid: 1.60577E+18
    Name: !PgUXybVLhnoydfkiQhXTjA==|022V5QScfEZZzaEY5h6ElA==
    Folder:
    URL: https://caws.nsslabs.com/set-password?securityString=APkRXvUgjNt3Mg1stbCUdBFG49OohVo9Shq-poWF9FP2lZu-oG7ReV_ygxV_hSIHOSiW8f
    Notes:
    Favorite: 0
    sharedfromaid:
    Username: !Cz0igRZjJfTURlCYPVmDCg==|mC9GeBig4TamB1yVSBVJaD6TWwORMOb5qat9n5T6SXo=
    Password: !CWas/v6nucD06bpllCkjTg==|l5jhMbYuXKHRnzcAQialo4i28aI89npzM3vBGABWbHM=
    Require Password Reprompt: 0
    Generated Password: 0
    Secure Notes: 0
    Last Used: 0
    AutoLogin: 0
    Disable Autofill: 0
    realm_data:
    fiid: 1605774395875220000
    custom_js:
    submit_id:
    captcha_id:
    urid: 0
    basic_auth: 0
    method:
    action:
    groupid:
    deleted: 0
    attachkey:
    attachpresent:
    individualshare: 0
    Note Type:
    noalert:
    Last Modified: 1561234492
    Shared with Others: 0
    Last Password Changed: 1495549680
    Created: 1495549680
    vulnerable:
    Auto Change Password Supported: 0
    breached: 0
    Custom Template:
    Form Fields: [{"Field Name": "ma_user", "Field Type": "text", "Field Value": "!YgV1yTdEegNlhczJUH4oWw==|KiOfBB3Vnl/mOuZUeYmg/PK1rLwCEhUSsA3ts61uf/E=", "checked": ""}, {"Field Name": "ma_pwd", "Field Type": "password", "Field Value": "!z3CzBVFn3yD584XhMcda+A==|b4l7UwC9ssXKm5NDGiUVLA==", "checked": ""}, {"Field Name": "ma_host", "Field Type": "text", "Field Value": "!i7L+hHHM+BT1BlcbrUunMg==|/UJdgtc7vdJrDLipNvo0eQ==", "checked": ""}, {"Field Name": "ma_user", "Field Type": "text", "Field Value": "!YgV1yTdEegNlhczJUH4oWw==|KiOfBB3Vnl/mOuZUeYmg/PK1rLwCEhUSsA3ts61uf/E=", "checked": ""}, {"Field Name": "ma_pwd", "Field Type": "password", "Field Value": "!z3CzBVFn3yD584XhMcda+A==|b4l7UwC9ssXKm5NDGiUVLA==", "checked": ""}, {"Field Name": "ma_host", "Field Type": "text", "Field Value": "!i7L+hHHM+BT1BlcbrUunMg==|/UJdgtc7vdJrDLipNvo0eQ==", "checked": ""}]

    1Password
    id: 1233
    vault_id: 9
    uuid: um2nkxniqzcdhpzn2vyvyfbhh4
    created_at: 1433513635
    updated_at: 1671820229
    template_uuid: 001
    changer_uuid: TE6YHRU26ZFK7PC4GW2UWLX6AI
    favorite: 0
    trashed: 0
    version: 8
    local_edit_count: 0
    rejection_reason: 0
    enc_overview: {"cty":"b5+jwk+json","kid":"nopmw2gamqd2jartqm6r6rdc6i","enc":"A256GCM","iv":"5C5wDOGLVTEsBHv-","data":"U18pH3zUmEHltlJOpJlSdXu7sfz7EaXgADyQevxYiPKKumx-n70h3HH6BlOMQ1ohtGRq8DK8zhzj0ZMlBwVjxRCc_V8nCCuJSoei5_6J-dbT612dmrKg3D0XkWDe4xYNfKKnHixT0519OhVO_rEgZSb_NkogkvInyQqtzl3HQYy6IH8z6CP9dP35NA-r6RXZgh5QoKUuj3C7SeJtxeI5Xf6DxyfxFqpG5eStYLijBkTUVp8pCIpt1fYBQGfk72oemGt9DxsGgsPMWos"}
    validated: 1

    #LastPassBreach

  15. Here is an interesting Youtube video about the #LastPassBreach
    Personally, I am not as confident as the dude in the video given all the GPGPU's in the hands of NK, CCP & Russ and have migrated all my #passwords to #keepass and maybe #BitWarden

    youtu.be/x2K2h6W4pTw

    Via @tomlawrence

  16. The #lastpassbreach has been weighing heavily on my mind since the most recent announcement. I was lucky enough to score an interview with @boblord from CISA to get his take on all of this.

    Tune in Monday for our chat and my recommendations:
    podcast.firewallsdontstopdrago

  17. @Jwilliams

    Thank you. That makes me feel much better.

    I changed a bunch of financial site passwords and (when possible) usernames and security question answers anyhow. To be safe / Out of an abundance of caution.

    #PWGen passwords make great security question answers:

    Q: Favorite elementary school teacher?

    A: L1m9J9b9hcqXUZ2

    #Security #PasswordSecurity #LastPassBreach #LastPass