home.social

#lastpassbreach — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lastpassbreach, aggregated by home.social.

  1. @Jwilliams

    Thank you. That makes me feel much better.

    I changed a bunch of financial site passwords and (when possible) usernames and security question answers anyhow. To be safe / Out of an abundance of caution.

    #PWGen passwords make great security question answers:

    Q: Favorite elementary school teacher?

    A: L1m9J9b9hcqXUZ2

    #Security #PasswordSecurity #LastPassBreach #LastPass

  2. I just did my final deletion of #LastPass account. I imported everything into the password vault associated with my VPN, #NordPass, If they can’t keep shit secure, I don’t know who can!

    and so far the tools are just really nice and slick. I’m really liking it. :)

    #LastPassBreach

  3. I published an article on the #LastPassBreach: palant.info/2022/12/23/lastpas

    This is very serious, no matter what #LastPass says. From the article:

    “This makes it sound like decrypting the passwords you stored with LastPass is impossible. It also prepares the ground for blaming you, should the passwords be decrypted after all: you clearly didn’t follow the recommendations. Fact is however: decrypting passwords is expensive but it is well within reach. And you need to be concerned.”

    Another conclusion from this article: #PBKDF2 is dead. Yes, you have that officially from me. If you still use it, feel free to go and fix that now.