In August, LastPass, one of the leading password manager services, announced that its servers had been hacked.
Over the Christmas holiday, LastPass discussedjust how bad a leak it really was.
At the time of the hack, LastPass said in a blog post that its initial investigation showed that while a hacker gained access to its development environment, "no evidence that this incident involved any access to customer data or encrypted password vaults."
Since August, LastPass has made three updates to that blog. The latest, released on December 22, revealed that the hacker involved was able to gain access to "backup customer vault data."
That includes "both unencrypted data, such as website URLs, as well as fully-encrypted, sensitive fields such as website usernames and passwords, secure notes, and form-filled data," the blog post reported.
That said, LastPass’ post adds, those fields remain encrypted, and "can only be decrypted with a unique encryption key derived from each user’s master password using our Zero Knowledge architecture."
LastPass users’ master passwords are not stored or maintained by the company, nor are they known to the company.
Though LastPass uses a minimum 12-character master password, which includes symbols, numbers and capital letters, hackers could attempt to get into the data using a brute force attack – that is, to employ software to guess combinations until getting it right.
LastPass says that if its customers use the default settings around their master password, "it would take millions of years to guess your master password using generally-available password-cracking technology."
However, according to Inc,customers should be wary of phishing attacks, where someone who appears to represent LastPass sends you an email seeking your password.
According to LastPass, there are "no recommended actions that you need to take at this time," should customers be using the default settings.
However, the site adds that those who don’t use the default settings should consider changing passwords stored there.
Regarding phishing attacks, LastPass says they will never email or contact users seeking their password information.
A password manager stores your online credentials within one program. This allows users to not have to remember complex passwords, while also allowing them to keep said passwords complex.
Besides LastPass, some of the better-known password managers include 1Password, BitWarden, Dashlaneand NordPass.
Copyright © 2023 Powered by
LastPass breach: Hacker stole passwords, company says-坐而论道网
sitemap
文章
35
浏览
85589
获赞
5364
5 things I noticed during my 24 hours with the Apple Watch Series 6
Given my very brief time with the Apple Watch Series 6, I’m a little hesitant to fully deliverChina’s Chery will reportedly launch a new EV brand this year · TechNode
Chinese car manufacturer Chery Auto will launch a new electric vehicle brand in the third quarter ofLight Year founder Wang Huiwen returns to Meituan as part
Meituan’s co-founder Wang Huiwen will return to the food delivery giant as a part-time consultant asA Games List of Only Amazing Hidden Indie Gems and Snubs
Over the past year we've been slammed with a barrage of superb games, from AAA blockbusters such asGoogle Pixel 5 leak suggests an earlier launch date
Google sort-of announced the Pixel 5 in August, saying the phone will come in the fall. Then, a leakChina’s group
Meituan Select and Duoduo Maicai, the two main players in China’s community group-buying field, haveAiming for Atoms: The Art of Making Chips Smaller
In the realm of computer chips, bigger numbers are often better. Morecores, higherGHz, and greaterFLHow JPEG Image Compression Works
In today's world of AI and machine intelligence, it sometimes skips the mind that the primary end-usApple now gives customers a full year to buy AppleCare+
If you bought an iPhone recently, Apple has some good news for you.Bloomberg reported Monday that foHow to Choose an SSD on a Flash Sale
What SSD Should You Buy? Under normal circumstances, we would simply recommend you to follow our BesThe OLED Burn
We're still aggressively burning in our test 4K OLED monitor and using exclusively it for productiviChina’s Chery will reportedly launch a new EV brand this year · TechNode
Chinese car manufacturer Chery Auto will launch a new electric vehicle brand in the third quarter ofDon't use any THC vaping product, FDA warns
The U.S. Food and Drug Administration has significantly ramped up its warnings about vaping productsA PC Gaming Music Journey: From Doom to Terraria, System Shock, and More Memorable Soundtracks
A few years back, we published a feature highlighting memorable video game music from the 8-bit and14 PC Games for Family Time Fun
It might be a rainy day, or you could have unexpected guests, or perhaps you're just in the mood for