Main menu

Pages

Lastpass Data Breach Scares Users, Some Say Hack 'Could Be Worse Than They're Letting On' – Security Bitcoin News

People involved in financial technology, software programming, cybersecurity and cryptocurrencies have been talking about the Lastpass data breach that was publicized two days ago. The password management company detailed that a breach, committed earlier this year, allowed hackers to obtain a “backup of customer vault data”.

Lastpass reveals that ‘the threat actor was also able to copy a backup of the client’s vault data’

On December 22, 2022, password management company Lastpass disclosed that an “unknown threat actor” managed to breach the company’s cloud-based storage environment around August 2022. As soon as the news was published, the leak of Lastpass data has been a topical discussion on social networks and forums. A large number of people believe that Lastpass’ situation “could be worse than they’re letting on”.

“Based on our investigation to date, we have discovered that an unknown threat actor accessed a cloud-based storage environment by leveraging information obtained from the incident we previously disclosed in August 2022,” Lastpass disclosed. The password management company added:

The threat actor was also able to copy a backup of the customer vault data from the encrypted storage container, which is stored in a proprietary binary format that contains unencrypted data such as website URLs, as well as fully encrypted sensitive fields such as website users. and passwords, secure notes and data filled in forms.

Lastpass insists that encrypted fields are secure with 256-bit AES encryption and that information can only be decrypted by leveraging each user’s master password using the company’s zero-knowledge architecture. “As a reminder, the master password is never known by Lastpass and is not stored or maintained by Lastpass,” the company detailed.

Lastpass’s security guarantee doesn’t seem to convince many critics

However, several reports believe that the situation is worse than Lastpass is letting on. Andrew Heinzman of Reviewgeek.com emphasizes in his report “please stop using Lastpass”. “Even if you use a strong master password, there is a chance that hackers will try to steal some information from you,” Heinzman wrote. The author added:

To be clear, Lastpass is still investigating this data breach. And after four months of ‘sorry, it’s worse than we thought’, customers are concerned that Lastpass doesn’t have all the details. For all we know, things could get even worse. We asked our readers to stop using Lastpass in July 2020.

Cryptocurrency supporter Udi Wertheimer also warned people who, if they use Lastpass, “attackers probably have a copy of your vault”. Wertheimer’s recommendation is the same as Heinzman’s, as the digital currency proponent insisted that users should “stop using Lastpass.”

“We don’t know how bad things are,” Wertheimer added🇧🇷 “It’s possible for attackers to have continued access, so don’t just change your passwords and put them back in Lastpass.” Furthermore, a Twitter user who claims to have worked as an engineer for the company for seven years also noted that the Lastpass breach situation is a big problem.

“I worked at Lastpass as an engineer a long time ago. 7+ years ago. My 2 cents on the situation,” the individual said🇧🇷 “This is the worst breach Lastpass has had. For much. The main difference is that customer vaults were accessed this time, which are kept in a completely separate database.”

Tags in this story

256-bit AES encryption, Andrew Heinzman, Encryption, Digital assets, encrypted fields, ex-engineer, Lastpass, Lastpass data breach, password management company, Passwords, Reviewgeek.com, secret passwords, Security, Seeds, Udi Wertheimer, zero knowledge architecture

What do you think of the Lastpass data breach and the speculation that it’s worse than Lastpass is letting on? Let us know what you think about this in the comments section below.

Jamie Redman

Jamie Redman is the head of news at Bitcoin.com News and a fintech journalist based in Florida. Redman has been an active member of the cryptocurrency community since 2011. He is passionate about Bitcoin, open source and decentralized applications. Since September 2015, Redman has written over 6,000 articles for Bitcoin.com News on the disruptive protocols emerging today.




image credits: Shutterstock, Pixabay, Wiki Commons

disclaimer: This article is for information purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services or companies. Bitcoin.com does not provide investment, tax, legal or accounting advice. Neither the company nor the author are responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.

Comments