G+_George Kozi Posted June 15, 2015 Share Posted June 15, 2015 Can this be true? Originally shared by Liz Quilty Ouch :/ http://lifehacker.com/lastpass-hacked-time-to-change-your-master-password-1711463571 Link to comment Share on other sites More sharing options...
G+_Randy Hudson Posted June 15, 2015 Share Posted June 15, 2015 Gotta love it Link to comment Share on other sites More sharing options...
G+_Dalt Wisney Posted June 15, 2015 Share Posted June 15, 2015 Everything gets hacked eventually. Everything. Link to comment Share on other sites More sharing options...
G+_Jean-Pierre White Posted June 16, 2015 Share Posted June 16, 2015 Read the lastpass blog. It's true. Link to comment Share on other sites More sharing options...
G+_Joshua “Wizdum” Burgess Posted June 16, 2015 Share Posted June 16, 2015 Dalt Wisney The difference here is that LastPass actually has internal security policies in place to minimize the damage. In the email from LastPass: "We wanted to alert you that, recently, our team discovered and immediately blocked suspicious activity on our network. No encrypted user vault data was taken, however other data, including email addresses and password reminders, was compromised." Passwords were not compromised. If you have a decent master password that you only use for LastPass, and your password hint isn't obvious, you're fine. Link to comment Share on other sites More sharing options...
G+_Travis Hershberger Posted June 16, 2015 Share Posted June 16, 2015 Is it true? Yes. Is it something to be concerned about? Not so much this time. LastPass is one of the few companies that seems to have gotten security right. So change your master password and move on. Link to comment Share on other sites More sharing options...
G+_Dalt Wisney Posted June 16, 2015 Share Posted June 16, 2015 LastPass is a combination of the app, network, company, its policies, security processes, etc. You compromise one piece and the whole thing is compromised. Good security doesn't imply that something won't be hacked, just that there are (tested) controls in place to minimize the damage. Besides, changing the master pw is a good idea no matter what the reason. Link to comment Share on other sites More sharing options...
G+_Steve Gledhill Posted June 16, 2015 Share Posted June 16, 2015 You should work on the basis that the email address you use to log in to Lastpass and your password reminder is compromised. If there is a chance that someone can use your reminder to guess your password then change it. Otherwise: you will be OK. Link to comment Share on other sites More sharing options...
G+_Joe Phillips Posted June 16, 2015 Share Posted June 16, 2015 Yubikey Link to comment Share on other sites More sharing options...
G+_Jeremy Oelke Posted June 16, 2015 Share Posted June 16, 2015 You don't need to change your password. It was only customer emails addresses that got taken. None of their deep security sector was breached. And i got an email from last pass they are being really open about this. Link to comment Share on other sites More sharing options...
G+_Steve Gledhill Posted June 16, 2015 Share Posted June 16, 2015 Jeremy Oelke They also got your password reminder so if your password reminder can be used to guess your password then you should change it. Link to comment Share on other sites More sharing options...
G+_Joshua “Wizdum” Burgess Posted June 16, 2015 Share Posted June 16, 2015 Steve Gledhill If your password reminder can be used to guess your password, you need to change your password even if there wasn't a breach.. Link to comment Share on other sites More sharing options...
G+_Steve Gledhill Posted June 16, 2015 Share Posted June 16, 2015 Joshua Burgess True, but if the bad guys have thousands of password hints they can cherry-pick the easy to guess ones rather than trying to reset lp based only on email and then looking at the hint. Your chance of your weak hint has just increased substantially because you will be at the top of their list. All in all, a timely reminder for people to be careful about their password recovery information. Link to comment Share on other sites More sharing options...
G+_Dalt Wisney Posted June 16, 2015 Share Posted June 16, 2015 If in doubt, change your pw. Link to comment Share on other sites More sharing options...
Recommended Posts