Fun

Lastpass Data Breach Frightens Users, Some Say Hack ‘May Be Worse Than They Are Letting on’

News Feed - 2022-12-25 07:12:05

Lastpass Data Breach Frightens Users, Some Say Hack ‘May Be Worse Than They Are Letting on’


People involved in financial tech, software programming, cyber security, and cryptocurrencies have been talking about the Lastpass data breach that was disclosed two days ago. The password management company detailed that a breach, committed earlier this year, allowed hackers to obtain a “backup of customer vault data.” Lastpass Reveals ‘Threat Actor Was Also Able to Copy a Backup of Customer Vault Data’


On Dec. 22, 2022, the password management firm Lastpass disclosed that an “unknown threat actor” managed to breach the firm’s cloud-based storage environment in or around Aug. 2022. As soon as the news was published, the Lastpass data leak has been a topical discussion on social media and forums. A great number of people believe that Lastpass’ situation “may be worse than they are letting on.” LastPass attackers now know all websites you have passwords stored for and the blobs, encrypted only by your master password https://t.co/Wdbt6mWe8C https://t.co/HldcJ8DYkK


— SwiftOnSecurity (@SwiftOnSecurity) December 22, 2022



“Based on our investigation to date, we have learned that an unknown threat actor accessed a cloud-based storage environment leveraging information obtained from the incident we previously disclosed in August of 2022,” Lastpass disclosed. The password management company added: The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.


Lastpass insists the encrypted fields are secure with 256-bit AES encryption and the info can only be decrypted by leveraging each user’s master password using the firm’s zero-knowledge architecture. “As a reminder, the master password is never known to Lastpass and is not stored or maintained by Lastpass,” the company detailed. lastpass gets hacked and immediately after a ton of crypto wallets are broken into and drained


“be your own bank”


nah go break into a brick & mortar establishment if you want my funds nerds, good luck


— gainzy (@gainzy222) December 24, 2022


Lastpass’ Security Reassurance Doesn’t Seem to Convince a Number of Critics


However, a number of reports believe that the situation is worse than Lastpass is letting on. Reviewgeek.com’s Andrew Heinzman stresses in his report to “please, stop using Lastpass.” “Even if you use a strong master password, there’s a chance that hackers will try to phish some information out of you,” Heinzman wrote. The author added: To be clear, Lastpass is still investigating this data breach. And after four months of ‘sorry, it’s worse than we thought,’ customers are rightfully worried that Lastpass doesn’t have all the details. For all we know, things could get even worse. We asked our readers to stop using Lastpass in July 2020.


Crypto supporter Udi Wertheimer also warned people that if they use Lastpass “attackers probably have a copy of your vault.” Wertheimer’s recommendation is the same as Heinzman’s as the digital currency proponent insisted that users should “stop using Lastpass.”


“We don’t know how bad things are,” Wertheimer added. “It’s possible that attackers have ongoing access, so don’t just change your passwords and put them back into Lastpass.” Moreover, a Twitter user who claims to have worked as an engineer for the company seven years ago also noted that Lastpass’ breach situation is a big deal.


“I worked at Lastpass as an engineer a long time ago. 7+ years ago. My 2 cents on the situation,” the individual said. “This is the worst breach Lastpass has had. By a lot. The key difference is that customer vaults were accessed this time, which are kept in a completely separate database.” Tags in this story 256-bit AES encryption, Andrew Heinzman, Crypto, Digital Assets, encrypted fields, former engineer, Lastpass, Lastpass data breach, password management firm, Passwords, Reviewgeek.com, secret passwords, Security, Seeds, Udi Wertheimer, zero-knowledge architecture


What do you think about the Lastpass data breach and the speculation that it is worse than Lastpass is letting on? Let us know what you think about this subject in the comments section below. Jamie Redman


Jamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 6,000 articles for Bitcoin.com News about the disruptive protocols emerging today. North Korean Lazarus Group Linked to New Cryptocurrency Hacking Scheme SECURITY | Dec 5, 2022 Hackers Are Taking Advantage of Typing Mistakes to Steal Cryptocurrency SECURITY | Oct 25, 2022


Image Credits: Shutterstock, Pixabay, Wiki Commons Previous articleCrypto Community Asks: Where in the World Is Ex-Alameda CEO Sam Trabucco? Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments More Popular NewsIn Case You Missed ItFidelity Investments Launches Crypto, Metaverse ETFs — Says "We Continue to See Demand"


Fidelity Investments, one of the largest financial services firms with more than $11 trillion under administration, is launching exchange-traded funds (ETFs) focusing on the crypto ecosystem and the metaverse. "We continue to see demand, particularly from young investors, for access ... read more.Privacy-Centric Monero Plans for July Hard Fork, Plans Include Ring Signature, Bulletproof Upgrade Australia to List Bitcoin ETF After 4 Clearinghouse Participants Commit to Meet Stringent Margin Terms Fed"s Bullard Wants to Raise Bank Rate to 3.5% by Year"s End, Hints at 75 Basis Point Rate Hike Iran to Increase Penalties for Unauthorized Cryptocurrency Mining

News Feed

Gareth Jenkinson45 minutes agoWeb3 gaming investors more ‘choosy’ in crypto winter — Animoca’s Robby YungAnimoca Brands CEO Robby Yung says investors have been more discerning when allocating capital to Web3 gami
Helen Partz13 hours agoCoinbase wins NFA approval to offer Bitcoin and Ether futures in USCoinbase is preparing to roll out cryptocurrency futures trading for institutional investors in the United States.4880 Total views
Bitcoin.com’s Mining Video Censored: The Tale of Youtube’s Blatant Censorship and Propaganda
Bitcoin.com"s Mining Video Censored: The Tale of Youtube"s Blatant Censorship and PropagandaDuring the last few years, the Google-owned Youtube platform has been accused of massive
Bitcoin approaches $60,000 after 3.7% daily gain
Zoltan Vardai1 minute agoBitcoin approaches $60,000 after 3.7% daily gainThe last time Bitcoin traded at similar levels was in November 2021, before correcting from its all-time high of $68,789.6 Total viewsMarkets NewsO
Brayden Lindrea6 hours agoStablecoin issuer Circle weighing up 2024 public launch: ReportCircle initially agreed to go public as part of a $4.5-billion merger in July 2021, but that deal fizzled out.2539 Total views8 Tot
Ezra Reguerra52 minutes agoBitcoin Ordinals creator proposes to change inscription numbering systemCasey Rodarmor, the creator of Bitcoin Ordinals, clarified that the inscription numbers would only be changed, not scrapp
Brazilian Cryptocurrency Exchange Mercado Bitcoin Lays Off 15% of Workforce Due to Global Economy Woes
Brazilian Cryptocurrency Exchange Mercado Bitcoin Lays Off 15% of Workforce Due to Global Economy Woes Mercado Bitcoin, one of the biggest Brazilian cryptocurrency exchanges, has a
Crypto Owners in Serbia Reach 200,000 as Country Regulates Digital Assets
Crypto Owners in Serbia Reach 200,000 as Country Regulates Digital Assets The number of cryptocurrency holders in Serbia has climbed to around 200,000 with interest in cryptocurren
Bitcoin RSI Targets Daily Retest That Triggered 2024 Price Rally, What Happened Last Time
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Minting Basic Income – US Lawmaker Asks Treasury to Issue Two $1 Trillion Coins With No Debt
Minting Basic Income - US Lawmaker Asks Treasury to Issue Two $1 Trillion Coins With No Debt The U.S. is now facing the onslaught from the coronavirus outbreak. During the last t
Bitcoin Rally To Continue If This Level Holds, Is $110,000 The Next Stop?
Este artículo también está disponible en español. After surpassing its $100,000 milestone, Bitcoin (BTC) recorded its largest retrace in the past month before recovering.
HSBC’s CEO Explains Why Crypto Is Not in the Banking Giant’s Future
HSBC"s CEO Explains Why Crypto Is Not in the Banking Giant"s Future Banking giant HSBC will not be offering crypto services, according to CEO Noel Quinn. Noting that HSBC is more n