Forumite Members › General Topics › Tech › Security Talk › LastPass Master Password Compromised?
- This topic has 4 replies, 3 voices, and was last updated 4 years, 2 months ago by
wasbit.
-
AuthorPosts
-
December 29, 2021 at 7:55 am #69047
If you use LastPass you MAY have a problem. This report from Bleeping indicates a possible break-in to LastPass Master Password storage, but it does not provide very much evidence that a break-in has happened. One to watch in terms of any attacks on your financial accounts.
On my part I distrust using Cloud based password systems. I prefer to keep a limited number of passwords in a little black book for mobile use, and the full list in KeePass2 for home use only.
December 31, 2021 at 4:19 pm #69052Just seen this explanation on their blog – HERE.
Looks like it was an over protective monitoring system – preferable to a lax one!!
January 1, 2022 at 9:59 am #69054JCD, I think that may well be the explanation, as the reports did not have the hallmark of hacking everyone’s master password. That said, a lot of the web speculation around it does perhaps point to ways in which focussed attacks on an individual’s master password MAY be possible. Comfortingly such attacks usually require pwning the actual PC so they will only be of real value for long term attacks on the individual by a Nation State or criminal enterprise.
All that said, the LastPass article had some useful general advice at the end. The only bit I thought needed a bit of explanation is their so-called ‘Dark Web’ monitoring. It struck me that this was just their fancy way of using https://haveibeenpwned.com/ , use of which does need a bit of tuition. For example I know that my email address has been previously pwned a specific number of times due to failures by companies (such as Malwarebytes) not taking sufficient care to secure their databases. However each of these has emailed me concerning their failure, and I also know that I had used a throwaway password with them. HaveIbeenPwned shows that there have been no successful ‘paste-ins’ of these passwords – showing that there were actually unique. I’ll now only get very concerned if I learn that a new attack on a financially important company such as PayPal etc has leaked my current password!
I’ll get a bit concerned/annoyed if the number of companies leaking my email increases and I have not already been informed by the company concerned. If that ever happens, I will be sending a zinger, complaining about them to the UK’s Information Commissioners Office!
January 1, 2022 at 11:00 am #69055HaveIbeenPwned shows that there have been no successful ‘paste-ins’ of these passwords – showing that there were actually unique. I’ll now only get very concerned if I learn that a new attack on a financially important company such as PayPal etc has leaked my current password!
Too true!! Clear Score also perform a similar monitoring – also using it as an income stream for their Plus service @ £4.99 pm. There are probably others.
January 2, 2022 at 1:27 am #69056I must have a hundred or more passwords yet have never seen the need to use a password manager.
HaveIbeenpawned shows that my name has been compromised 5 times. One is dropbox which I have never used & the other 4 I’ve never heard of.
IIRC my name dates back to registering on the Micromart forums back in the 90’s. In all that time I’ve only had to jump through Microsoft hoops to secure my email twice.
--
Regards
wasbitRig 1: Optiplex 3050 SFF
Rig 2: Asus ROG G20CB (rebuilt wreck)
Rig 3: HP Elitebook 8440PDear Starfleet, hate you, hate the Federation, taking Voyager. - Janeway
-
AuthorPosts
- You must be logged in to reply to this topic.
