LastPass Hacked, Change Your Master Password Now
-
Ouch - I've been considering using Password Card - if they are still around...
Which they are....
-
Well, I'm changing my password. I even considered moving away from LastPass but I think that's a bit extreme.
-
I didn't even know lastpass existed until reading this and so nothing of significance was lost... for me. I feel bad for anyone who does suffer because of whatever the issue here was. Being able to take a bunch of hashes really almost always is a result of an SQL injection, probably UNION SELECT to just pull down all of the password hashes. For god's sake escape your queries.
-
Everything I've read suggests that the encryption method LastPass uses means that even with the hashes and salts, brute forcing passwords would take a very long time, even with the weakest of passwords. As long as you change your password in the near future I'd say that you're safe.
-
Yes, cracking a good password hash is very non-trivial. Assuming that they have access to the Amazon cloud fleet, I'm guessing this is still quite some time to crack.
-
I agree with Nick and Scott - while this is not good, it's definitely not as bad as it sounds... the bad thing - non technical people won't understand why and they'll just crucify LastPass instead.
If I mentioned this to my boss she would kill my desire to push out this service to our users.
-
@Dashrender said:
I agree with Nick and Scott - while this is not good, it's definitely not as bad as it sounds... the bad thing - non technical people won't understand why and they'll just crucify LastPass instead.
If I mentioned this to my boss she would kill my desire to push out this service to our users.
Pushing last pass to users- is it as a suggestion to all users to manage their own pass or will it be used as a password manager for company use?
-
Yeah, I was not even going to try and change passwords today. The last time this happened (2010 ??) the reset servers were completely overwhelmed.
-
@Dashrender said:
I agree with Nick and Scott - while this is not good, it's definitely not as bad as it sounds... the bad thing - non technical people won't understand why and they'll just crucify LastPass instead.
I'll include myself as non technical person here. It does further put me off hosted solutions. That's not the only reason I use on-premise (Keepass) as I didn't really like LastPass when I tried it anyway. I do store my Keepass databases in the cloud though, but that's a different risk.
-
@Ambarishrh said:
@Dashrender said:
I agree with Nick and Scott - while this is not good, it's definitely not as bad as it sounds... the bad thing - non technical people won't understand why and they'll just crucify LastPass instead.
If I mentioned this to my boss she would kill my desire to push out this service to our users.
Pushing last pass to users- is it as a suggestion to all users to manage their own pass or will it be used as a password manager for company use?
At this point it's a suggestion to users so they can manage their own passwords. A few have tried it so far, and like any password manager has quite a learning curve, it's going OK.
-
@Carnival-Boy said:
@Dashrender said:
I agree with Nick and Scott - while this is not good, it's definitely not as bad as it sounds... the bad thing - non technical people won't understand why and they'll just crucify LastPass instead.
I'll include myself as non technical person here. It does further put me off hosted solutions. That's not the only reason I use on-premise (Keepass) as I didn't really like LastPass when I tried it anyway. I do store my Keepass databases in the cloud though, but that's a different risk.
The sad fact of the matter is that unless you completely unplug yourself, you just can't avoid hosted solutions. I say sad, and others will say, what makes it sad? Life has so many advantages today because of the hosted/integrated solutions - this is a conundrum I haven't reconciled yet.