【Kurt Meinicke】
In August,Kurt Meinicke LastPass, one of the leading password manager services, announced that its servers had been hacked.
Over the Christmas holiday, LastPass discussedjust how bad a leak it really was.
At the time of the hack, LastPass said in a blog post that its initial investigation showed that while a hacker gained access to its development environment, "no evidence that this incident involved any access to customer data or encrypted password vaults."
You May Also Like
Since August, LastPass has made three updates to that blog. The latest, released on December 22, revealed that the hacker involved was able to gain access to "backup customer vault data."
That includes "both unencrypted data, such as website URLs, as well as fully-encrypted, sensitive fields such as website usernames and passwords, secure notes, and form-filled data," the blog post reported.
That said, LastPass’ post adds, those fields remain encrypted, and "can only be decrypted with a unique encryption key derived from each user’s master password using our Zero Knowledge architecture."
LastPass users’ master passwords are not stored or maintained by the company, nor are they known to the company.
Could hackers get into LastPass passwords and data?
Though LastPass uses a minimum 12-character master password, which includes symbols, numbers and capital letters, hackers could attempt to get into the data using a brute force attack – that is, to employ software to guess combinations until getting it right.
LastPass says that if its customers use the default settings around their master password, "it would take millions of years to guess your master password using generally-available password-cracking technology."
However, according to Inc,customers should be wary of phishing attacks, where someone who appears to represent LastPass sends you an email seeking your password.
What should LastPass users do about the breach?
According to LastPass, there are "no recommended actions that you need to take at this time," should customers be using the default settings.
Related Stories
- What is Hermit spyware and how do you protect yourself from it?
- Bumble makes cyberflashing detection tool available as open-source code
- Twitter hack shows need for cybersecurity regulations, govt. report says
- The very best password managers, as recommended by our experts
- This $20 lifetime subscription adds a fully-functional second number to your phone
However, the site adds that those who don’t use the default settings should consider changing passwords stored there.
Regarding phishing attacks, LastPass says they will never email or contact users seeking their password information.
What is a password manager?
A password manager stores your online credentials within one program. This allows users to not have to remember complex passwords, while also allowing them to keep said passwords complex.
Besides LastPass, some of the better-known password managers include 1Password, BitWarden, Dashlaneand NordPass.
Topics Apps & Software Cybersecurity
Search
Categories
Latest Posts
Barcelona Open 2025 livestream: Watch live tennis for free
2025-06-26 21:47Everything coming to Hulu in October 2020
2025-06-26 21:42Jimmy Kimmel tweets update on 3
2025-06-26 20:19Perplexity's new Deep Research tool is powered by DeepSeek R1
2025-06-26 19:54Popular Posts
10 Free Steam Games Worth Playing
2025-06-26 21:53'Sopranos' memes are having a real moment in 2020
2025-06-26 20:30Nintendo Switch 2 preorder just days away, per leak
2025-06-26 20:20Featured Posts
Trump tariff news: See the latest impacts on consumer tech
2025-06-26 22:12Stubbs the cat, longtime mayor of an Alaska town, dies at 20
2025-06-26 21:53An Xbox mic drop: Microsoft acquires Bethesda Softworks
2025-06-26 21:24Ramy Youssef's Emmy loss tweet deserves its own award
2025-06-26 20:34Popular Articles
Patched Desktop PC: Meltdown & Spectre Benchmarked
2025-06-26 21:565 significant history
2025-06-26 21:48Everything coming to Hulu in October 2020
2025-06-26 21:42Jimmy Kimmel tweets update on 3
2025-06-26 20:46Boeing's new VR simulator immerses astronauts in space training
2025-06-26 19:56Newsletter
Subscribe to our newsletter for the latest updates.
Comments (79424)
Warmth Information Network
Japan orders Google to stop alleged antitrust violations
2025-06-26 22:14Inspiration Information Network
How to reduce remote learning burnout in kids
2025-06-26 22:03Discovery Information Network
That 'Futurama' guy is now the White House Communications Director
2025-06-26 21:22Pursuit Information Network
LAPD used facial recognition software tied to wrongful arrests
2025-06-26 21:12Impression Information Network
Against Fear
2025-06-26 21:05