Passwordstate password manager hacked in supply chain attack

Discussion in 'other security issues & news' started by guest, Apr 23, 2021.

  1. guest

    guest Guest

    Passwordstate password manager hacked in supply chain attack
    April 23, 2021
    https://www.bleepingcomputer.com/ne...ssword-manager-hacked-in-supply-chain-attack/
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I have never heard of them before, but looks like they are a big player? That's why 2FA stays very important, there is always a chance that username and passwords will be stolen. On the other hand, I expect better security measures from password management companies. Hopefully other big players will learn from this.
     
  3. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,544
    Location:
    U.S.A. (South)
    I would go one further and up an additional level even at this stage of matters to implement 3FA and really throw those hackers into a tizzy. It doesn't have to be overwhelming for the end user just a added simple step to put some real distance before the fact since they'll be experimenting crawling all over 2FA if they ever employ it as standard. But they better do it fast!
     
  4. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,425
    What third factor do you propose?
    1. Something you know (password)
    2. Something you have (hardware token)
    3. ?
    Only thing I can think of is “Something you are” (fingerprint, face, iris, voice?).

    What do you have in mind?
     
  5. guest

    guest Guest

    Passwordstate hackers phish for more victims with updated malware
    April 28, 2021
    https://www.bleepingcomputer.com/ne...-phish-for-more-victims-with-updated-malware/
     
  6. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    178,841
    Location:
    Texas
    Click Studios asks customers to stop tweeting about its Passwordstate data breach
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I do hope that most websites will soon offer 2FA via authentication apps, of course Win 10 should then be able to run those apps because I don't want to use my mobile phone for this stuff. And we all know that 2FA via SMS is not secure enough because of SIM swapping. And I forgot to say that websites should also support 2FA keys like YubiKey.

    https://www.androidauthority.com/best-two-factor-authenticator-apps-904743/
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    LOL, turns out this stuff already exists! Authy has an app for Windows, I really wonder when all major websites, think of online shopping, online banking, cloud storage and email, will implement this stuff!

    https://authy.com/blog/introducing-authy-for-your-personal-computer/
     
  9. guest

    guest Guest

    Passwordstate customers complain of silence and secrecy after cyberattack
    A supply chain attack sought to steal passwords directly from customer servers
    August 4, 2021
    https://techcrunch.com/2021/08/04/passwordstate-supply-chain-attack/
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Another bug was found in Passwordstate, makes you wonder if using a cloud based password manager is truly a good idea.

    https://thehackernews.com/2022/12/critical-security-flaw-reported-in.html
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.