LastPass Says Source Code Stolen in Data Breach

Discussion in 'other security issues & news' started by guest, Aug 25, 2022.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    Now LastPass is being sued by someone who claims his crypto account got hacked because of this breach. Which would mean that hackers cracked the master password.
    https://cointelegraph.com/news/lastpass-data-breach-led-to-53k-in-bitcoin-stolen-lawsuit-alleges
     
  2. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,675
    Location:
    USA
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    BTW, about the lawsuit against Lastpass involving the stolen bitcoins, I assume it's always the user who needs to make sure he/she is using 2FA. I mean, I assume 2FA can't be bypassed just because someone cracked your password database.
     
  4. pegas

    pegas Registered Member

    Joined:
    May 22, 2008
    Posts:
    2,966
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    Yes, I know that it can be bypassed by for example phishing, but this is still the users mistake. So it will be an interesting lawsuit.
     
  6. pegas

    pegas Registered Member

    Joined:
    May 22, 2008
    Posts:
    2,966
    Right. I don't understand campaigns for strong passwords when 2FA is more important.
     
  7. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,675
    Location:
    USA
    I don't feel one is any more important than the other. And they both come up short. Everything does.
     
  8. guest

    guest Guest

    LastPass breach exposes how US breach notification laws can leave consumers in the lurch
    By lias Groll @EliasGroll | Cyberscoop - November 11, 2023
     
  9. guest

    guest Guest

    LastPass owner GoTo says hackers stole customers’ backups
    By Carly Page @carlypage_ - January 24, 2023
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    I'm surprised that nobody responded to this. This is another major blow to LastPass and GoTo's credibility. I do wonder how hackers got access to the third party cloud storage. I suppose this stuff is secured via 2FA, so it was either a phishing attack where employees were tricked to going to a fake website, or hackers planted a cookie stealer on employee PC's.
     
  11. ProTruckDriver

    ProTruckDriver Registered Member

    Joined:
    Sep 18, 2008
    Posts:
    1,447
    Location:
    "An Apple a Day, Keeps Microsoft Away"
    Hey, another day, another adventure in the cyber world. I believe everything in the cyber world is hackable to some point.
     
  12. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,675
    Location:
    USA
    I didn't bother because I already assumed that was the case. I'm glad a cancelled them and deleted my data a long time ago. I hope they weren't storing an undisclosed copy of it somewhere.
     
  13. waking

    waking Registered Member

    Joined:
    Jan 25, 2016
    Posts:
    176
    GoTo admits: Customer cloud backups stolen together with decryption key

    25 Jan 2023

    https://nakedsecurity.sophos.com/2023/01/25/goto-admits-customer-cloud-backups-stolen-together-with-decryption-key/

    "What to do?

    ...

    So, we suggest:

    Change all passwords in your company that relate to the services listed above.

    ...

    Reset any app-based 2FA code sequences that you are using on your accounts.

    ...

    Re-generate new backup codes,

    ...

    Consider switching to app-based 2FA codes if you can,

    ..."
     
  14. Hadron

    Hadron Registered Member

    Joined:
    Apr 1, 2014
    Posts:
    2,150
    They reckon some people are still using LastPass.
     
  15. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,675
    Location:
    USA
    People will still need to change all of that stuff anyway. But if anyone is intending to continue with them after this... o_O
     
  16. Hadron

    Hadron Registered Member

    Joined:
    Apr 1, 2014
    Posts:
    2,150
     
  17. ProTruckDriver

    ProTruckDriver Registered Member

    Joined:
    Sep 18, 2008
    Posts:
    1,447
    Location:
    "An Apple a Day, Keeps Microsoft Away"
    Membership for LastPass must be dropping. I keep getting the nag screen every few days now to upgrade to the paid version. I've got them only a few times in 4 or 5 years. This last data breach must of done them in.
     
  18. guest

    guest Guest

    If You Use LastPass, You Need to Change All of Your Passwords ASAP
    By Shaun - February 10, 2023
     
  19. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,675
    Location:
    USA
    That is what I would do. Immediately after closing my account and deleting my data from their servers. Except I already did that 2 years ago.
     
  20. Malcontent

    Malcontent Registered Member

    Joined:
    Dec 30, 2005
    Posts:
    612
    Location:
    Cleveland, Ohio USA
    LastPass says employee’s home computer was hacked and corporate vault taken
     
  21. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,386
  22. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    And that's why I keep saying that it doesn't hurt to use extra protection tools in addition to your AV. An anti-logger would have stopped this attack, and I'm guessing that the AV, which was probably Win Defender, was bypassed. Sure, most of us would probably not be targeted, but there are plenty of people who will be. So that's why I always criticized the ''AV + not being click happy is all you need'' mantra.

     
  23. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,675
    Location:
    USA
    Not good enough for someone that is an employee of a password manager developer and has a home PC with company data. If they are working from home they should have had a company owned PC that was used only for their job. And a personal home PC that was only used for personal use. The company PC should utilize a VPN. Another inexcusable fail by this company. They need to shut it down or sell the product to someone that takes it seriously. Under current ownership they shouldn't have any users left.
     
  24. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,256
    Location:
    Among the gum trees
    Latest email from LastPass:
     
  25. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,080
    Location:
    DC Metro Area
    "LastPass Employee Could've Prevented Hack With a Software Update

    The hacker exploited a vulnerability in the Plex Media Server software that was patched in May 2020. 'The version that addressed this exploit was roughly 75 versions ago,' Plex says...

    This week, LastPass revealed the hacker pulled off the breach by installing malware on an employee’s home computer, enabling them to capture keystrokes on the machine. But one lingering question was how the malware was delivered.

    At the time, LastPass said only that the hacker exploited 'a vulnerable third-party media software package,' without naming the vendor or the exact flaw.

    ...the hacker targeted the Plex Media Server software to load the malware on the LastPass employee's home computer. But interestingly, the exploited flaw was nothing new. According to Plex, the vulnerability is nearly three years old and was patched long ago..."

    https://www.pcmag.com/news/lastpass-employee-couldve-prevented-hack-with-a-software-update
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.