Passwordstate password manager hacked in supply chain attack April 23, 2021 https://www.bleepingcomputer.com/ne...ssword-manager-hacked-in-supply-chain-attack/
I have never heard of them before, but looks like they are a big player? That's why 2FA stays very important, there is always a chance that username and passwords will be stolen. On the other hand, I expect better security measures from password management companies. Hopefully other big players will learn from this.
I would go one further and up an additional level even at this stage of matters to implement 3FA and really throw those hackers into a tizzy. It doesn't have to be overwhelming for the end user just a added simple step to put some real distance before the fact since they'll be experimenting crawling all over 2FA if they ever employ it as standard. But they better do it fast!
What third factor do you propose? Something you know (password) Something you have (hardware token) ? Only thing I can think of is “Something you are” (fingerprint, face, iris, voice?). What do you have in mind?
Passwordstate hackers phish for more victims with updated malware April 28, 2021 https://www.bleepingcomputer.com/ne...-phish-for-more-victims-with-updated-malware/
I do hope that most websites will soon offer 2FA via authentication apps, of course Win 10 should then be able to run those apps because I don't want to use my mobile phone for this stuff. And we all know that 2FA via SMS is not secure enough because of SIM swapping. And I forgot to say that websites should also support 2FA keys like YubiKey. https://www.androidauthority.com/best-two-factor-authenticator-apps-904743/
LOL, turns out this stuff already exists! Authy has an app for Windows, I really wonder when all major websites, think of online shopping, online banking, cloud storage and email, will implement this stuff! https://authy.com/blog/introducing-authy-for-your-personal-computer/
Passwordstate customers complain of silence and secrecy after cyberattack A supply chain attack sought to steal passwords directly from customer servers August 4, 2021 https://techcrunch.com/2021/08/04/passwordstate-supply-chain-attack/
Another bug was found in Passwordstate, makes you wonder if using a cloud based password manager is truly a good idea. https://thehackernews.com/2022/12/critical-security-flaw-reported-in.html