7 ms·
Note that master passwords were not compromised, the the warnings were triggered in error[1]. That's not to say that other concerns around security aren't valid
by basseq 5y ago
Note that master passwords were not compromised, the the warnings were triggered in error[1]. That's not to say that other concerns around security aren't valid.
[1] https://www.theverge.com/2021/12/28/22857485/lastpass-compromised-breach-scare https://www.theverge.com/2021/12/28/22857485/lastpass-compro...
- computershit 5y agoThe warnings might have been triggered in error, but the evidence is certainly there for masters to have been compromised. Until recently their publicly available support forum running phpBB was using the master password for customer logins.[1] [1] https://news.ycombinator.com/item?id=29706579 https://news.ycombinator.com/item?id=29706579
- basseq 5y agoI'm trying to differentiate between "there has been evidence of a breach" and "there are less-desirable security practices". As I understand it, the phpBB / master password practices—which are indeed, not good, but also not fully understood exactly how they did it—are also not evidence that the masters have been compromised. Again, that it could be an attack vector is interesting and relevant, but different from "has been breached" per OP.