masto.ai is one of the many independent Mastodon servers you can use to participate in the fediverse.
A general Mastodon server for all languages.

Administered by:

Server stats:

2.2K
active users

#LastPassHack

0 posts0 participants0 posts today
@MulticlassGeek@meow.social has moved to @MulticlassGeek@mas.to<p>Actually laughed out loud at the email from LastPass with the subject line "Cybersecurity starts with you." <a href="https://meow.social/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a></p>
Davey 민선<p>Thanks to <a href="https://sfba.social/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a> I finally migrated my passwords from <a href="https://sfba.social/tags/lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpass</span></a> to <a href="https://sfba.social/tags/1password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>1password</span></a> and updated/altered most of them. Liking it so far. Especially the break down and color coding of password characters. Lastpass made me deliberately avoid using upper case i and lower case L, or letter O versus zero etc. I liked Lastpass for the longest time but now I think it's fallen off the rails.</p>
Motherboard<p>The company published new details about a disastrous breach in which hackers stole customers' vaults. It's time to switch.<br><a href="https://www.vice.com/en/article/xgye3k/lastpass-shouldnt-be-trusted-with-your-passwords" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">vice.com/en/article/xgye3k/las</span><span class="invisible">tpass-shouldnt-be-trusted-with-your-passwords</span></a><br><a href="https://federated.press/tags/CYBER" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CYBER</span></a> <a href="https://federated.press/tags/LastPassBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassBreach</span></a> <a href="https://federated.press/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a> <a href="https://federated.press/tags/worldnews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>worldnews</span></a> <a href="https://federated.press/tags/hacks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacks</span></a> <a href="https://federated.press/tags/passwordmanagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwordmanagers</span></a> <a href="https://federated.press/tags/Breach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Breach</span></a></p>
Stark<p><span class="h-card"><a href="https://mastodon.social/@Haste" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Haste</span></a></span></p><p>Will this be the end of <a href="https://techhub.social/tags/Lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Lastpass</span></a>? Is anyone still using it? I was actually one of those hardcore fans that paid when they changed the pricing-tiers, but due to it being closed source and me still seeing ads showing that I was tracked, I realised it was them so a switched to <a href="https://techhub.social/tags/BitWarden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BitWarden</span></a>. Since then, all <a href="https://techhub.social/tags/ads" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ads</span></a> are irrelevant to me.</p><p><a href="https://techhub.social/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://techhub.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://techhub.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://techhub.social/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://techhub.social/tags/hack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hack</span></a> <a href="https://techhub.social/tags/Lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Lastpass</span></a> <a href="https://techhub.social/tags/LastpassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastpassHack</span></a> <a href="https://techhub.social/tags/Bitwarden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Bitwarden</span></a> <a href="https://techhub.social/tags/PasswordManager" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManager</span></a></p>
Stark<p><span class="h-card"><a href="https://techhub.social/@Techmeme" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Techmeme</span></a></span></p><p><a href="http://www.techmeme.com/230227/p30#a230227p30" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">http://www.</span><span class="ellipsis">techmeme.com/230227/p30#a23022</span><span class="invisible">7p30</span></a></p><p>It was through their home computer and a keylogger due to a known remote code execution exploit. </p><p>Again, very weird how they knew to target this person and where. These guys were watched.</p><p><a href="https://techhub.social/tags/godaddy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>godaddy</span></a> <a href="https://techhub.social/tags/Lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Lastpass</span></a> <a href="https://techhub.social/tags/lastpasshack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpasshack</span></a> <a href="https://techhub.social/tags/Hack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hack</span></a> <a href="https://techhub.social/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://techhub.social/tags/breach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>breach</span></a></p>
Stark<p><span class="h-card"><a href="https://techhub.social/@Techmeme" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Techmeme</span></a></span></p><p><a href="https://www.bleepingcomputer.com/news/security/lastpass-devops-engineer-hacked-to-steal-password-vault-data-in-2022-breach" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/lastpass-devops-engineer-hacked-to-steal-password-vault-data-in-2022-breach</span></a></p><p>"As only four LastPass DevOps engineers had access to these decryption keys, the threat actor targeted one of the engineers. Ultimately, the hackers successfully installed a keylogger on the employee's device by exploiting a remote code execution vulnerability in a third-party media software package."</p><p>It's crazy how they knew to target these 4 individuals. I would love to know how they figured it out. Both this and the <a href="https://techhub.social/tags/GoDaddy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GoDaddy</span></a> hacks were very intricate </p><p><a href="https://techhub.social/tags/Lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Lastpass</span></a> <a href="https://techhub.social/tags/LastpassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastpassHack</span></a> <a href="https://techhub.social/tags/Hack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hack</span></a> <a href="https://techhub.social/tags/Hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hacking</span></a> <a href="https://techhub.social/tags/Breach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Breach</span></a></p>
Simon Migliano<p>After being a <a href="https://infosec.exchange/tags/LastPass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPass</span></a> user for around 10 years, I've shifted over to <a href="https://infosec.exchange/tags/1password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>1password</span></a> due to the shameful way they handled the <a href="https://infosec.exchange/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a> and it's superior product by far. Should have done this ages ago.</p>
Jeroen Herrie :verified:<p>Straks Last Pass vervangen door Bitwarden. De laatste info over LP is toch niet zo geruststellend. <a href="https://mastodon-belgium.be/tags/lastpasshack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpasshack</span></a></p>
Wowbggr<p>The Register: For password protection, dump LastPass for open source Bitwarden.<br><a href="https://www.theregister.com/2023/01/16/dump_lastpass_bitwarden/" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">theregister.com/2023/01/16/dum</span><span class="invisible">p_lastpass_bitwarden/</span></a><br><a href="https://mastodon.org.uk/tags/lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpass</span></a> <br><a href="https://mastodon.org.uk/tags/lastpasshack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpasshack</span></a> <br><a href="https://mastodon.org.uk/tags/bitwarden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bitwarden</span></a></p>
boojit<p>Been working with the <a href="https://mastodon.pundo.com/tags/LastPass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPass</span></a> tool that Steve Gibson publicized on the latest <a href="https://mastodon.pundo.com/tags/SecurityNow" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityNow</span></a> podcast (episode 905). But ran into an issue with shared folders, and covered it in this blog post. </p><p><a href="https://www.boojit.com/blog/2023-01-13.1+LastPass+vaults+and+shared+folders" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">boojit.com/blog/2023-01-13.1+L</span><span class="invisible">astPass+vaults+and+shared+folders</span></a></p><p><a href="https://mastodon.pundo.com/tags/LastPassBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassBreach</span></a> <a href="https://mastodon.pundo.com/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a></p>
BreakingBadness<p>Episode 144 of <a href="https://infosec.exchange/tags/BreakingBadness" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BreakingBadness</span></a> is now available. This week <span class="h-card"><a href="https://infosec.exchange/@ColonelPanic" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ColonelPanic</span></a></span> speaks with CISO <span class="h-card"><a href="https://infosec.exchange/@danonsecurity" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>danonsecurity</span></a></span> and <a href="https://infosec.exchange/tags/SecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecOps</span></a> Engineer <span class="h-card"><a href="https://masto.deoan.org/@neurovagrant" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>neurovagrant</span></a></span> on the <a href="https://infosec.exchange/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a>. Tune in for their thoughts and recommendations here: <a href="https://www.domaintools.com/resources/podcasts/144-lastpass-on-the-left?utm_source=Social&amp;utm_medium=Mastodon&amp;utm_campaign=Breaking-Badness" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">domaintools.com/resources/podc</span><span class="invisible">asts/144-lastpass-on-the-left?utm_source=Social&amp;utm_medium=Mastodon&amp;utm_campaign=Breaking-Badness</span></a></p>
Alan K. Martinez<p>What sucks, as a security student and advocate, I tell people that using any password manager is better than nothing... now something like this happens and a lot of us have to explain and re-assure people...</p><p>A lot of security people might be taking a hit in their credibility when things like this happen and have to deal with people who are skeptics/doubters to begin with...</p><p><a href="https://infosec.exchange/tags/lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpass</span></a> <a href="https://infosec.exchange/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a> <a href="https://infosec.exchange/tags/LastPassBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassBreach</span></a> <a href="https://infosec.exchange/tags/cybersecuritynews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecuritynews</span></a> <br><a href="https://www.youtube.com/watch?v=SoyYpq4y6XE" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">youtube.com/watch?v=SoyYpq4y6X</span><span class="invisible">E</span></a></p>
Led By Fools<p><span class="h-card"><a href="https://fediscience.org/@ct_bergstrom" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ct_bergstrom</span></a></span> <span class="h-card"><a href="https://mstdn.social/@bxchen" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>bxchen</span></a></span> The Verge covers it well: <a href="https://www.theverge.com/2022/12/28/23529547/lastpass-vault-breach-disclosure-encryption-cybersecurity-rebuttal" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">theverge.com/2022/12/28/235295</span><span class="invisible">47/lastpass-vault-breach-disclosure-encryption-cybersecurity-rebuttal</span></a></p><p><a href="https://kolektiva.social/tags/LastPass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPass</span></a> <a href="https://kolektiva.social/tags/LastPassBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassBreach</span></a> <a href="https://kolektiva.social/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a> are all good hashtags for more info/opinions by infosec experts.</p>
Erick RM<p><a href="https://youtube.com/watch?v=9XWHCF4pLmI&amp;feature=share" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">youtube.com/watch?v=9XWHCF4pLm</span><span class="invisible">I&amp;feature=share</span></a> <a href="https://mastodon.online/tags/lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpass</span></a> <a href="https://mastodon.online/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a> <a href="https://mastodon.online/tags/lastpassfail" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpassfail</span></a></p>
Led By Fools<p><span class="h-card"><a href="https://sfba.social/@Mikal" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Mikal</span></a></span> Its not so much _your_ password that counts when the DJI data vault gets hacked despite their glib assurances of "security", b/c then all you can do is reset your pwd again (and again). Assuming they detected the breach.</p><p>If you have not already done it, use <a href="https://HaveIBeenPwned.com" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="">HaveIBeenPwned.com</span><span class="invisible"></span></a> to see where your emails/phones show up in hacks.</p><p>I was reading about the <a href="https://kolektiva.social/tags/LastPass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPass</span></a> <a href="https://kolektiva.social/tags/LastPassBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassBreach</span></a> <a href="https://kolektiva.social/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a> and decided since my vault had been exposed, even tho' encrypted, that since LastPass didn;t reveal all details, they aren't to be trusted, so I switched pw managers to another popular one.</p>
War on the Castle, Peace in the Valley🛡️🍉🇵🇸 🏳️‍🌈<p>"Problems With Passphrases<br>To say it one more time: Your passphrases need to be randomly generated! (As well as your passwords, of course.) Do not generate your own “good” passphrase by just looking around in the room you are sitting in and concatenating the things you see to generate a passphrase."<br>SOURCE: <a href="https://weberblog.net/password-strengthentropy-characters-vs-words/" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">weberblog.net/password-strengt</span><span class="invisible">hentropy-characters-vs-words/</span></a></p><p><a href="https://infosec.exchange/tags/password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>password</span></a> <a href="https://infosec.exchange/tags/passphrase" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passphrase</span></a> <a href="https://infosec.exchange/tags/passwords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwords</span></a> <a href="https://infosec.exchange/tags/passwordmanager" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwordmanager</span></a> <a href="https://infosec.exchange/tags/lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpass</span></a> <a href="https://infosec.exchange/tags/LastpassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastpassHack</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
Apicultor 🐝<p><span class="h-card"><a href="https://furry.engineer/@soatok" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>soatok</span></a></span> Actually, it might be even worse than just ECB:</p><p><a href="https://twitter.com/cryptopathic/status/1606416137771782151" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">twitter.com/cryptopathic/statu</span><span class="invisible">s/1606416137771782151</span></a></p><p><a href="https://hachyderm.io/tags/lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpass</span></a> <a href="https://hachyderm.io/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a></p>
Erick RM<p><span class="h-card"><a href="https://zirk.us/@gobsmacked" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>gobsmacked</span></a></span> Thanks! will do. <a href="https://mastodon.online/tags/Lastpasshack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Lastpasshack</span></a></p>
War on the Castle, Peace in the Valley🛡️🍉🇵🇸 🏳️‍🌈<p>"Forbes is the self consciousness of the bourgeois class" - TGoTJ</p><p>Major <a href="https://infosec.exchange/tags/password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>password</span></a> manager - <a href="https://infosec.exchange/tags/HACKED" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HACKED</span></a>! I stayed up late last night changing passwords to "GFY" and then deleting their entries in lastpass. Because I migrated to <a href="https://infosec.exchange/tags/bitwarden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bitwarden</span></a> already, but did not entirely delete my <a href="https://infosec.exchange/tags/lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpass</span></a></p><p><a href="https://www.forbes.com/sites/daveywinder/2022/12/23/lastpass-password-vaults-stolen-by-hackers-change-your-master-password-now/?sh=1b68b0024461" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">forbes.com/sites/daveywinder/2</span><span class="invisible">022/12/23/lastpass-password-vaults-stolen-by-hackers-change-your-master-password-now/?sh=1b68b0024461</span></a></p><p><a href="https://infosec.exchange/tags/LastPassBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassBreach</span></a> <a href="https://infosec.exchange/tags/lastpasshack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpasshack</span></a></p>
BeardlyDavid<p><span class="h-card"><a href="https://jasette.facil.services/@simonforgues" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>simonforgues</span></a></span> </p><p>J’ai cessé d’utiliser <a href="https://social.librem.one/tags/lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lastpass</span></a> il y as déjà quelques années, a cause de certaines pratiques douteuses.<br>Je vois que j’ai bien fais! Une chance que j’ai fais détruire mon compte.<br>Ça fait peur de voir que même une compagnie qui se spécialise en sécurité peut être vulnérable à ça point.<br><a href="https://social.librem.one/tags/LastPassHack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LastPassHack</span></a> <a href="https://social.librem.one/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>