3 ms·
Yes. But prior to this breach it was easy to look the other way due to the extremely large amount of inertia associated with changing a manager and all your pas
by weakfortress 4y ago
Yes. But prior to this breach it was easy to look the other way due to the extremely large amount of inertia associated with changing a manager and all your passwords. I know this was the case for me. In August we thought it was simply another "simple" breach. E.g. they got hold of some information that would be useful to spearphish or whatever but not the vaults themselves. No big deal, just be on the lookout for emails.
Once it came to light they lost control of their vaults the calculus changed. In my memory this is the largest, most prolific breach in history. Every other breach of a major site pales in comparison. The only solution is to change password managers immediately (I went to 1password) and begin the process of changing everything and updating your security posture. Unfortunately, the hackers also have an insane amount of metadata on customers. So if you stored incriminating (either legally or socially) websites in there the hackers now have a lot of leverage to get you to bend the knee.
In summary, lastpass has been on the down slope for a long time. But it was easy to just accept this and work around it. This breach changed everything. It revealed their incompetence in full and woke a lot of people, including myself, up to just how hard it is to trust a company. It's just not enough anymore to have a big company slapped onto your logo (LogMeIn) and hope they provide the correct mitigations through experience. From now on I, and many people I know, will be carefully evaluating their choices with password managers, etc from now on. I don't think their CEO can be trusted especially with all the weasel words used in the disclosure and the timing of the disclosure. They showed no respect for their customers in either the aspect of security or disclosure. If you know nothing else about this breach that should be enough to get you and everyone you know to run.
- geocrasher 4y agoI think it's a lesser breach than the 2011 RSA hack. That doesn't make it insignificant, however. https://www.wired.com/story/the-full-story-of-the-stunning-rsa-hack-can-finally-be-told/ https://www.wired.com/story/the-full-story-of-the-stunning-r...