6 ms·
Norton LifeLock says thousands of customer accounts breached
- kylehotchkiss 4y agoBummer, this is one of the nicer identity theft monitoring programs. Have you ever tried the one that TurboTax offers? It’s garbage
- listenallyall 4y agoWhat does LifeLock actually do? They collect subscription money, sure, but then what do they actually do to prevent customer identity theft? My guess is, not much.
- Eleison23 4y ago[dead]
- mesozoic 4y agoThey had one job.
- djha-skin 4y agoFirst LastPass and now this. Is any customer data secure online if security companies can't take care of it?
- acdha 4y agoLifeLock was always a scam, not a security company, and they had a history of security problems. Norton acquired them but as a subsidiary I’d expect less chulture change, especially given Norton’s own history here.
- djha-skin 4y agoOkay upon actually reading the article this is way trumped up. Accounts were breached by using credential stuffing which means using a password that was in some password breach and seeing if the users had reused their password. LifeLock wasn't hacked at all. They're just being an overly cautious company about publishing to users whether or not those users might have been compromised. Some users were compromised but this was due to password reuse.
- acdha 4y agoIt sounds they’re not using a service like HIBP to monitor compromised passwords and that they don’t have good controls for logins from unusual locations, both of which are table stakes for a service like this. The note about MFA being optional as well is concerning since that’s similarly a sign that they’re years behind even the banking industry, as an ostensible security vendor selling a password manager. The most concerning part is that they “cannot rule out that the intruders also accessed customers’ saved passwords” — since the attacker didn’t breach their application, this suggests that they don’t have adequate logging. Every access to a saved password should be logged.