4 ms·
Seems like a lot of their talk of zero knowledge was bs. >In December, we notified a subset of customers whose SCIM, Enterprise API, and SAML keys were stored
by replaceusb 4y ago
Seems like a lot of their talk of zero knowledge was bs.
>In December, we notified a subset of customers whose SCIM, Enterprise API, and SAML keys were stored in unencrypted form. This only affected customers who joined LastPass and used these services in 2019 or before.
This part just blew my mind.
>Important: Since resetting MFA shared secrets destroys all LastPass sessions and trusted devices for these users, these users will need to log back in, go through location verification, and re-enable their respective MFA apps to continue using the service.
I feel sorry for everyones internal helpdesk. This is going to be brutal.