3 ms·
Pretty much, limiting mfa options to otp only. Then the attacker getting access to customer shared secrets means they basically just have to guess the master pa
by replaceusb 4y ago
Pretty much, limiting mfa options to otp only. Then the attacker getting access to customer shared secrets means they basically just have to guess the master password.
>Backup of LastPass MFA/Federation Database – contained copies of LastPass
Authenticator seeds, telephone numbers used for the MFA backup option (if enabled), as
well as a split knowledge component (the K2 “key”) used for LastPass federation (if
enabled). This database was encrypted, but the separately-stored decryption key was
included in the secrets stolen by the threat actor during the second incident.
Unless I am misunderstanding this, they mention to business users the need to reset shared secrets from OTP providers.
>For users of Duo Security, Symantec VIP, RSA SecurID, or SecureAuth, regenerate the shared secret for each respective MFA solution and paste the new shared secret into the respective MFA app configuration in the Admin Console.