5 ms·
It's even beyond using a duplicate password which as you point out is ignorant. They were so unclear on the concept that they used a password that was written
by pwman 14y ago
It's even beyond using a duplicate password which as you point out is ignorant. They were so unclear on the concept that they used a password that was written down into their source code, and once that source code was stolen they didn't change that password!
They also failed to utilize the two different free multi-factor options LastPass offers (not to mention the premium ones).
LastPass tries to educate people and push them on not utilizing the same password anywhere with a security challenge, but that clearly didn't teach the concept here.
Their last breach involved losing access to their email: info@bitcoinica.com -- so what email did they use here with LastPass? info@bitcoinica.com They didn't utilize the security email either.
It is all unbelievable.
How do we drag this out of cargo cult security?
I see some are pushing certifications; If I made a free LastPass certification that both proves you understand the concepts, and that you're currently putting them into practice by showing that you/your company has multi-factor enabled would people demanded it?