4 ms·
Citation needed. There was a 'network traffic anomaly' a while back - but it wasn't a confirmed compromise. Not saying it wasn't.. but I think you should prov
by baconhigh 13y ago
Citation needed.
There was a 'network traffic anomaly' a while back - but it wasn't a confirmed compromise.
Not saying it wasn't.. but I think you should provide examples before blindly calling a hack.
- AhtiK 13y agoThe cause for the 'network traffic anomaly' was not identified and it was big enough to contain usernames, emails and hashed passwords (no data-blobs) [1]. I find it hard to believe that a programming or devops error could result in this kind of traffic anomaly that remained unidentified (the traffic destination IP was likely something LastPass guys did not expect, not just a lastpass-owned S3 backup bucket). The good part is that after the incident they also improved the algorithms: PBKDF2 with a user-configurable iteration count [2]. I think LastPass handled the situation perfectly, implemented the changes required. My only remaining concern is the risk of distributing tampered browser plugins in order to provide NSA the passwords whenever they ask for it. It's not that I'm paranoid of NSA being interested in me. Having tampered plugins opens up the attack vector for all hackers rendering the encryption layer useless. [1] http://blog.lastpass.com/2011/05/lastpass-security-notification.html http://blog.lastpass.com/2011/05/lastpass-security-notificat... [2] https://helpdesk.lastpass.com/security-options/password-iterations-pbkdf2/ https://helpdesk.lastpass.com/security-options/password-iter...