{"id":9376,"date":"2022-12-25T16:58:30","date_gmt":"2022-12-25T16:58:30","guid":{"rendered":"http:\/\/cryptoheretostay.com\/?p=9376"},"modified":"2022-12-25T16:58:31","modified_gmt":"2022-12-25T16:58:31","slug":"lastpass-data-breach-frightens-users-some-say-hack-may-be-worse-than-they-are-letting-on","status":"publish","type":"post","link":"https:\/\/cryptoheretostay.com\/?p=9376","title":{"rendered":"Lastpass Data Breach Frightens Users, Some Say Hack \u2018May Be Worse Than They Are Letting on\u2019"},"content":{"rendered":"<p> <script type=\"text\/javascript\">\r\namzn_assoc_placement = \"adunit0\";\r\namzn_assoc_tracking_id = \"totafreearti-20\";\r\namzn_assoc_ad_mode = \"search\";\r\namzn_assoc_ad_type = \"smart\";\r\namzn_assoc_marketplace = \"amazon\";\r\namzn_assoc_region = \"US\";\r\namzn_assoc_default_search_phrase = \"crypto\";\r\namzn_assoc_default_category = \"All\";\r\namzn_assoc_search_bar = \"false\";\r\namzn_assoc_title = \"\";\r\namzn_assoc_rows =\"1\";\r\n<\/script>\r\n<script src=\"\/\/z-na.amazon-adsystem.com\/widgets\/onejs?MarketPlace=US\"><\/script><br \/>\n<\/p>\n<p><strong>People involved in financial tech, software programming, cyber security, and cryptocurrencies have been talking about the Lastpass data breach that was disclosed two days ago. The password management company detailed that a breach, committed earlier this year, allowed hackers to obtain a \u201cbackup of customer vault data.\u201d<\/strong><\/p>\n<h2>Lastpass Reveals \u2018Threat Actor Was Also Able to Copy a Backup of Customer Vault Data\u2019<\/h2>\n<p>On Dec. 22, 2022, the password management firm Lastpass disclosed that an \u201cunknown threat actor\u201d managed to breach the firm\u2019s cloud-based storage environment in or around Aug. 2022. As soon as the news was published, the Lastpass data leak has been a topical discussion on social media and forums. A great number of people believe that Lastpass\u2019 situation \u201cmay be worse than they are letting on.\u201d<\/p>\n<p lang=\"en\" dir=\"ltr\">LastPass attackers now know all websites you have passwords stored for and the blobs, encrypted only by your master password https:\/\/t.co\/Wdbt6mWe8C https:\/\/t.co\/HldcJ8DYkK<\/p>\n<p>\u2014 SwiftOnSecurity (@SwiftOnSecurity) December 22, 2022<\/p>\n<p>\u201cBased on our investigation to date, we have learned that an unknown threat actor accessed a cloud-based storage environment leveraging information obtained from the incident we previously disclosed in August of 2022,\u201d Lastpass disclosed. The password management company added:<\/p>\n<p>The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.<\/p>\n<p>Lastpass insists the encrypted fields are secure with 256-bit AES encryption and the info can only be decrypted by leveraging each user\u2019s master password using the firm\u2019s zero-knowledge architecture. \u201cAs a reminder, the master password is never known to Lastpass and is not stored or maintained by Lastpass,\u201d the company detailed.<\/p>\n<p lang=\"en\" dir=\"ltr\">lastpass gets hacked and immediately after a ton of crypto wallets are broken into and drained<\/p>\n<p>\u201cbe your own bank\u201d <\/p>\n<p>nah go break into a brick &amp; mortar establishment if you want my funds nerds, good luck<\/p>\n<p>\u2014 gainzy (@gainzy222) December 24, 2022<\/p>\n<h2>Lastpass\u2019 Security Reassurance Doesn\u2019t Seem to Convince a Number of Critics<\/h2>\n<p>However, a number of reports believe that the situation is worse than Lastpass is letting on. Reviewgeek.com\u2019s Andrew Heinzman stresses in his report to \u201cplease, stop using Lastpass.\u201d \u201cEven if you use a strong master password, there\u2019s a chance that hackers will try to phish some information out of you,\u201d Heinzman wrote. The author added:<\/p>\n<p>To be clear, Lastpass is still investigating this data breach. And after four months of \u2018sorry, it\u2019s worse than we thought,\u2019 customers are rightfully worried that Lastpass doesn\u2019t have all the details. For all we know, things could get even worse. We asked our readers to stop using Lastpass in July 2020.<\/p>\n<p>Crypto supporter Udi Wertheimer also warned people that if they use Lastpass \u201cattackers probably have a copy of your vault.\u201d Wertheimer\u2019s recommendation is the same as Heinzman\u2019s as the digital currency proponent insisted that users should \u201cstop using Lastpass.\u201d<\/p>\n<p>\u201cWe don\u2019t know how bad things are,\u201d Wertheimer added. \u201cIt\u2019s possible that attackers have ongoing access, so don\u2019t just change your passwords and put them back into Lastpass.\u201d Moreover, a Twitter user who claims to have worked as an engineer for the company seven years ago also noted that Lastpass\u2019 breach situation is a big deal.<\/p>\n<p>\u201cI worked at Lastpass as an engineer a long time ago. 7+ years ago. My 2 cents on the situation,\u201d the individual said. \u201cThis is the worst breach Lastpass has had. By a lot. The key difference is that customer vaults were accessed this time, which are kept in a completely separate database.\u201d<\/p>\n<p>Tags in this story<\/p>\n<p>256-bit AES encryption, Andrew Heinzman, Crypto, Digital Assets, encrypted fields, former engineer, Lastpass, Lastpass data breach, password management firm, Passwords, Reviewgeek.com, secret passwords, Security, Seeds, Udi Wertheimer, zero-knowledge architecture<\/p>\n<p><em><strong>What do you think about the Lastpass data breach and the speculation that it is worse than Lastpass is letting on? Let us know what you think about this subject in the comments section below.<\/strong><\/em><\/p>\n<p>Jamie Redman <\/p>\n<p class=\"article__body__author__info__about\">\nJamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 6,000 articles for Bitcoin.com News about the disruptive protocols emerging today.<\/p>\n<p><i class=\"td-icon-font td-icon-twitter\"\/><\/p>\n<p class=\"images_credits\"><em>Image Credits: Shutterstock, Pixabay, Wiki Commons<\/em><\/p>\n<p><strong>Disclaimer<\/strong>: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.<\/p>\n<p>More Popular NewsIn Case You Missed It<\/p>\n<p><script type=\"text\/javascript\">\r\namzn_assoc_placement = \"adunit0\";\r\namzn_assoc_tracking_id = \"totafreearti-20\";\r\namzn_assoc_ad_mode = \"search\";\r\namzn_assoc_ad_type = \"smart\";\r\namzn_assoc_marketplace = \"amazon\";\r\namzn_assoc_region = \"US\";\r\namzn_assoc_default_search_phrase = \"bitcoin\";\r\namzn_assoc_default_category = \"All\";\r\namzn_assoc_search_bar = \"false\";\r\namzn_assoc_title = \"\";\r\namzn_assoc_rows =\"1\";\r\n<\/script>\r\n<script src=\"\/\/z-na.amazon-adsystem.com\/widgets\/onejs?MarketPlace=US\"><\/script><br \/>\n<br \/><a href=\"https:\/\/news.bitcoin.com\/lastpass-data-breach-frightens-users-some-say-hack-may-be-worse-than-they-are-letting-on\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>People involved in financial tech, software programming, cyber security, and cryptocurrencies have been talking about the Lastpass data breach that was disclosed two days ago. The password management company detailed that a breach, committed earlier this year, allowed hackers to obtain a \u201cbackup of customer vault data.\u201d Lastpass Reveals \u2018Threat Actor Was Also Able to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9377,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wp_rev_ctl_limit":""},"categories":[1],"tags":[],"class_list":["post-9376","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto-updates"],"_links":{"self":[{"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=\/wp\/v2\/posts\/9376","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9376"}],"version-history":[{"count":1,"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=\/wp\/v2\/posts\/9376\/revisions"}],"predecessor-version":[{"id":9378,"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=\/wp\/v2\/posts\/9376\/revisions\/9378"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=\/wp\/v2\/media\/9377"}],"wp:attachment":[{"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9376"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9376"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoheretostay.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9376"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}