CTO News Hubb
Advertisement
  • Home
  • CTO News
  • IT
  • Technology
  • Tech Topics
    • AI
    • QC
    • Robotics
    • Blockchain
  • Contact
No Result
View All Result
  • Home
  • CTO News
  • IT
  • Technology
  • Tech Topics
    • AI
    • QC
    • Robotics
    • Blockchain
  • Contact
No Result
View All Result
CTO News Hubb
No Result
View All Result
Home Technology

LastPass Data Breach: It’s Time to Ditch This Password Manager

December 28, 2022
in Technology


This means that LastPass users should go through their vaults and take extra steps to protect themselves—including changing all of their passwords. 

Start by turning on two-factor authentication for as many of your accounts as possible, particularly high-value accounts like your email, financial services, and highly used social media accounts. This way, even if attackers compromise the passwords for the accounts, they can’t actually log in without the one-time code or hardware authentication key you’ve added as the “second factor.” Next, change the passwords for all of those sensitive and high-value accounts. And then change all the remaining passwords stored in your LastPass vault.

As you’re doing all of this (or at least as much of it as you can), the time is ripe to switch to a new password manager. You can add accounts to the new service as you change them. WIRED recommends 1Password and the free service Bitwarden along with some alternatives. We haven’t recommended LastPass since the company scaled back its free offerings a couple of years ago, given that LastPass had suffered an array of past security incidents before this latest, most dire breach was even revealed.

“One hundred percent, yes, people should switch to other password managers,” says one senior security engineer, who asked not to be named because of professional relationships with people on the LastPass security team. “They failed to do the one thing they are supposed to provide—cloud-based secure credential storage.”

Security practitioners universally emphasize that the situation with LastPass shouldn’t deter people from using password managers in general. And if you’re a loyal LastPass user, you should still change your vault password, turn on two factor for every account that offers it, and change all the passwords in your vault even if you don’t migrate somewhere else in the process.

“As someone with experience handling and communicating EU data breach notifications, I’d say that LastPass’s chosen communication strategy may undermine user confidence,” says Lukasz Olejnik, an independent privacy researcher and consultant. “The big issue is also the timing. Why do it just prior to the end of year holidays when the initial investigation began months ago?”

As Jeremi Gosney, a longtime password cracker and senior principal engineer of the Yahoo security team, wrote this week in an extensive series of posts about the situation: “I used to support LastPass. I recommended it for years and defended it publicly in the media … But things change.”



Source link

Tags: hackingpasswordssecurityvulnerabilities
Previous Post

Your Next Amazon Delivery Could Be From a Drone

Next Post

The newest crop found on the farm? Solar panels.

Next Post

The newest crop found on the farm? Solar panels.

Applying DevOps to Competitive Advantage

Trending News

Who Will Blockchain Put out of Business?

December 26, 2022

The Hard Truth About Performance — A Guide for CTOs

December 31, 2022

R1/beta4 – Release Notes | Haiku Project

December 23, 2022

© 2022 CTO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Navigate Site

  • Home
  • CTO News
  • IT
  • Technology
  • AI
  • QC
  • Robotics
  • Blockchain
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • CTO News
  • IT
  • Technology
  • Tech Topics
    • AI
    • QC
    • Robotics
    • Blockchain
  • Contact

© 2021 JNews – Premium WordPress news & magazine theme by Jegtheme.

SUBSCRIBE TO OUR WEEKLY NEWSLETTERS