Re: LastPass Vault Breached via Employee's Home Computer
The Stuff of Legend <Use-Author-Supplied-Address-Header@[127.1]> Wed, 1 Mar 2023 06:21:02 +0000 (GMT)
| Newsgroups | alt.privacy.anon-server,alt.computer.security |
|---|---|
| Organization | dizum.com - The Internet Problem Provider |
| Message-ID | <[email protected]> |
On Tue, 28 Feb 2023 20:04:06 -0600, [email protected] said in Message-ID: <[email protected]>: > https://pjmedia.com/news-and-politics/gregbyrnes/2023/02/28/lastpass-vault-breached-via-employees-home-computer-giving-keys-to-the-kingdom-to-hackers-n1674308 > > "Millions of LastPass users may be at risk after a major breach of the > home computer of one of their top employees. This employee was only > one of four people in the company with access to their corporate > vault. The breach may have come through a home Plex media account, > according to Ars Technica*, and appears to have been perpetrated by > the same hackers who breached LastPass security on a smaller scale > last August. At about the same time, Plex’s security was also > breached." > > *https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/ > > This is wjy I don't use password mangagers. I keep my > passwords/phrases in a PGP file on my comp. > Yeah, I gotta copy paste after opening the PGP, but it is safer than > using password "protector" dumbware like LastPass. The problem isn't password managers, per-se -- the problem is relying on a cloud- based provider like LastPass. BTW, using PGP is a *great* idea for protecting your passwords and other confidential data, especially if you use symmetric encryption to do so, using a Diceware™ passphrase. Back in the day, in a moment of madness, I seriously considered using LastPass, but ultimately what turned me off, and made me change my mind, was the cloud- based nature of the service. I just don't feel comfortable storing /any/ data in the cloud, regardless of its' sensitivity.