Re: LastPass Vault Breached via Employee's Home Computer

anonymous <[email protected]> Wed, 1 Mar 2023 21:03:08 +0100 (CET)
Newsgroups alt.computer.security,alt.privacy.anon-server
Organization dizum.com - The Internet Problem Provider
Message-ID <[email protected]>
On 28 Feb 2023, The Stuff of Legend
<Use-Author-Supplied-Address-Header@[127.1]> posted some
news:[email protected]: 

> On Tue, 28 Feb 2023 20:04:06 -0600, [email protected] said in 
> Message-ID: <[email protected]>: 
> 
>> https://pjmedia.com/news-and-politics/gregbyrnes/2023/02/28/lastpass-v
>> ault-breached-via-employees-home-computer-giving-keys-to-the-kingdom-t
>> o-hackers-n1674308 
>> 
>> "Millions of LastPass users may be at risk after a major breach of
>> the home computer of one of their top employees. This employee was
>> only one of four people in the company with access to their corporate
>> vault. The breach may have come through a home Plex media account,
>> according to Ars Technica*, and appears to have been perpetrated by
>> the same hackers who breached LastPass security on a smaller scale
>> last August. At about the same time, Plex’s security was also
>> breached."
>> 
>> *https://arstechnica.com/information-technology/2023/02/lastpass-hacke
>> rs-infected-employees-home-computer-and-stole-corporate-vault/ 
>> 
>> This is wjy I don't use password mangagers.  I keep my
>> passwords/phrases in a PGP file on my comp. 
>> Yeah, I gotta copy paste after opening the PGP, but it is safer than
>> using password "protector" dumbware like LastPass.
> 
> The problem isn't password managers, per-se -- the problem is relying
> on a cloud- based provider like LastPass. BTW, using PGP is a *great*
> idea for protecting your passwords and other confidential data,
> especially if you use symmetric encryption to do so, using a
> Diceware™ passphrase. 

Sucks when you die and your executor must settle your estate.  You just 
handed a government the majority, if not all of your hard earned assets 
because nobody could access your financials for lack of password details.  

The government doesn't care.  They will wait the seven years to gleefully 
take your money.  Of course you won't care that your family was destitute 
or even homeless because you're dead.

> Back in the day, in a moment of madness, I seriously considered using
> LastPass, but ultimately what turned me off, and made me change my
> mind, was the cloud- based nature of the service. I just don't feel
> comfortable storing /any/ data in the cloud, regardless of its'
> sensitivity. 

Oh come on.  You know India managed cloud resources are safe.  Just ask 
IBM, HPE, Dell and Kyndryl.  They will tell you so.