Password Manager LastPass Hacked
LastPass says user account email addresses, password reminders, server per user salts, and authentication hashes compromised.
The ongoing password migraine continues: popular cloud-based password management service LastPass yesterday said it had suffered a data breach, exposing user account email addresses, password reminders, server per use salts, and authenication hashes. The company said it has "no evidence" that encrypted user vault data was stolen, however.
"We are confident that our encryption measures are sufficient to protect the vast majority of users. LastPass strengthens the authentication hash with a random salt and 100,000 rounds of server-side PBKDF2-SHA256, in addition to the rounds performed client-side. This additional strengthening makes it difficult to attack the stolen hashes with any significant speed," LastPass said in a post on its website.
Customers of the service who are not using multifactor authentication for LastPass must now verify their accounts via email when logging in from a new device or IP address. LastPass also will alert users to update their master password.
"You do not need to update your master password until you see our prompt. However, if you have reused your master password on any other website, you should replace the passwords on those other websites," LastPass said. "Because encrypted user data was not taken, you do not need to change your passwords on sites stored in your LastPass vault."
Read more about the breach here.
About the Author(s)
You May Also Like
Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024Where and Why Threat Intelligence Makes Sense for Your Enterprise Security Strategy
May 15, 2024Safeguarding Political Campaigns: Defending Against Mass Phishing Attacks
May 16, 2024Why Effective Asset Management is Critical to Enterprise Cybersecurity
May 21, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024