LastPass hacked. Maybe

Majic 7

Senior member
Mar 27, 2008
668
0
0
Getting notices from LastPass about problems connecting to server. Turns out they had some suspicious activity and are telling users to change their master password. Most secure passwords last. Their servers are overwhelmed at the moment, thus the errors. This is getting tiresome. I've had three notifications in the last couple of months about data bases being hacked and email accounts being compromised. I just started LastPass a few days ago because of all the things going on, now it may have been hacked.:eek:
 

Majic 7

Senior member
Mar 27, 2008
668
0
0
Thanks for posting the link. I kinda freaked and forgot the blog post from LastPass.
 
Last edited:

seepy83

Platinum Member
Nov 12, 2003
2,132
3
71
This is exactly why I typically recommend PasswordSafe or other similar products that are installed locally for password management. See this thread for the points I raised last Nov.
 

Gooberlx2

Lifer
May 4, 2001
15,381
6
91
So how compromised would the data be though? Would the masters be stored as something like a seeded SHA-512, which is used to encrypt the rest of your data? Or do they just encrypt/decrypt on the fly with the password you provide during login?

I'm curious how this kind of stuff works for sites which are known to be secure and smart about this stuff (or certainly are supposed to be), like banks, etc...

Did PSN store everything as weakly-hashed data, or (god forbid) plain text, like whatever dating site that was?
 
Last edited:

LiuKangBakinPie

Diamond Member
Jan 31, 2011
3,903
0
0
Getting notices from LastPass about problems connecting to server. Turns out they had some suspicious activity and are telling users to change their master password. Most secure passwords last. Their servers are overwhelmed at the moment, thus the errors. This is getting tiresome. I've had three notifications in the last couple of months about data bases being hacked and email accounts being compromised. I just started LastPass a few days ago because of all the things going on, now it may have been hacked.:eek:

Im not bothered they can steal my forum passwords what can they do troll around. I dont do secure business over the net.
 

LiuKangBakinPie

Diamond Member
Jan 31, 2011
3,903
0
0
So how compromised would the data be though? Would the masters be stored as something like a seeded SHA-512, which is used to encrypt the rest of your data? Or do they just encrypt/decrypt on the fly with the password you provide during login?

I'm curious how this kind of stuff works for sites which are known to be secure and smart about this stuff (or certainly are supposed to be), like banks, etc...

Did PSN store everything as weakly-hashed data, or (god forbid) plain text, like whatever dating site that was?

Using an evolved host-proof hosted solution, LastPass employs localized, government-level encryption (256-bit AES implemented in C++ and JavaScript) and local one-way salted hashes to give you complete security with the go-anywhere convenience of syncing through the cloud. All encrypting and decrypting happens on your computer - no one at LastPass can ever access your sensitive data. LastPass’ Security Challenge also allows you to identify weak account data and provides suggestions for significantly improving your online security.
http://helpdesk.lastpass.com/