• Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Flyy Tech
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs
  • Camera
  • Audio
No Result
View All Result
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs
  • Camera
  • Audio
No Result
View All Result
Flyy Tech
No Result
View All Result

LastPass admits to customer data breach caused by previous breach – Naked Security

flyytech by flyytech
December 2, 2022
Home Security
Share on FacebookShare on Twitter


Back in August 2022, popular password manager company LastPass admitted to a data breach.

The company, which is owned by sofware-as-a-service business GoTo, which used to be LogMeIn, published a very brief but nevertheless useful report about that incident about a month later:

Briefly put, LastPass concluded that the attackers managed to implant malware on a developer’s computer.

With a beachhead on that computer, it seems that the attackers were then able to wait until the developer had gone through LastPass’s authentication process, including presenting any necessary multi-factor authentication credentials, and then “tailgate” them into the company’s development systems.

LastPass insisted that the developer’s account hadn’t given the criminals access to any customer data, or indeed to anyone’s encrypted password vaults.

The company did admit, however, that the crooks had made off with LastPass proprietary information, notably including “some of our source code and technical information”, and that the crooks were in the network for four days before they were spotted and kicked out.

According to LastPass, customer passwords backed up on the company’s servers never exist in decrypted form in the cloud. The master password used to unscramble your saved passwords is only ever requested and used in memory on your own devices. Therefore, any passwords stored into the cloud are encrypted before they’re uploaded, and only decrypted again after they’ve been downloaded. In other words, even if password vault data had been stolen, it would have been unintelligible anyway.

Latest developments

Right at the end of November 2022, however, LastPass further admitted that there was a bit more to the story than perhaps they’d hoped.

According to a security bulletin dated 2022-11-30, the company was recently breached again by attackers “using information obtained in the August 2022 incident”, and this time customer data was stolen.

In other words, even if the criminals weren’t able to dig around in customer records directly from the account of the developer who got infected by malware back in August, it seems that the crooks nevertheless made off with internal details that indirectly gave them, or someone to whom they sold on the data, access to customer information later on.

Unfortunately, LastPass isn’t yet giving out any information about what sort of customer data was stolen, reporting simply that it is “working diligently to understand the scope of the incident and identify what specific information has been accessed”.

All that LastPass can say for sure right now [2022-12-01-T23:30Z] is to reiterate that “[o]ur customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture.”

(Zero knowledge is a jargon term that reflects the fact that although LastPass holds some sort of data in its customers’ password vaults, it has no knowledge of what that data actually refers to, or even if it actually consists of account names and passwords at all.)

In short, even if it ultimately turns out that the crooks could have made off with personal information such as home addresses, phone numbers and payment card details (though we hope that’s not the case, of course), your passwords are still as safe as the master password you originally chose for yourself, which LastPass’s cloud services never ask for, let alone keep copies of.

What to do?

  • If you’re a LastPass customer, we suggest you keep your eye on the company’s security incident report for updates.
  • If you’re a cybersecurity defender, why not listen to expert advice from Sophos cybersecurity researcher Chester Wisniewski on how to protect your own IT estate from this sort of get-a-beachhead-and-go-forth-from-there attack?

In the podcast below (there’s a full transcript if you prefer reading to listening), Chester discusses a similar sort of breach that happened in September 2022 at ride-hailing business Uber, and reminds you why “divide and conquer”, also known by the jargon term zero trust, is an important part of contemporary cyberdefence.

As Chester explains, even though all breaches cause some harm, either to your reputation or to your bottom line, the outcome will inevitably be a lot worse if crooks who get access to some of your network can roam around wherever they like until they get access to all of it.

Click-and-drag on the soundwaves below to skip to any point. You can also listen directly on Soundcloud.




Source_link

flyytech

flyytech

Next Post
U.S. Supreme Court Will Take Up Biden’s Debt-Cancellation Plan

U.S. Supreme Court Will Take Up Biden’s Debt-Cancellation Plan

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Europol and Bitdefender Release Free Decryptor for LockerGoga Ransomware

Europol and Bitdefender Release Free Decryptor for LockerGoga Ransomware

September 19, 2022
‘River City Girls 2’, ‘Cosmo Dreamer’, Plus Today’s Other New Releases and Sales – TouchArcade

‘River City Girls 2’, ‘Cosmo Dreamer’, Plus Today’s Other New Releases and Sales – TouchArcade

December 16, 2022

Trending.

Review: Zoom ZPC-1

Review: Zoom ZPC-1

January 28, 2023
Image Creator now live in select countries for Microsoft Bing and coming soon in Microsoft Edge

Image Creator now live in select countries for Microsoft Bing and coming soon in Microsoft Edge

October 23, 2022
Elden Ring best spells 1.08: Tier lists, sorceries, incantations, and locations

Elden Ring best spells 1.08: Tier lists, sorceries, incantations, and locations

January 14, 2023
Allen Parr’s false teaching examined. Why you should unfollow him.

Allen Parr’s false teaching examined. Why you should unfollow him.

September 24, 2022
How to View Ring Doorbell on a Roku TV

How to View Ring Doorbell on a Roku TV

December 20, 2022

Flyy Tech

Welcome to Flyy Tech The goal of Flyy Tech is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

Follow Us

Categories

  • Apple
  • Applications
  • Audio
  • Camera
  • Computers
  • Cooking
  • Entertainment
  • Fitness
  • Gaming
  • Laptop
  • lifestyle
  • Literature
  • Microsoft
  • Music
  • Podcasts
  • Review
  • Security
  • Smartphone
  • Travel
  • Uncategorized
  • Vlogs

Site Links

  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Recent News

CP+ 2023: Canon interview – ‘It’s our mission to make any camera system easier operate’: Digital Photography Review

CP+ 2023: Canon interview – ‘It’s our mission to make any camera system easier operate’: Digital Photography Review

March 26, 2023
Apple’s 2022 10th generation iPad is now available for just $399

Apple’s 2022 10th generation iPad is now available for just $399

March 26, 2023

Copyright © 2022 Flyytech.com | All Rights Reserved.

No Result
View All Result
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs

Copyright © 2022 Flyytech.com | All Rights Reserved.

What Are Cookies
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT