Lastpass Source Code Stolen by Hackers

Consider migrating to a different password manager

Friday, August 26, 2022 by DrJBHL | Discussion: Personal Computing

Not very good news for many WCers, I'm afraid.

Luckily, Hankers saw this and had no qualms about waking me out of a sound postprandial slumber to bring this warning to you all. 

It seems that a dev working on stuff for Lastpass got hacked, and portions of Lastpass's source code got lifted in the exploit. This happened two weeks ago, but Lastpass didn't see fit to warn folks of the possible repercussions of such a theft.

"LastPass CEO Karim Toubba says the company uncovered a breach where bad actors gained access to portions of the company’s source code and proprietary technical information through a single compromised developer account. As a boilerplate response, the company started an investigation (which is still underway) and deployed mitigation measures. It also sought the services of an unnamed cybersecurity firm to prevent such events in the future.

The company says LastPass services continue to operate normally and customer data as well as encrypted password vaults remain unaffected by the breach. The company adds that users don’t need to take any remedial action at this point." - Chandraveer Matha, Android Police

Truth is, this isn't the first breech Lastpass has had. Leaked master passwords occurred in 2021...again, not their fault, they maintained.

Anyhow, the article's author concluded that you might want to change password managers.

I'll save you ducking that: https://www.pcmag.com/picks/the-best-password-managers

Have a safer weekend...and thanks, Hank.   

 

Additional sources:

https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/

 

Hankers
Reply #1 Friday, August 26, 2022 8:52 AM

Thanks Seth. Well written and informative as always. 

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01