Another LastPass security incident

TL;DR

Notice of Recent Security Incident Update as of Wednesday, November 30, 2022 To All LastPass Customers, In keeping with our commitment to transparency, I wanted to inform you of a security incident that our team is currently investigating.Karim Toubba LastPass CEO Update as of Thursday, September 15, 2022 To All LastPass Customers, On August 25th, 2022, we notified you about a security incident that was limited to the LastPass Development environment in which some of our source code and technical information was taken.Thirdly, LastPass does not have any access to the master passwords of our customers’ vaults – without the master password, it is not possible for anyone other than the owner of a vault to decrypt vault data as part of our Zero Knowledge security model.As part of our risk management program, we have also partnered with a leading cyber security firm to further enhance our existing source code safety practices which includes secure software development life cycle processes, threat modeling, vulnerability management and bug bounty programs.Karim Toubba CEO LastPass Original post from August 25, 2022 To All LastPass Customers, I want to inform you of a development that we feel is important for us to share with our LastPass business and consumer community."

Like summarized versions? Support us on Patreon!