The Lastpass hack was worse than the company first reported

TL;DR

After being hacked for the second time in as many years this August, password manager app Lastpass announced on Thursday the most recent intrusion was much more damaging than initially reported with the attackers having made off with users' password vaults in some cases.However, some of the app's source code was lifted and then used to spearphish a Lastpass employee into giving up their access credentials, then used those keys to decrypt and copy off, "some storage volumes within the cloud-based storage service.""These encrypted fields remain secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user’s master password using our Zero Knowledge architecture," Toubba said.It'll be a pain but swapping out all of your various existing site passwords for new ones — as well as picking a new master password — might ultimately prove necessary to regain your online security.Or you could just tell Lastpass to go kick rocks and switch over to 1Password or Bitwarden."

Like summarized versions? Support us on Patreon!