Apologies for the res, but has anyone else's LastPass recently started displaying every single saved sight when clicking on the star to select your log on.
Apologies for the res, but has anyone else's LastPass recently started displaying every single saved sight when clicking on the star to select your log on.
Well then I dunno if something has updated to have caused this. Another colleague has the same issue, granted we both use Chrome and LastPass, so yarrr.
meh. clickbait from MyBB. Actual facts are less dramatic
https://blog.lastpass.com/2015/06/lastpass-security-notice.html/
Was my master password exposed?
No, LastPass never has access to your master password. We use encryption and hashing algorithms of the highest standard to protect user data. We hash both the username and master password on the user’s computer with 5,000 rounds of PBKDF2-SHA256, a password strengthening algorithm. That creates a key, on which we perform another round of hashing, to generate the master password authentication hash. That is sent to the LastPass server so that we can perform an authentication check as the user is logging in. We then take that value, and use a salt (a random string per user) and do another 100,000 rounds of hashing, and compare that to what is in our database. In layman’s terms: Cracking our algorithms is extremely difficult, even for the strongest of computers.
We are confident that our encryption measures are sufficient to protect the vast majority of users. LastPass strengthens the authentication hash with a random salt and 100,000 rounds of server-side PBKDF2-SHA256, in addition to the rounds performed client-side. This additional strengthening makes it difficult to attack the stolen hashes with any significant speed.
Yeah. When I logged in for the first time after the "hack", they just asked me to confirm my account by following a link in a verification email. No password changes were required.
Using LastPass is still one of the best decisions I ever made![]()
Slight thread necro, but you guys might wanna read this:LastPass vulnerable to simple phishing attack
I am way too paranoid to ever use this, I get how easy it makes things for people, but its not for me.
Always use 2 step authentication if it's available!
Here's Everywhere You Should Enable Two-Factor Authentication Right Now
List is quite old. There should be a lot more sites that now support 2 step authentication.Thanks for sharing.
Always use 2 step authentication if it's available!
Here's Everywhere You Should Enable Two-Factor Authentication Right Now