• @hperrin
    link
    English
    5010 months ago

    It was LastPass, but the passwords themselves weren’t leaked. All of these encrypt the password.

    • @Passerby6497
      link
      English
      2210 months ago

      the passwords themselves weren’t leaked

      You’re not wrong, but you kinda are. The plaintext passwords weren’t released, but the encrypted blobs were stolen. Unfortunately, the LastPass defaults were absolutely shit so people have been able to selectively attack the blobs and decrypt the vaults, leading to millions in crypto being stolen.

      I was a long time supporter of LastPass, but they haven’t been responsible stewards of sensitive information. The fact that they failed to encourage or force existing customers to update the encryption settings as they updated their defaults is negligent and is disqualifying in my opinion.

    • @Z4rK
      link
      English
      1910 months ago

      There is no excuse for LastPass and it absolutely should not be treated with your passwords or secrets.

      • @shaggy959500
        link
        English
        410 months ago

        Security Now is amazing. For anyone that wants the deep dive tech perspective, plus what it means for everyday people and users, this is a great option.

    • @Tangent5280
      link
      English
      410 months ago

      Ah, alright, thanks. Thats a good thing then, that you cant get to the passwords even if you hack the company.