{"id":15823,"date":"2022-12-24T23:03:44","date_gmt":"2022-12-24T23:03:44","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/lastpass-data-breach-frightens-users-some-say-hack-may-be-worse-than-they-are-letting-on-security-bitcoin-news\/"},"modified":"2022-12-24T23:03:44","modified_gmt":"2022-12-24T23:03:44","slug":"lastpass-data-breach-frightens-users-some-say-hack-may-be-worse-than-they-are-letting-on-security-bitcoin-news","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/lastpass-data-breach-frightens-users-some-say-hack-may-be-worse-than-they-are-letting-on-security-bitcoin-news\/","title":{"rendered":"Lastpass Data Breach Frightens Users, Some Say Hack \u2018May Be Worse Than They Are Letting on\u2019 \u2013 Security Bitcoin News"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div id=\"\">\n<header class=\"article__header\">\n<\/header>\n<div class=\"featured_image_container\">\n<\/div>\n<p><strong>People involved in financial tech, software programming, cyber security, and cryptocurrencies have been talking about the Lastpass data breach that was disclosed two days ago. The password management company detailed that a breach, committed earlier this year, allowed hackers to obtain a \u201cbackup of customer vault data.\u201d<\/strong><\/p>\n<h2>Lastpass Reveals \u2018Threat Actor Was Also Able to Copy a Backup of Customer Vault Data\u2019<\/h2>\n<p>On Dec. 22, 2022, the password management firm Lastpass <a href=\"https:\/\/blog.lastpass.com\/2022\/12\/notice-of-recent-security-incident\/\">disclosed<\/a> that an \u201cunknown threat actor\u201d managed to breach the firm\u2019s cloud-based storage environment in or around Aug. 2022. As soon as the news was published, the Lastpass data leak has been a <a href=\"https:\/\/twitter.com\/search?q=lastpass%20&amp;src=typed_query\">topical discussion<\/a> on social media and forums. A great number of people <a href=\"https:\/\/twitter.com\/Cryptopathic\/status\/1606416137771782151?s=20&amp;t=19SxY03tBVQ6imOzad_qog\">believe<\/a> that Lastpass\u2019 situation \u201cmay be worse than they are letting on.\u201d<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">LastPass attackers now know all websites you have passwords stored for and the blobs, encrypted only by your master password <a href=\"https:\/\/t.co\/Wdbt6mWe8C\">https:\/\/t.co\/Wdbt6mWe8C<\/a> <a href=\"https:\/\/t.co\/HldcJ8DYkK\">https:\/\/t.co\/HldcJ8DYkK<\/a><\/p>\n<p>\u2014 SwiftOnSecurity (@SwiftOnSecurity) <a href=\"https:\/\/twitter.com\/SwiftOnSecurity\/status\/1606071798667173888?ref_src=twsrc%5Etfw\">December 22, 2022<\/a><\/p>\n<\/blockquote>\n<p>\u201cBased on our investigation to date, we have learned that an unknown threat actor accessed a cloud-based storage environment leveraging information obtained from the incident we previously disclosed in August of 2022,\u201d Lastpass disclosed. The password management company added:<\/p>\n<blockquote>\n<p>The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.<\/p>\n<\/blockquote>\n<p>Lastpass insists the encrypted fields are secure with 256-bit AES encryption and the info can only be decrypted by leveraging each user\u2019s master password using the firm\u2019s <a href=\"https:\/\/www.lastpass.com\/security\/zero-knowledge-security\">zero-knowledge architecture<\/a>. \u201cAs a reminder, the master password is never known to Lastpass and is not stored or maintained by Lastpass,\u201d the company detailed.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">lastpass gets hacked and immediately after a ton of crypto wallets are broken into and drained<\/p>\n<p>\u201cbe your own bank\u201d <\/p>\n<p>nah go break into a brick &amp; mortar establishment if you want my funds nerds, good luck<\/p>\n<p>\u2014 gainzy (@gainzy222) <a href=\"https:\/\/twitter.com\/gainzy222\/status\/1606447880683880452?ref_src=twsrc%5Etfw\">December 24, 2022<\/a><\/p>\n<\/blockquote>\n<h2>Lastpass\u2019 Security Reassurance Doesn\u2019t Seem to Convince a Number of Critics<\/h2>\n<p>However, a number of <a href=\"https:\/\/www.reviewgeek.com\/140432\/the-lastpass-data-breach-just-got-even-worse-again\/\">reports<\/a> believe that the situation is worse than Lastpass is letting on. Reviewgeek.com\u2019s Andrew Heinzman stresses in his report to \u201cplease, stop using Lastpass.\u201d \u201cEven if you use a strong master password, there\u2019s a chance that hackers will try to phish some information out of you,\u201d Heinzman wrote. The author added:<\/p>\n<blockquote>\n<p>To be clear, Lastpass is still investigating this data breach. And after four months of \u2018sorry, it\u2019s worse than we thought,\u2019 customers are rightfully worried that Lastpass doesn\u2019t have all the details. For all we know, things could get even worse. We asked our readers to stop using Lastpass in July 2020.<\/p>\n<\/blockquote>\n<p>Crypto supporter Udi Wertheimer also <a href=\"https:\/\/twitter.com\/udiWertheimer\/status\/1606501962526097408?s=20&amp;t=qF0JrIiasIF3onCzjzo7FA\">warned<\/a> people that if they use Lastpass \u201cattackers probably have a copy of your vault.\u201d Wertheimer\u2019s recommendation is the same as Heinzman\u2019s as the digital currency proponent insisted that users should \u201cstop using Lastpass.\u201d<\/p>\n<p>\u201cWe don\u2019t know how bad things are,\u201d Wertheimer <a href=\"https:\/\/twitter.com\/udiWertheimer\/status\/1606501968263778304?s=20&amp;t=qF0JrIiasIF3onCzjzo7FA\">added<\/a>. \u201cIt\u2019s possible that attackers have ongoing access, so don\u2019t just change your passwords and put them back into Lastpass.\u201d Moreover, a Twitter user who claims to have worked as an engineer for the company seven years ago also noted that Lastpass\u2019 breach situation is a big deal.<\/p>\n<p>\u201cI worked at Lastpass as an engineer a long time ago. 7+ years ago. My 2 cents on the situation,\u201d the individual <a href=\"https:\/\/twitter.com\/ejcx_\/status\/1606428769731878913?s=20&amp;t=19SxY03tBVQ6imOzad_qog\">said<\/a>. \u201cThis is the worst breach Lastpass has had. By a lot. The key difference is that customer vaults were accessed this time, which are kept in a completely separate database.\u201d<\/p>\n<div class=\"article__body__tags-related__tags\">\n<h6 class=\"article__body__tags-related__title\">\nTags in this story<br \/>\n<\/h6>\n<div class=\"article__body__tags\"><a href=\"https:\/\/news.bitcoin.com\/tag\/256-bit-aes-encryption\/\">256-bit AES encryption<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/andrew-heinzman\/\">Andrew Heinzman<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/crypto\/\">Crypto<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/digital-assets\/\">Digital Assets<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/encrypted-fields\/\">encrypted fields<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/former-engineer\/\">former engineer<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/lastpass\/\">Lastpass<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/lastpass-data-breach\/\">Lastpass data breach<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/password-management-firm\/\">password management firm<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/passwords\/\">Passwords<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/reviewgeek-com\/\">Reviewgeek.com<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/secret-passwords\/\">secret passwords<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/security\/\">Security<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/seeds\/\">Seeds<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/udi-wertheimer\/\">Udi Wertheimer<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/zero-knowledge-architecture\/\">zero-knowledge architecture<\/a><\/div>\n<\/div>\n<p><em><strong>What do you think about the Lastpass data breach and the speculation that it is worse than Lastpass is letting on? Let us know what you think about this subject in the comments section below.<\/strong><\/em><\/p>\n<div class=\"article__body__author\">\n<div class=\"article__body__author__avatar\">\n<img src=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-150x150.jpg\" srcset=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-150x150.jpg 1x, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-300x300.jpg 2x\" class=\"avatar avatar-150 photo\"\/><\/div>\n<div class=\"article__body__author__info\">\n<h6 class=\"article__body__author__info__name\">\nJamie Redman <\/h6>\n<p class=\"article__body__author__info__about\">\nJamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 6,000 articles for Bitcoin.com News about the disruptive protocols emerging today.<br \/><span class=\"td-social-icon-wrap\"><br \/>\n<a target=\"_blank\" href=\"https:\/\/twitter.com\/jamieCrypto\" title=\"Twitter\" rel=\"noopener\"><br \/>\n<i class=\"td-icon-font td-icon-twitter\"\/><br \/>\n<\/a><br \/>\n<\/span>\n<\/p>\n<\/div>\n<\/div>\n<p class=\"images_credits\"><em><b>Image Credits<\/b>: Shutterstock, Pixabay, Wiki Commons<\/em><\/p>\n<div class=\"disclaimer\">\n<p><strong>Disclaimer<\/strong>: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. <a href=\"https:\/\/bitcoin.com\">Bitcoin.com<\/a> does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.<\/p>\n<\/div>\n<div class=\"bottom_article_widgets\">\n<aside id=\"bn_widget_spacing-18\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-21\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>More Popular News<\/span><\/h4>\n<\/aside>\n<aside id=\"bn_widget_spacing-19\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-46\" class=\"widget_text td_block_template_1 widget widget_custom_html\"\/>\n<aside id=\"bn_widget_spacing-20\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-30\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>In Case You Missed It<\/span><\/h4>\n<\/aside>\n<\/div>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script>(function(d, s, id) {\n        var js, fjs = d.getElementsByTagName(s)[0];\n        if (d.getElementById(id)) return;\n        js = d.createElement(s); js.id = id;\n        js.src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&version=v3.2\";\n        fjs.parentNode.insertBefore(js, fjs);\n    }(document, 'script', 'facebook-jssdk'));<\/script><br \/>\n<br \/><a href=\"https:\/\/news.bitcoin.com\/lastpass-data-breach-frightens-users-some-say-hack-may-be-worse-than-they-are-letting-on\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) People involved in financial tech, software programming, cyber security, and cryptocurrencies have been talking about the Lastpass data breach that was disclosed two days ago. The password management company detailed that a breach, committed earlier this year, allowed hackers to obtain a \u201cbackup of customer vault data.\u201d Lastpass [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":15824,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/15823"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=15823"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/15823\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/15824"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=15823"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=15823"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=15823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}