LastPass Password Manager Acknowledges Breach

Advertisement
By Nicole Perlroth, The New York Times | Updated: 16 June 2015 09:23 IST
LastPass Password Manager Acknowledges Breach
LastPass, the online password manager, announced Monday in a blog post that its network was breached and that hackers made off with user email addresses, password reminders and encrypted master passwords.

Within the security community, password managers have long been controversial. Some say online password managers help everyday users become more secure than they would otherwise, because it makes it easier to set up complex different passwords for different accounts without having to remember them all. Others have been wary of password managers like LastPass because if the password manager gets breached, hackers can potentially unlock all the accounts managed through the service.

Joe Siegrist, the LastPass chief executive, said the company discovered the breach on Friday after detecting suspicious activity on its network. The company said that it found no evidence that LastPass user accounts were compromised, or that hackers were able to get users' master passwords, or passwords encrypted with that user password.

But the data hackers did access - including email addresses and password reminders - is still troubling, security experts note, in that often all hackers need to unlock an email account is an email as a username plus a password reminder.

Advertisement

Tod Beardsley, a security engineering manager at Rapid7, said that the attack gave hackers a list of LastPass user email addresses that they could target in so-called phishing attacks, in which they send victims emails with links that try to trick users into revealing more data, like a fake "Update your LastPass master password" email, that can be used to crack their accounts.

Advertisement

LastPass said it would be resetting users' master passwords, and advised users to turn on multifactor authentication, an added security measure which requires a second one-time password, often sent to users via text message, anytime they log in to their accounts from an unrecognized machine.

The company said it was confident that its encryption measures would be enough to protect the vast majority of its users. LastPass strengthens the keys needed to unlock master passwords by forcing them to go through a large number of complicated iterations. The company appends random digits to the key, then encrypts it more than 100,000 times, which makes it difficult to break stolen hashes with password cracking tools.

Advertisement

The attack was the second breach notification from LastPass. The first incident happened four years ago. The latest attempt to access the company's passwords was discovered on Friday, but a picture posted to Imgur, the image sharing site, of a Google security warning suggests that hackers may have found a way inside the service as long as three weeks ago.

© 2015 New York Times News Service

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Tecno Spark Go 5G Launched in India With 6,000mAh Battery: See Price
  2. Vijay Sales Freedom Sale Brings Discounts on iPhone 16 Pro Max and More
  3. Qubo Dashcam Pro 3K Review: A Solid Choice for Your Car
  4. Best Mobile Phones Under Rs. 25,000 in India
  5. This Is When Apple Can Announce September Event
  6. iQOO 15 Launch Timeline, Specifications Leaked Online
  7. iPhone 17 Air in Sky Blue Colourway Appears in a Video Online
  8. Vivo T4 Pro India Launch Teased; Flipkart Availability Confirmed
  9. Google Photos' Remix Feature Can Turn Your Photos Into Artistic Styles
  10. Independence Day 2025: FASTag Annual Pass Price Breakdown
  1. Russia Imposes Partial Restrictions on WhatsApp, Telegram Voice Calls
  2. HTC Vive Eagle AI Smart Glasses Launched With Snapdragon AR1 Gen 1 SoC, AI Assistant: Price, Specifications
  3. Tecno Spark Go 5G Launched in India With 6,000mAh Battery, 50-Megapixel Main Camera: Price, Specifications
  4. Nothing Phone 3a Pro, Phone 3a, CMF Phone 2 Pro, More Discounted in Nothing's Independence Day Sale
  5. PS Plus Game Catalog Adds Mortal Kombat 1, Marvel's Spider-Man and Sword of the Sea in August
  6. Amazon's Next Color Kindle Leaked Hinting "Petit Color" Could Be a Cheaper Alternative
  7. iPhone 17 Series Launch Countdown Begins: This Is When Apple Can Announce September Event
  8. Samsung’s Display-Less AI Smartglasses are Reportedly Delayed to Next Year
  9. Vivo T4 Pro Teased to Launch in India Soon; to Be Available on Flipkart
  10. Vijay Sales Mega Freedom Sale: Deals on iPhone 16 Pro Max, iPhone 15, Samsung Galaxy S25 Ultra, and More
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.