Go Back   IceInSpace > General Astronomy > General Chat
Register FAQ Calendar Today's Posts Search

Reply
 
Thread Tools Rate Thread
  #1  
Old 23-12-2022, 10:28 PM
DarkArts
Registered User

DarkArts is offline
 
Join Date: Dec 2014
Posts: 673
LastPass has been hacked

Another day, another hack ...

The hacker stole a large amount of personal information including (encrypted) hashes of passwords. Brute forcing the hashes will be very resource intensive, especially if LastPass's implememtation was good, but it's not impossible.

So, if you were using LastPass as a password manager, it would be a good time to change your passwords:

Quote:
Originally Posted by ArsTechnica
LastPass customers should ensure they have changed their master password and all passwords stored in their vault. They should also make sure they're using settings that exceed the LastPass default.
Reply With Quote
  #2  
Old 24-12-2022, 10:01 AM
AstroViking's Avatar
AstroViking (Steve)
Registered User

AstroViking is offline
 
Join Date: Mar 2022
Location: Melbourne
Posts: 1,243
Rather than changing all your passwords, how about simply changing your LastPass 'Master Password'? That will re-encrypt your vault - so even if the bad guys do manage to find your old master password, it won't do them any good.

Or migrate to a new password manager. I moved from LP to BitWarden when LP killed multi-device support in their free offering.

Having said that, I am reminded of a very old saying: "If builders built buildings the way programmers write software, the first strong breeze would destroy civilisation."
Reply With Quote
  #3  
Old 24-12-2022, 01:59 PM
DarkArts
Registered User

DarkArts is offline
 
Join Date: Dec 2014
Posts: 673
Quote:
Originally Posted by AstroViking View Post
Rather than changing all your passwords, how about simply changing your LastPass 'Master Password'?
Because the hackers have the hashes of all the passwords.
Reply With Quote
  #4  
Old 24-12-2022, 03:11 PM
iborg's Avatar
iborg (Philip)
Registered User

iborg is offline
 
Join Date: Feb 2015
Location: Lynbrook, Australia
Posts: 682
Hi All


For some some people, using a password manager in a double mode mode is something to consider.


Have a look at the link here if you are interested.


Philip
Reply With Quote
  #5  
Old 24-12-2022, 03:31 PM
AstroViking's Avatar
AstroViking (Steve)
Registered User

AstroViking is offline
 
Join Date: Mar 2022
Location: Melbourne
Posts: 1,243
Hmmm. I read the article as saying the bad guys got the hashes of the master passwords for every user's password vaults. Hence my previous post.

IF the bad guys got the contents of everyone's vaults as well, then yeah, it's a world of pain.

Quote:
Originally Posted by DarkArts View Post
Because the hackers have the hashes of all the passwords.
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time is now 03:27 PM.

Powered by vBulletin Version 3.8.7 | Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Advertisement
Bintel
Advertisement