Charlottezweb

General Conversation => Script Chat => Topic started by: Jason on June 17, 2015, 09:02:29 PM

Title: Lastpass.com hacked - Action required if you use their software :: June 2015
Post by: Jason on June 17, 2015, 09:02:29 PM
Lastpass was apparently compromised again.  If you use their software, you should change your Master Password as soon as possible.  (If you use the same password for anything else, you should change it there as well.)

http://lifehacker.com/lastpass-hacked-time-to-change-your-master-password-1711463571?utm_campaign=socialflow_lifehacker_facebook&utm_source=lifehacker_facebook&utm_medium=socialflow

Excerpt:

Quote
LastPass has announced on their company blog that they detected an intrusion to their servers. While encrypted user data (read: your stored passwords for other sites) was not stolen, the intruders did take LastPass account email addresses, password reminders, server per user salts, and authentication hashes. The latter is what's used to tell LastPass that you have permission to access your account.

According to LastPass, the authentication hashes should be sufficiently encrypted to prevent anyone from using them to access your account. However, the company is still prompting all users to update their master password that they use to log in to their LastPass account. If you use LastPass, you should do this immediately. If you share that master password with any other services, you should change it there, too. Finally, if you haven't enabled two-factor authentication you should do that immediately here.