LastPass says employee’s home computer was hacked and corporate vault taken
1–10 of 12 posts
Re: LastPass says employee’s home computer was hacked and corporate vault taken
#2Re: LastPass says employee’s home computer was hacked and corporate vault taken
#3Re: LastPass says employee’s home computer was hacked and corporate vault taken
#4Wow. So those backups - which I hope and assume are encrypted with users’ credentials and were supposed to have one more layer of “LastPass” corp encryption - now seem to be lacking the latter. This sounds equivalent to stealing the encrypted blobs from each and every LP user. (Hoping to be wrong here)
If one workstation getting hacked led to something like this I wonder what other mess is hiding in the crypto details…
Re: LastPass says employee’s home computer was hacked and corporate vault taken
#5Re: LastPass says employee’s home computer was hacked and corporate vault taken
#6Re: LastPass says employee’s home computer was hacked and corporate vault taken
#7Edit: NVM, the article says it was Plex
Re: LastPass says employee’s home computer was hacked and corporate vault taken
#8Does this mean they got access to unencrypted vaults? I have had a few beers and cannot comprehend from the article or lastpass's statement.
To get unencrypted vaults, they'd need to change the client-side code. But we haven't been told that this happened.
(As a best practice, it's probably best to assume everything in LastPass vault was compromised at this point.)
Re: LastPass says employee’s home computer was hacked and corporate vault taken
#9How bad is this?