Showing posts with label lastpass. Show all posts
Showing posts with label lastpass. Show all posts

Friday, December 23, 2022

The last straw for LastPass

from here and here

How does a password management company make such a grave error as not protecting URLs? Knowing you have an account on a questionable website is sensitive in and of itself, without giving away the username or password, and by sensitive I mean it can get folks killed in some places.

This metadata will also be useful for phishing attacks, so if you're a LastPass user, you might see an increase in phishing emails. However, since the breach itself was months ago, the increase might have already happened.

Password managers are still good, of course, but maybe not this particular one, and maybe not online ones. Online password managers are incredibly valuable targets, while each of us individually is  generally not. An offline password manager would require someone getting through your own defenses to compromise you instead of compromising millions of users at once. 

Friday, February 26, 2021

It's just not right

from here and here (source article)

Trust is difficult to gain but easy to lose, so I have to wonder what LastPass was thinking when they stuffed their app full of trackers. Did they think no one would notice? Have they never heard the phrase "Trust But Verify"?

LastPass isn't my password manager of choice, but if it had been I'd be looking for a new one now.