And how did LastPass fuck this up anyway?
And how did LastPass fuck this up anyway?
However, that does mean they can attempt to “brute force” the encryption, trying any number of passwords as often as they like - and it seems some earlier versions of LastPass used rather poor choices with that cryptography, meaning the amount of effort needed to make an attempt is lower than other similar services (plus some users may have rather poor master passwords, making them easier to guess).
Consider that many users may have had very guessable vault passwords, and encryption generally gets weaker as hardware and techniques advance.
I'm not saying for a moment that Lastpass are competent (there's plenty of evidence to the contrary), but... saying that this isn't complicated seems a bit much. This is an extremely complex set of transactions where many many things can be done incorrectly.
There's also of course the general as-yet-not-conclusively-solved problem of non-reproducible builds / trusting remotely-updated code.
I guess someone could key log my master password on my device, copy my vault and pwn me everywhere.
Also, when quantum computing becomes practical enough we password manager users might be in trouble, but surely in that case major changes in infosec would be needed regardless.
"The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs" - https://blog.lastpass.com/2022/12/notice-of-recent-security-...
The "such as..." without enumerating everything is very ominous as well.
You should do some actual math to roughly estimate what it would take to crack a good password. Use a strong password, use a resource-intensive key derivation function, and you should feel extremely comfortable that your encrypted data will not be cracked within your lifetime.
Fortunately for me, I don't use LastPass.