Password Manageri - LastPass data breach, the sequel
#1
Malo kasnim s ovom informacijom, članak je izašao prije 4 dana. LastPass je fasovao data breach u augustu OVE godine i OPET 30og novembra.
LastPass nije napisao detaljno šta/kako se desio breach, ali e'o šta reče CEO Karim Toubba:

We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security firm, and alerted law enforcement.

Okej, uradili su dobro, odmah su kontaktirali sigurnosnu firmu i obavijestili službe, ali da li se ovo ikako moglo spriječiti i kako?

Šta mislite o password managerima? Jesu li ljudi prodali svoju sigurnost za pogodnost i udobnost?

Izvor/inspiracija:
https://www.ghacks.net/2022/12/01/lastpa...ta-stolen/
Izvor izvora:
https://blog.lastpass.com/2022/11/notice...-incident/
Scio me nihil scire.
Reply
#2
Hvala za info Hana. Po meni ovakvi sistemi moraju koristiti dedicated online resurse kako bi sprečili ovakve napade.
Inače podržavam korišćene password menadzera samo ako su offline bez ikakve network funkcionalnosti.
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply
#3
Nema na čemu. Da, pročitala sam da Dashlane je nekad imao tu opciju for free za korisnike, sada više nema.
Scio me nihil scire.
Reply
#4
Poslednji update sto se lastpass tice...
Probijanje moguce uz upotrebu brute force..

"LastPass said customers’ password vaults are encrypted and can only be unlocked with the customers’ master password, which is only known to the customer. But the company warned that the cybercriminals behind the intrusion “may attempt to use brute force to guess your master password and decrypt the copies of vault data they took.”

https://techcrunch-com.cdn.ampproject.or...tolen/amp/

Na zalost toliko o sigurnoj upotrebi password menadzera...mozda deluje korisno,moguce deljenje, generisanje...ali ukoliko hocete siguran password, najbolje je koristiti offline menadzere i najbolje ga je generisatilicno bez upotrebe auto generate.
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)