Skip to content

Comment on LastPass users: Your info and vault data is now in hackers’ hands

Comments

There ought to be some kind of legal sanction against companies that try to hide the seriousness of data breaches.

I read the customer update, and the severity of this breach is hidden deep in the statement and skimmed over.

Basically: LastPass just shared which sites you have logins for with the attacker. This could be sold or released to the entire world. They claim the usernames are encrypted fields but often the usernames can also be in the URLs saved along with the site.

I really don’t understand why they didn’t just encrypt the whole records.

The convenience of offering to re-login if your session is expired and you hit a site where you use it?

That could have been cached locally on your machine, separate from your vault.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.