Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Software
General Apps
Passwords and passkeys
Almost Secure Blog: A year after the disastrous breach, LastPass has not improved
Message
<blockquote data-quote="Wladimir Palant" data-source="post: 1056279" data-attributes="member: 89522"><p>This isn’t really about online vs. offline. It’s possible to encrypt data in a way that it is safe to store online. But for that you have to understand crypto and to encrypt everything. Most popular password managers are doing an okay’ish job on that – there might be smaller issues, but these aren’t showstoppers. In case of a breach, only a few high-profile targets might have reason to worry. Also, the other password managers took the LastPass breach as an occasion to check their security, and they did improve things.</p><p></p><p>LastPass is really exceptionally bad. Not only is it clear from their source code that they don’t understand crypto and never did. This is at least their third breach, and they failed to learn from any of them. Never mind their “regular” security issues where they received reports of issues in the same area again and again, being unable to fix things properly.</p></blockquote><p></p>
[QUOTE="Wladimir Palant, post: 1056279, member: 89522"] This isn’t really about online vs. offline. It’s possible to encrypt data in a way that it is safe to store online. But for that you have to understand crypto and to encrypt everything. Most popular password managers are doing an okay’ish job on that – there might be smaller issues, but these aren’t showstoppers. In case of a breach, only a few high-profile targets might have reason to worry. Also, the other password managers took the LastPass breach as an occasion to check their security, and they did improve things. LastPass is really exceptionally bad. Not only is it clear from their source code that they don’t understand crypto and never did. This is at least their third breach, and they failed to learn from any of them. Never mind their “regular” security issues where they received reports of issues in the same area again and again, being unable to fix things properly. [/QUOTE]
Insert quotes…
Verification
Post reply
Top