Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> We have determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information. Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture.

Sure sounds like they found passwords or keys in the development environment breach back in August, and nobody bothered to change those after knowing they were hacked.



The most shocking thing for me. The real stopper for anyone who is still trying to keep their trust in LastPass.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: