Jump to content

LastPass Faces Class-Action Lawsuit Over Password Vault Breach

Proud Cipher

Summary

 

A LastPass user is filing a class-action lawsuit against the company, citing the recent vault breaches and other security concerns.

 

Quotes

Quote

The lawsuit(Opens in a new window), filed this week in the US district court in Massachusetts, comes from an anonymous LastPass user named John Doe, who originally signed up for the service in May 2016. He’s now demanding the company pay in damages after LastPass announced last month it had lost a copy of every users’ password vaults to a hacker. 

“Plaintiff and the Class are anxious and alert as they are at a substantial risk of being bombarded with phishing emails and other scams, in addition to the fraud they have already suffered,” reads the lawsuit, which is suing LastPass for negligence, breach of contract, and deceptive acts.   

 

My thoughts

 This is upsetting to me personally because I am a regular LastPass user, and I've likely been affected by the breach. I've already changed my passwords, and although I use 2FA on everything it still has me feeling anxious. I had loved the service up until this point. In a cruel twist, I had purchased another year of the service a week before this breach was announced. I'm going to keep using LastPass until this year is up, or until I find a replacement that matches my preferences.

 

Sources

https://www.pcmag.com/news/lastpass-faces-class-action-lawsuit-over-password-vault-breach

Don't forget to mark posts as the solution if you're satisfied!

Link to comment
Share on other sites

Link to post
Share on other sites

oh a password site being hacked didn't see that coming...

I have dyslexia plz be kind to me. dont like my post dont read it or respond thx

also i edit post alot because you no why...

Thrasher_565 hub links build logs

Corsair Lian Li Bykski Barrow thermaltake nzxt aquacomputer 5v argb pin out guide + argb info

5v device to 12v mb header

Odds and Sods Argb Rgb Links

 

Link to comment
Share on other sites

Link to post
Share on other sites

Quote

 user suspects the breach at LastPass may have led a hacker to steal $53,000 in bitcoin from him over Thanksgiving weekend

 

Oh No Anyway GIF - Oh No Anyway - Discover & Share GIFs

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

16 minutes ago, Proud Cipher said:

I'm going to keep using LastPass until this year is up, or until I find a replacement that matches my preferences.

I'd check if you can't use the hack as a reason to get out of that year early and then switch somewhere else asap.

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Eigenvektor said:

I'd check if you can't use the hack as a reason to get out of that year early and then switch somewhere else asap.

That would be a huge pain in the ass, but it's certainly an option. I've got a lot of other stuff on my plate currently but I'm going to be keeping an eye out for a similar service that also allows Yubikeys as a 2FA method.

Don't forget to mark posts as the solution if you're satisfied!

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Proud Cipher said:

That would be a huge pain in the ass, but it's certainly an option. I've got a lot of other stuff on my plate currently but I'm going to be keeping an eye out for a similar service that also allows Yubikeys as a 2FA method.

Bitwarden supports it, if you have a premium account. They should also have an option to import from LastPass: https://bitwarden.com/help/import-from-lastpass/

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
Share on other sites

Link to post
Share on other sites

I was looking at Bitwarden, it's definitely the #1 option for me right now. Maybe I will take a crack at that refund from LastPass...

 

EDIT: Oh wow, it's also way cheaper. Looks like Bitwarden is the winner by default lmao

Don't forget to mark posts as the solution if you're satisfied!

Link to comment
Share on other sites

Link to post
Share on other sites

In fact I've gone ahead and got a year of premium for Bitwarden. Transferring everything over from LastPass was extremely simple and the software and interfaces are pretty good, not quite as polished as LastPass though. The way it handles TOTP is a little jank.

Don't forget to mark posts as the solution if you're satisfied!

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Proud Cipher said:

The way it handles TOTP is a little jank.

You shouldnt store that there....

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, jagdtigger said:

You shouldnt store that there....

I never said I was going to use Bitwarden's built in authenticator, only that the way it's handled is weird.

Don't forget to mark posts as the solution if you're satisfied!

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, Proud Cipher said:

I never said I was going to use Bitwarden's built in authenticator, only that the way it's handled is weird.

Weird how? You enter a secret key and it spits out a new 2FA code every 30 seconds, just like the authenticator app on a phone does it. Only difference would be that you need to manually enter the code, instead of scanning a QR code.

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
Share on other sites

Link to post
Share on other sites

Was always a bit skeptical as far as password managers are concerned that aren't from Google.

Personally I wouldn't trust anything that isn't part of Cloudflare or Google, at least those two have to always keep their services at the state of the art as far as security is concerned, and of course those aren't a sure bet either, it is always a matter of when a breach happens, not if it happens, but I like to have the belief that those two have the lowest chance of having something of the sort ocuring to them.

Link to comment
Share on other sites

Link to post
Share on other sites

Just be sure to register more than one Yubikey with one being a backup of the other in case it's lost or stolen.

 

Ideally you have a 3rd registered and kept offsite. Though definitely get a 2nd if you haven't already.

Link to comment
Share on other sites

Link to post
Share on other sites

On 1/15/2023 at 12:57 PM, Eigenvektor said:

Weird how? You enter a secret key and it spits out a new 2FA code every 30 seconds, just like the authenticator app on a phone does it. Only difference would be that you need to manually enter the code, instead of scanning a QR code.

You can scan a QR on the app

Link to comment
Share on other sites

Link to post
Share on other sites

i think the point is not to trust anyone with your data. vpns, password storage, cripto wallet, data center, photo upoload sites, any and all will be hacked. some one is buying your data and they would sell it to anyone... that the point of all apps collecting data. there are long term sites and projects that losses moeny for years and have a plan to make it back just like youtube. it was one free if you can remember. 

Edited by thrasher_565

I have dyslexia plz be kind to me. dont like my post dont read it or respond thx

also i edit post alot because you no why...

Thrasher_565 hub links build logs

Corsair Lian Li Bykski Barrow thermaltake nzxt aquacomputer 5v argb pin out guide + argb info

5v device to 12v mb header

Odds and Sods Argb Rgb Links

 

Link to comment
Share on other sites

Link to post
Share on other sites

And people laugh at me for using a pen and paper.  The term "putting all your eggs in one basket"  sounds fairly apt here.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

24 minutes ago, mr moose said:

And people laugh at me for using a pen and paper.  The term "putting all your eggs in one basket"  sounds fairly apt here.

what i find amusing, funny, weird (and ultimately irritating) is how they go from one key logger pass service to another saying its the best thing ever, not realizing that they're all the same, inherently unsecure, unreliable,  jank. 

 

 

The direction tells you... the direction

-Scott Manley, 2021

 

Softwares used:

Corsair Link (Anime Edition) 

MSI Afterburner 

OpenRGB

Lively Wallpaper 

OBS Studio

Shutter Encoder

Avidemux

FSResizer

Audacity 

VLC

WMP

GIMP

HWiNFO64

Paint

3D Paint

GitHub Desktop 

Superposition 

Prime95

Aida64

GPUZ

CPUZ

Generic Logviewer

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

24 minutes ago, mr moose said:

And people laugh at me for using a pen and paper.  The term "putting all your eggs in one basket"  sounds fairly apt here.

Dismissing the benefits of one thing because it might at some point have a drawback is not a very smart thing to do.

 

 

4 minutes ago, Mark Kaine said:

what i find amusing, funny, weird (and ultimately irritating) is how they go from one key logger pass service to another saying its the best thing ever, not realizing that they're all the same, inherently unsecure, unreliable,  jank.

Wanna know what is actually irritating? People who lack basic understanding of computer-security making dumb comments which are incorrect 99/100 cases, and then act smug when that 100th time happens to be somewhat correct.

 

Not all password managers are the same. I think it is ridiculous to say that they are. It's like saying all cars are the same, or all games are the same. Of course they are not the same.

Password managers are not "inherently secure". Security is not binary, and certain things have both strengths and drawbacks. What's important is weighting the benefits vs the drawbacks, and implementing things that minimizes the risks that comes with the drawbacks.

Not sure how all password managers are unreliable, and I especially don't see why all password managers would be more unreliable than for example pen+paper or just remembering passwords in your head.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Mark Kaine said:

what i find amusing, funny, weird (and ultimately irritating) is how they go from one key logger pass service to another saying its the best thing ever, not realizing that they're all the same, inherently unsecure, unreliable,  jank. 

 

 

Not all these services are the same however. While Bitwarden can store passwords on the cloud, which is how I currently use it. You can also store your password database locally. There are similar password managers that do this as well. The reason the Lastpass thing is so bad was because its a cloud based solution, also some people were down right dumb and stored their 2FA backup keys as well as other information in last pass. When I used Last Pass I never stored any other info besides my passwords, Name, Address and Phone number. My name, address and phone number have been leaked countless times by other hacks. 

 

To me the biggest take aways from this is cloud based password managers are probably a bad idea. Now hosting a pass word database locally is likely fine, because its not like the average hacker is going to hack in to a persons home network to get passwords when they can hack in to a corporate network and get accounts from many people at once. 

 

I for one am thinking about bringing my database local, maybe investing in to Yubikey's.  

I just want to sit back and watch the world burn. 

Link to comment
Share on other sites

Link to post
Share on other sites

On 1/15/2023 at 1:20 AM, Proud Cipher said:

In fact I've gone ahead and got a year of premium for Bitwarden. Transferring everything over from LastPass was extremely simple and the software and interfaces are pretty good, not quite as polished as LastPass though. The way it handles TOTP is a little jank.

When LastPass pulled their weird-ass "one device" policy for free accounts, I jumped ship over to Bitwarden and I haven't looked back. It works like a gem, and I can't recommend it enough. I'm glad you joined the club! (I use the free version)

--Dominik W

 

(What else do you need, this is just a signature, plus I have them disabled 😅)

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, mr moose said:

And people laugh at me for using a pen and paper.  The term "putting all your eggs in one basket"  sounds fairly apt here.

At this point, I store most of my passwords on my iPhone in the Passwords section, as well as Cryptical, and my phone is set to automatically completely erase itself after around 10 attempts of trying to get into it. I have never used a password manager in my life lol.

"It pays to keep an open mind, but not so open your brain falls out." - Carl Sagan.

"I can explain it to you, but I can't understand it for you" - Edward I. Koch

Link to comment
Share on other sites

Link to post
Share on other sites

My LastPass subscription was ending in 2 months so I made the switch to Bitwarden. 

I would like to use an external key but I'm super forgetful with where I place my things. So I'm afraid I will lose it.

Wish there was a FIDO2 compliant bio implant on the market.

AMD Ryzen 5 3600 | AsRock B450M-Pro4 | Zotac GTX 3070 Ti

Shure SRH840A | Sennheiser Momentum 2 AEBT | LG C9 55"

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×