minigubben's lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Lee Duna@lemmy.nz to Technology@lemmy.worldEnglish · 1 year ago

Researcher uncovers one of the biggest password dumps in recent history

arstechnica.com

external-link
message-square
44
fedilink
289
external-link

Researcher uncovers one of the biggest password dumps in recent history

arstechnica.com

Lee Duna@lemmy.nz to Technology@lemmy.worldEnglish · 1 year ago
message-square
44
fedilink
Roughly 25 million of the passwords have never been seen before by widely used service.
  • Tangent5280@lemmy.world
    link
    fedilink
    English
    arrow-up
    32
    ·
    1 year ago

    I feel like atleast one of these has been hacked at some point in the past, but I cant remember which.

    • hperrin@lemmy.world
      link
      fedilink
      English
      arrow-up
      56
      arrow-down
      6
      ·
      1 year ago

      It was LastPass, but the passwords themselves weren’t leaked. All of these encrypt the password.

      • Observer1199@lemmy.ml
        link
        fedilink
        English
        arrow-up
        61
        ·
        1 year ago

        LaatPass should not be recommended or used by anyone after the extent of the breach and how they lied about when they eventually told people

        https://www.forbes.com/sites/daveywinder/2023/03/03/why-you-should-stop-using-lastpass-after-new-hack-method-update/

      • Passerby6497@lemmy.world
        link
        fedilink
        English
        arrow-up
        22
        ·
        1 year ago

        the passwords themselves weren’t leaked

        You’re not wrong, but you kinda are. The plaintext passwords weren’t released, but the encrypted blobs were stolen. Unfortunately, the LastPass defaults were absolutely shit so people have been able to selectively attack the blobs and decrypt the vaults, leading to millions in crypto being stolen.

        I was a long time supporter of LastPass, but they haven’t been responsible stewards of sensitive information. The fact that they failed to encourage or force existing customers to update the encryption settings as they updated their defaults is negligent and is disqualifying in my opinion.

      • Z4rK@lemmy.world
        link
        fedilink
        English
        arrow-up
        19
        ·
        1 year ago

        There is no excuse for LastPass and it absolutely should not be treated with your passwords or secrets.

      • Plopp@lemmy.world
        link
        fedilink
        English
        arrow-up
        12
        ·
        1 year ago

        This is an interesting and a bit terrifying podcast about it (and other things), from a infosec perspective. https://twit.tv/shows/security-now/episodes/905?autostart=false

        • shaggy959500@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          1 year ago

          Security Now is amazing. For anyone that wants the deep dive tech perspective, plus what it means for everyday people and users, this is a great option.

      • Tangent5280@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 year ago

        Ah, alright, thanks. Thats a good thing then, that you cant get to the passwords even if you hack the company.

    • 1984@lemmy.today
      link
      fedilink
      English
      arrow-up
      43
      ·
      1 year ago

      Lastpass had lots of issues.

    • boatswain@infosec.pub
      link
      fedilink
      English
      arrow-up
      18
      ·
      1 year ago

      KeePass doesn’t store your stuff in the cloud; it’s all local storage. You can sync your encrypted KeePass DB in a number of different ways; personally, I go for SyncThing, but you can use Box or whatever.

    • SteefLem@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      deleted by creator

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1.28K users / day
  • 2.57K users / week
  • 5.59K users / month
  • 8 users / 6 months
  • 0 local subscribers
  • 58.7K subscribers
  • 12.7K Posts
  • 537K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemm.ee
  • L4sBot@lemmy.world
  • fry@fry.gs
  • L3s@fry.gs
  • enu@lemmy.world
  • L4sBot@fry.gs
  • BE: 0.19.7
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org