LOGO
General Discussion Undecided where to post - do it here.

Reply to Thread New Thread
Old 05-05-2011, 09:50 PM   #1
lollypopz

Join Date
Oct 2005
Posts
410
Senior Member
Default LastPass Possibly Hacked
Just a warning for anyone that uses the service.

http://thenextweb.com/apps/2011/05/0...ter-passwords/
lollypopz is offline


Old 05-05-2011, 10:08 PM   #2
Amomiamup

Join Date
Nov 2005
Posts
414
Senior Member
Default
That sucks.. changed
Amomiamup is offline


Old 05-06-2011, 12:00 AM   #3
slimfifa

Join Date
Oct 2005
Posts
476
Senior Member
Default
Use http://keepass.info/ instead
slimfifa is offline


Old 05-06-2011, 12:04 AM   #4
engacenus

Join Date
Oct 2005
Posts
494
Senior Member
Default
Use http://keepass.info/ instead
That's not online is it?
engacenus is offline


Old 05-06-2011, 12:25 AM   #5
Rchzygnc

Join Date
Oct 2005
Posts
366
Senior Member
Default
That's not online is it?
Too much effort to click?
Rchzygnc is offline


Old 05-06-2011, 12:29 AM   #6
engacenus

Join Date
Oct 2005
Posts
494
Senior Member
Default
Too much effort to click?
I clicked but on the page couldn't see any log-in area.
engacenus is offline


Old 05-06-2011, 12:59 AM   #7
Rchzygnc

Join Date
Oct 2005
Posts
366
Senior Member
Default
I clicked but on the page couldn't see any log-in area.
I clicked on the page but I have no idea what I'm looking at.
Rchzygnc is offline


Old 05-06-2011, 01:42 AM   #8
citalopram

Join Date
Oct 2005
Posts
553
Senior Member
Default
So much for the advice to use one of these services to keep all your passwords remembered. One hack and some ne'er-do-well has all your passwords. Great.
citalopram is offline


Old 05-06-2011, 01:50 AM   #9
lollypopz

Join Date
Oct 2005
Posts
410
Senior Member
Default
So much for the advice to use one of these services to keep all your passwords remembered. One hack and some ne'er-do-well has all your passwords. Great.
Not necessarily
lollypopz is offline


Old 05-06-2011, 01:56 AM   #10
Greapyjeory

Join Date
Nov 2005
Posts
405
Senior Member
Default
Not necessarily
Definitely a "Not necessarily." If the passwords were stored on the service's servers in an un-encrypted manner, yeah.

But in the case of LastPass, everything's encrypted -- Even moreso if you use one of their methods of two-factor identification. Even if they got your master password, they'd also need the second factor for that to even be useful!
Greapyjeory is offline


Old 05-06-2011, 02:06 AM   #11
sapedotru

Join Date
Oct 2005
Posts
367
Senior Member
Default
Definitely a "Not necessarily." If the passwords were stored on the service's servers in an un-encrypted manner, yeah.

But in the case of LastPass, everything's encrypted -- Even moreso if you use one of their methods of two-factor identification. Even if they got your master password, they'd also need the second factor for that to even be useful!
The problem with the two-factor encryption is that makes it only as secure as your e-mail as there's always the possibility to disable the second authentication. However, as you say everything is encrypted.
sapedotru is offline


Old 05-06-2011, 02:11 AM   #12
Greapyjeory

Join Date
Nov 2005
Posts
405
Senior Member
Default
The problem with the two-factor encryption is that makes it only as secure as your e-mail as there's always the possibility to disable the second authentication. However, as you say everything is encrypted.
Correct, but then it'd require having your email already hacked... Even Google Apps has two-factor authentication now.
Greapyjeory is offline


Old 05-06-2011, 02:37 AM   #13
lollypopz

Join Date
Oct 2005
Posts
410
Senior Member
Default
Definitely a "Not necessarily." If the passwords were stored on the service's servers in an un-encrypted manner, yeah.

But in the case of LastPass, everything's encrypted -- Even moreso if you use one of their methods of two-factor identification. Even if they got your master password, they'd also need the second factor for that to even be useful!
Exactly, ergo they are just erring on the side of caution.
lollypopz is offline


Old 06-05-2011, 11:05 AM   #14
Qeiafib

Join Date
Oct 2005
Posts
526
Senior Member
Default
I hear one of these works pretty good.

Qeiafib is offline


Old 06-05-2011, 03:19 PM   #15
UltraSearchs

Join Date
Oct 2005
Posts
375
Senior Member
Default
I hear one of these works pretty good.

Yeah, but I hear the encryption on those kinda suck......
UltraSearchs is offline


Old 06-05-2011, 04:14 PM   #16
sapedotru

Join Date
Oct 2005
Posts
367
Senior Member
Default
Yeah, but I hear the encryption on those kinda suck......
Haha, not to mention passing via multiple devices hooked up via internet.
sapedotru is offline



Reply to Thread New Thread

« Previous Thread | Next Thread »

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

All times are GMT +1. The time now is 10:50 PM.
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.6.0 PL2
Design & Developed by Amodity.com
Copyright© Amodity