• Passerby6497@lemmy.world
    link
    fedilink
    English
    arrow-up
    20
    ·
    10 months ago

    the passwords themselves weren’t leaked

    You’re not wrong, but you kinda are. The plaintext passwords weren’t released, but the encrypted blobs were stolen. Unfortunately, the LastPass defaults were absolutely shit so people have been able to selectively attack the blobs and decrypt the vaults, leading to millions in crypto being stolen.

    I was a long time supporter of LastPass, but they haven’t been responsible stewards of sensitive information. The fact that they failed to encourage or force existing customers to update the encryption settings as they updated their defaults is negligent and is disqualifying in my opinion.