LastPass Hack: The CRUCIAL Problem No One Is Talking About

แชร์
ฝัง
  • เผยแพร่เมื่อ 31 ม.ค. 2023
  • Sign up for DeleteMe! Use the coupon code SNUBS for 20% off any consumer plans! Linky: www.JoinDeleteMe.com/MorseCode * (coupon code automatically applied at checkout)
    LastPass admitted to getting hacked a couple of months ago, and we're just now learning more details about what was breached. Password Managers are often targeted in hacks but in my opinion, LastPass is downplaying a crucial problem that can affect users.
    My fav password managers for 2023:
    25% off 1Password: www.jdoqocy.com/click-1003458... *
    30% off Roboform: www.kqzyfj.com/click-10034586... *
    Dashlane: www.dashlane.com/
    Bitwarden: bitwarden.com/
    Keeper: www.keepersecurity.com/
    What Is A Password Manager And Should You Trust Them? - • What Is A Password Man...
    LINKS:
    blog.lastpass.com/2022/12/not...
    support.lastpass.com/help/wha...
    support.lastpass.com/download...
    www.goto.com/blog/our-respons...
    blog.gaborszathmari.me/sessio...
    capec.mitre.org/data/definiti...
    cwe.mitre.org/data/definition...
    FTC: Links marked with * are affiliate links, which means I make a small commission off any sales.
    Becoming a Morse Code Member by checking out the perks linked here!:
    / @shannonmorse
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    SUBSCRIBE! 🌸 th-cam.com/users/ShannonMorse?s...
    TWITTER 🌸 / snubs
    Patreon 🌸 / shannonmorse
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    SUPPORT MY WORK
    Patreon 💛 / shannonmorse
    Buy Me a Coffee 💛 www.buymeacoffee.com/snubs
    Shop 💛 snubsie.com/shop
    TeeSpring 💛 teespring.com/stores/morsecode
    Coupon Codes 💛 snubsie.com/support
    Tech I Use & Recommend 💛 kit.co/ShannonMorse
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    FOLLOW THE SOCIALS THINGS
    Twitter 🌸 / snubs
    Instagram 🌸 / snubs
    TH-cam 🌸 th-cam.com/users/ShannonMorse?s...
    Website 🌸 www.shannonrmorse.com
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    TECH I USE AND RECOMMEND
    My Kits, Builds, and Must Haves ✨ kit.co/ShannonMorse
    My Amazon Influencer Page ✨ www.amazon.com/shop/shannonmorse
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    MY OTHER SHOWS
    ThreatWire 🌙 th-cam.com/users/hak5?sub_confi...
    Sailor Snubs 🌙 th-cam.com/users/sailorsnubs?s...
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    GET IN TOUCH
    Mail ✈
    snubsie.com/contact
    Email for Business and Sponsorship Inquiries ✈ Shannon@ShannonRMorse.com
    My Media Kit ✈ snubsie.com/work-with-me
    Sponsor This Channel ✈ snubsie.com/shannon-morse
    Music from 🎵 Epidemic Sound: www.epidemicsound.com/referra...
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    😍 FTC DISCLAIMER 😍
    Affiliate links listed above allow me to receive a small commission. Any sponsorships for videos are noted in video and listed in descriptions. Any products provided as gifts are listed above. Thank you for your support!
    Comment section code of conduct policy:
    Constructive feedback is appreciated, but please leave unproductive, divisive and harmful conversation at the door. Hateful comments are not tolerated, and these kinds of messages will be automatically removed. Thank you for making this community a welcoming experience for all viewers :)
    snubsie.com/code-of-conduct

ความคิดเห็น • 470

  • @happysprollie
    @happysprollie ปีที่แล้ว +278

    I switched from LastPass to Bitwarden when the hack happened, and actually find BW to be superior. And FWIW, I'm in the infosec business. I'd become anxious about LP after its aquisition by LogMeIn (which didn't have a stellar security record). Wish I'd acted sooner.

  • @mu_zines
    @mu_zines ปีที่แล้ว +91

    There’s also an additional problem you didn’t mention - LastPass not updating customers’ hash iteration value. They changed the default to 100,000+ iterations, but people who created accounts a decade ago had iteration counts of 5000, or even

  • @Wyrenth
    @Wyrenth ปีที่แล้ว +97

    An updated password manager video would be awesome. As well as how to make the process of migrating easier. Right now the challenge is momentum - it’s hard to just get started.

  • @Rickmakes
    @Rickmakes ปีที่แล้ว +35

    Another problem with this is that it makes people lose trust in password managers, which ultimately leaves them more vulnerable. I like your advice of not having your most valuable passwords in your manager and to switch managers early if you hear of a breach. Hopefully it is sinking in that people need to take an active approach to security.

  • @paulsullivan649
    @paulsullivan649 ปีที่แล้ว +28

    Thanks so much for talking about this. I love that you bring issues like this to a wider community, on top of always talking about safer ways to keep our private information actually private!

  • @pudelz
    @pudelz ปีที่แล้ว +8

    I'm glad I'm not the only one that pays attention to the words used like "such as" in statements.

  • @wavemakersdj
    @wavemakersdj ปีที่แล้ว +9

    Switched to Keeper. The bad part is the vault data that was stolen is not going to be impacted by what you change now, so it can be scanned for years to try and get new credentials that are still in place. What users should really do is change every single password in their lastpass list, save on a different service or locally, and drop all go-to products from this point forward.

  • @TimDavis77
    @TimDavis77 ปีที่แล้ว +6

    Great breakdown. I hadn't considered the Session ID issue in the URL until your video. As much as I loved Lastpass, this breach was the last straw for me.

  • @Alexoladele
    @Alexoladele ปีที่แล้ว +1

    Absolutely love this video! Great explanation of what happened.

  • @kevorka3281
    @kevorka3281 ปีที่แล้ว +2

    >makes secure password manager

  • @genxguy

    As a network Sysadmin geek myself I love your videos. Will spoken clear and to the point.

  • @cmdrbozo
    @cmdrbozo ปีที่แล้ว +28

    My suggestion, no matter where you record your passwords, is to use and store a partial passwords, but to have a secret code, e.g., three ending characters you add to every password. And never record that secret code anywhere except maybe on the side of your bottom dresser drawer. That way if your UN/PW is hacked you're safe because the hacker has only a partial password. Also protected if you have a written list.

  • @solarnightedge5732
    @solarnightedge5732 ปีที่แล้ว +4

    great video and love how u break it down so easily that anyone thats not very tech savvy can understand.👍

  • @Blizzard4242
    @Blizzard4242 ปีที่แล้ว +2

    That's a really good point. I already had those thoughts when I read about it as well, thankfully though this should really only affect either the websites you recently added (which might still have a valid session ongoing), I really hope there are no websites around that never change the session. But as you said, you can't know so it's always the safest to change the passwords to make sure.

  • @jmr
    @jmr ปีที่แล้ว +10

    Hardware 2FA needs to be a universal option.

  • @MorbidGod391

    11:37

  • @craigbailey9487
    @craigbailey9487 ปีที่แล้ว +1

    Thank you! I love the tech videos, but this is great information!😎

  • @LedNe0nDevil
    @LedNe0nDevil ปีที่แล้ว +5

    Thank you for explaining this in detail, I know nothing about security, more of an hardware guy. So this thought me a lot. Session hijack achievement unlocked.

  • @rerunx5
    @rerunx5 ปีที่แล้ว +11

    I'm glad I switched a long time ago to Bitwarden. Your video on showcasing different password managers really helped me on making my decision.

  • @jonnyhepcat
    @jonnyhepcat ปีที่แล้ว

    Great information! You gave me more to think about on this hack.