infoTECH Feature

June 18, 2015

LastPass is the Latest Security Provider to Get Hacked

Even though the vast majority of us love what digital technology has done for the world we live in, when it comes to the issue of security, it gives us pause. With news of breaches almost a daily occurrence, it seems as if there is no way anyone can fully protect themselves. The recent announcement by Kaspersky, a global digital security provider, that its labs were hacked only validates this apprehension and the current state of the security threat landscape. Granted most of us don’t have the assets that warrant the type of effort required to hack Kaspersky or other large organizations, we are still vulnerable. The latest company to announce its assets were compromised is LastPass, a platform used to secure the personal information of individual consumers and organizations. 

Although the company has not revealed full details of the breach, CEO Joe Siegrist blogged that they don’t yet know the number of users affected by the incident, but account email addresses and password reminders were compromised. This is the third time the company experienced instances in which the information of its customers were put at risk.

In 2011 around 1.25 million accounts were stolen, and in 2013 a software bug exposed the passwords of Internet Explorer users.

It is worth noting that the hackers did not get actual passwords from LastPass’ network and the user vaults were not accessed, so any information within those vaults are safe.

The company has an extremely elaborate encryption system to ensure the passwords of its users are safe. It uses encryption and hashing algorithms that hash both the username and master password on the user’s computer with 5,000 rounds of PBKDF2-SHA256 algorithm. The company never has access to the master password.

Once a key is created, another round of hashing is initiated to generate the master password authentication. This information is sent to the company’s server to perform a check as the user is logging in.  According to the company, “We then take that value, and use a salt (a random string per user) and do another 100,000 rounds of hashing, and compare that to what is in our database.”

On the blog Siegrist said, “If you used your master password for any other website, we do advise changing it – on LastPass as well as on the other websites. Note that you should never reuse passwords – especially your LastPass master password!”

Whether you are using a platform such as LastPass or another security measure, you have to be vigilant at all times. Even if you don’t have millions of dollars or trade secrets on your computer, start getting into the habit of practicing good security measures to protect the assets you own. Create long passwords, change them regularly, go over your information to ensure they are safe, don’t centralize your information in one location, back up the data and have a recovery system in place.




Edited by Dominick Sorrentino
FOLLOW US

Subscribe to InfoTECH Spotlight eNews

InfoTECH Spotlight eNews delivers the latest news impacting technology in the IT industry each week. Sign up to receive FREE breaking news today!
FREE eNewsletter

infoTECH Whitepapers