LOL cloud-based password managers, honestly.

"The threat actor was also able to copy a backup of customer vault data"

blog.lastpass.com/2022/12/noti

@ocdtrekkie Fortunately, the passwords themselves, while in the hands of bad actors now, are encrypted and should be mathematically unbreakable (if I understand correctly, the encryption algorithm is good enough... Assuming, of course, they didn't screw anything up with the implementation).

But the immediate concern is that a lot of data wasn't encrypted, like the plain text domain names. So the data set serves as a giant map from users to the websites they frequent.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.