/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

LastPass' breach update was full of lies, omitted damning info, tried to present the August 2022 incident and the data leak as two separate events, and more

Almost Secure Wladimir Palant

Context & Ripple Effects

LastPass initially said the August intrusion had not shown access to customer data or encrypted vaults, but its later disclosure tied customer-data access to information taken in that incident. The latest critique centers on whether the company presented that connected sequence as separate events.

The arc sharpened days earlier when LastPass said attackers obtained a backup copy of encrypted and unencrypted vault data using cloud-storage keys taken from an employee. That makes the framing of the August compromise central to customers’ understanding of their exposure.

First-order effects

  • LastPass faces an immediate credibility problem: customers must reconcile its earlier assurance that customer data had not been accessed with disclosures that the August breach enabled later access to cloud-stored data.
  • Customers and organizations using LastPass have to assess the incidents as a linked attack chain rather than rely on the narrower initial description of the August intrusion.

Second-order effects

  • Password-manager competitors gain a clear trust and communications contrast as LastPass customers evaluate whether its disclosures gave them a complete basis for risk decisions.
  • Security teams that use LastPass must account for the cloud-storage compromise and vault-data theft together when reviewing vendor notifications and internal response records.

Third-order effects

  • If vendors continue to describe connected compromises as discrete events, breach disclosure will be judged increasingly on whether it explains the full attack path, not simply whether each individual statement is technically bounded.
  • The episode points to trust becoming a durable competitive factor for credential-management providers, alongside the security of their systems.

The trend: Cybersecurity vendors are being judged not only on breach containment but on whether their incident disclosures accurately connect the stages of an attack.

Discussion

  • @LukaszOlejnik@mastodon.social Lukasz Olejnik on mastodon
    LastPass breach is much more serious than the official Breach Notice wants you to know.  It is, however, very cleverly crafted.  Essentially cybersecurity/privacy PR.  Decrypted here @WPalant@infosec.exchange — so have a look. …
  • @joshbressers@mastodon.social Josh Bressers on mastodon
    There will be time for smug comments about LastPass later Actually useful information is to first migrate to a different service.  LastPass shouldn't be trusted at this time.  Do not use the same master password Once migrated. …
  • @kennwhite@mastodon.social Kenn White on mastodon
    The painful thing for LastPass users who did unfortunately reuse their master password on other sites is that this case is now an *offline* attack - which means 2FA or changing one's LastPass web password …
  • @kennwhite@mastodon.social Kenn White on mastodon
    For the vast majority of people, having some kind of secure centralized (yes, cloud-based) password management with straightforward recovery & trusted family/guardian delegation is the probably the best option. …
  • @networkchuck @networkchuck on x
    This bad boy can crack into your LastPass vaults in 3 seconds. 😜 https://twitter.com/...
  • @saradietschy @saradietschy on x
    Not too freaked out by the LastPass hack since my Master Password was insane however it was the last straw for me re: LastPass — I spent yesterday figuring out a new password manager and changing a lot of important passwords / making sure they all have 2factor set up
  • @gcluley Graham Cluley on x
    This analysis by @WPalant of LastPass's PR statement about its data breach is pretty damning... :( I do hope LastPass users who need to take action haven't missed what's going on amid all this Christmas/New Year malarkey https://palant.info/...
  • @woonomic Willy Woo on x
    The more I learn about the @LastPass breach the more pissed their customers should be. They did not encrypt your URLs or your last use of a password. So basically they could monitor your web activity. They reduced your security for their own benefit. https://twitter.com/...
  • @0xfoobar @0xfoobar on x
    Done using any sites which require a private key signature to simply connect a wallet. It's absurd authentication overreach, and explicitly training users to get hacked. Goodbye to @opensea, @1inch, and many more. Do better
  • @0xfoobar @0xfoobar on x
    @opensea @1inch Much like LastPass arguing in past years that unencrypted URL info was “nothing to worry about”, sites which push this feature plainly reveal they don't care one bit about user safety, and are destined for even worse privacy breaches in the future
  • @j0hnnyxm4s @j0hnnyxm4s on x
    Extremely important, and generally overlooked: the LastPass breach included UNENCRYPTED URLs, which may mean your intranet URLs and perhaps external URLs you generally don't want crawled have been leaked: https://www.seroundtable.com/ ...