LastPass Discloses Another Security Breach


    


    Sarah Tew/CNET
    


    Password manager LastPass has had another security breach, stemming directly from one that occurred in August, the company said Wednesday.?
    “An unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information,” LastPass CEO Karim Toubba?wrote in a blog post. “Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture.”
    LastPass is designed to let people securely generate and save passwords across their devices, store digital records, and share both with trusted contacts. LastPass’ zero knowledge model is meant to give only the customer, and not LastPass, access to an account’s master password.
    The company’s services are fully functional, Toubba said. LastPass is working with an outside security firm to determine the scope of the breach and exactly what information was accessed, the company said.
    The breach was identified in a cloud storage service shared by LastPass affiliate GoTo, which acknowledged the same breach on Wednesday.
    
Read more

  • Best Password Manager to Use for 2022
  • LastPass Review: A Leading Password Manager With a Changing Value Proposition
  • Bitwarden vs. LastPass: How Do CNET’s Top Password Manager Picks Stack Up?
  • Need a LastPass Alternative? This Is the Best Free Password Manager We’ve Found