Skip to main content
  1. Home
  2. Computing
  3. News

LastPass suspects a breach, meaning it’s time for a password change

Add as a preferred source on Google

LastPass, the password management service, posted an update on June 15 to its blog noting that there had been “suspicious activity” on its website. The company stated, however, that its encryption measures have kept all of its users’ data safe.

“LastPass strengthens the authentication hash with a random salt and 100,000 rounds of server-side PBKDF2-SHA256, in addition to the rounds performed client-side,” wrote LastPass CEO and Founder Joe Siergrist. “This additional strengthening makes it difficult to attack the stolen hashes with any significant speed.”

Recommended Videos

As a result of the suspected breach, LastPass says it’s requiring all of its users who are logging in from a new device or IP address to verify their email, unless a multifactor authentication is enabled. LastPass is also asking everyone to update their master password, which could be a downer if you already committed your old one to memory.

And to make sure everyone is up to speed, LastPass is emailing all of its customers about the breach. Now, it appears that the website is handling a large wave of customers attempting to keep their data secure, according to TechSpot.

As of late Monday afternoon, a server overload message has been popping up when you attempt to change your master password. This doesn’t mean you should give up on taking LastPass’ advice, however, especially if it turns out the breach is worse than expected.

“We apologize for the extra steps of verifying your account and updating your master password, but ultimately believe this will provide you better protection,” Siergrist continued.

LastPass, which is headquartered in Virginia, does business in 71 countries around the world. In addition to encrypting passwords, LastPass encrypts and decrypts information locally before syncing it. This allows you to keep your sensitive data on your device.

“Security and privacy are our top concerns here at LastPass,” said Siergrist, reassuring customers following the breach.

Krystle Vermes
Former Digital Trends Contributor
Krystle Vermes is a professional writer, blogger and podcaster with a background in both online and print journalism. Her…
A simple coding mistake is exposing API keys across thousands of websites
Security gaps that are easier to miss than you think
Computer, Electronics, Laptop

After analyzing 10 million webpages, researchers have found thousands of websites accidentally exposing sensitive API credentials, including keys linked to major services like Amazon Web Services, Stripe, and OpenAI.

This is a serious issue because APIs act as the backbone of the apps we use today. They allow websites to connect to services like payments, cloud storage, and AI tools, but they rely on digital keys to stay secure. Once exposed, API keys can allow anyone to interact with those services with malicious intent.

Read more
AMD’s latest Ryzen 9 9950X3D2 pushes X3D to the limit
Dual 3D V-Cache, higher power, and a focus on enthusiast performance
AMD Ryzen 9 9950X3D2 FEatured

AMD has unveiled what might be its most extreme desktop CPU yet, the Ryzen 9 9950X3D2. And it’s going all-in on one thing: cache.

https://twitter.com/jackhuynh/status/2037159705395491033?s=20

Read more
Next-gen AI breakthrough promises chatbots that can read the room better
Researchers are teaching AI chatbots to read between the lines
Generative AI

Have you ever asked a chatbot something and felt like it completely missed your point? You say something with a bit of nuance, and the AI misses the subtlety entirely. That is exactly the problem researchers are trying to solve.

Even though the emotional connection with AI can feel deeper than human conversation for many users, most AI systems today still treat a sentence as a single block of sentiment. If you mix praise and criticism, the nuance often gets lost.

Read more