Saturday, June 7, 2025

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
  • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Security Bloggers Network » The Antidote for the LastPass password vault breach

SBN

The Antidote for the LastPass password vault breach

by Steve Tout on December 29, 2022

Earlier in December, we learned that LastPass customers’ data was stolen in a security incident. LastPass informed its customers that leaked sensitive data, including email, phone, billing address, and the IP address of users while using the service. The company assured its customers that credentials were not compromised in the incident.

On December 22, we learned that the hacker also accessed backups of credential vaults. Even though we are assured by LastPass that no attacker can crack the password vaults due to the AES-256 encryption and Zero Knowledge architecture, we can conclude from research and personal experience that many master passwords are weak, reused, and more easily guessable than high entropy passwords.

Too many passwords

LastPass celebrated reaching 25 million users in 2020. A study commissioned by NordPass last year found that the average user has around 100 passwords for websites and services. Going by averages, a conservative estimate, an additional 2.5 billion leaked credentials will be sold on the dark web sooner than any of us expect.

Techstrong Gang Youtube
AWS Hub

The pedestrian advice journalists and experts currently recommend to users and organizations ranges from changing passwords to enabling MFA to ditch LastPass or password managers altogether. I don’t use LastPass (I use a different password manager) and my vault has over 800 credentials. Whether users have 100 or 800 passwords, changing passwords and enabling MFA on most or all accounts is a challenge, even for tech-savvy users.

Simple math:

100 password resets * 5 minutes per reset = 500 minutes = 8.33 hours

800 password resets * 5 minutes per reset = 4000 minutes = 66.66 hours

That time doesn’t include setting up MFA, which is impossible for all accounts.

It is improbable that anyone would invest hours, days, or weeks of their lives resetting their passwords even after an incident such as the LastPass breach.

The obvious solution of changing all the passwords –or enabling MFA– isn’t the most practical or realistic.

Credential verification stops ATOs before they start

Organizations have a fiduciary and legal responsibility to protect their users’ credentials and sensitive data. We often discuss the need to assess the risk of compromised credentials and warn that free breach notification services are not viable security solutions and provide a false sense of security.

We also explain how the risk of ATO attacks can be mitigated with modern identity threat intelligence solutions like our patented CredVerify technology. CISOs and IT leaders must go beyond free breach notification services and generic compromised password lists. The solution for monitoring and verification of compromised credentials needs to be able to answer the following:

  • Is my current password leaked or reused?
  • How at risk are the executives and privileged users in my organization?
  • How can I only notify affected users without forcing a user to change his or her password due to hypothetical risk?
  • How can I verify compromised credentials without revealing the account identifier or the credential with a service provider?
  • Does this user’s leaked credential satisfy or violate my organization’s password policy?

If you haven’t done so, you can request a demo or get started with credential verification for protecting your sensitive data and customer accounts.

VeriClouds is the white-labeled solution behind one of the largest email providers in the world.

Download the Datasheet

The post The Antidote for the LastPass password vault breach appeared first on VeriClouds.

*** This is a Security Bloggers Network syndicated blog from Blog – VeriClouds authored by Steve Tout. Read the original post at: https://www.vericlouds.com/the-antidote-for-the-lastpass-password-vault-breach/

December 29, 2022January 4, 2023 Steve Tout Account Takeover Attacks, exposed data, ITDR, leaked passwords
  • ← Developing a “Corporate Foreign Policy”: The Urgent Need for Boardroom Geopolitics Strategies
  • Happy 13th Birthday, KrebsOnSecurity! →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Cloud Field Day

Upcoming Webinars

How to Spot and Stop Security Risks From Unmanaged AI Tools
Software Supply Chain Security: Navigating NIST, CRA, and FDA Regulations

Podcast

Listen to all of our podcasts

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

ThreatLocker

Most Read on the Boulevard

Akamai Extends Cybersecurity Reach to DNS Posture Management
Meta’s Secret Spyware: ‘Local Mess’ Hack Tracks You Across the Web
Qualcomm Fixes Three Adreno GPU Flaws Abused in Android Attacks
Sysdig Reveals Discovery of Cyberattack Aimed at Tool to Build AI Apps
Yet Another Exposed Database, This Time with 184 Million Records
Microsoft Open Sources GitHub Copilot: A New Era for AI Coding
Multiple High-Risk Vulnerabilities in Microsoft Products
Critical Linux Vulnerabilities Risk Password Hash Theft Worldwide
How Morpheus AI Automates the Entire L1 & L2 Pipeline
Interlock and the Kettering Ransomware Attack: ClickFix’s Persistence

Industry Spotlight

Meta’s Secret Spyware: ‘Local Mess’ Hack Tracks You Across the Web
Application Security Cloud Security Cyberlaw Cybersecurity Data Privacy DevOps Endpoint Featured Governance, Risk & Compliance Humor Identity & Access Incident Response Industry Spotlight Malware Mobile Security Most Read This Week Network Security News Popular Post Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Social Engineering Spotlight Threats & Breaches Vulnerabilities 

Meta’s Secret Spyware: ‘Local Mess’ Hack Tracks You Across the Web

June 4, 2025 Richi Jennings | 2 days ago 0
USDA Worker, 5 Others Charged in Food Stamp Fraud Operation
Cyberlaw Cybersecurity Data Security Featured Governance, Risk & Compliance Identity & Access Industry Spotlight News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

USDA Worker, 5 Others Charged in Food Stamp Fraud Operation

May 30, 2025 Jeffrey Burt | May 30 0
Victoria’s Secret Hit By ‘Security Incident’ After Attacks on UK Retailers
Cloud Security Cybersecurity Data Security Featured Incident Response Industry Spotlight Malware Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Victoria’s Secret Hit By ‘Security Incident’ After Attacks on UK Retailers

May 29, 2025 Jeffrey Burt | May 29 0

Top Stories

Zscaler Tightens AI Security With New Tools
Application Security Cybersecurity Data Privacy Data Security Featured Network Security News Social - Facebook Social - LinkedIn Social - X Zero-Trust 

Zscaler Tightens AI Security With New Tools

June 5, 2025 Jon Swartz | 1 day ago 0
Microsoft Launches Free Security Program for European Governments
Cloud Security Cybersecurity Data Privacy Data Security Featured Governance, Risk & Compliance Incident Response Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Microsoft Launches Free Security Program for European Governments

June 4, 2025 Jeffrey Burt | 2 days ago 0
Microsoft, CrowdStrike Partner to Bring Clarity to Threat Actor Identities
Cloud Security Cybersecurity Data Security Featured Identity & Access Incident Response Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Microsoft, CrowdStrike Partner to Bring Clarity to Threat Actor Identities

June 3, 2025 Jeffrey Burt | 3 days ago 0

Security Humor

Facebook CEO Mark Zuckerberg announces the plan to make Facebook more private at Facebook’s Developer Conference on April 30, 2019

Meta’s Secret Spyware: ‘Local Mess’ Hack Tracks You Across the Web

Download Free eBook

Managing the AppSec Toolstack

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2025 Techstrong Group Inc. All rights reserved.
×