Do you use LastPass? Announced Zero-day

A dangerous LastPass security vulnerability allows attackers to gain remote access to user accounts.

LastPass saves user passwords in a "secure" area and automatically displays credentials for you on the pages that require it when needed. The system uses AES-256 bit encryption with PBKDF2 SHA-256 and salted hashes to protect valuable data that is stored.LastPass

But according to the well-known security researcher from the Tavis Ormandy, the software contains "critical issues" that could put user accounts at risk.

On Tuesday, White Hat revealed on Twitter that a quick look at LastPass security discovered "obvious" security issues.

So millions of users can be in danger until the problem is repaired. Of course, you understand that if an attacker can intercept a LastPass user account, it gives him access to a thesaurus with credentials for other online services.

Ormandy has announced zero-day and other critical critical security issues without giving technical details.

The same researcher has discovered critical problems in the software of major companies such as Symantec, Avast and many others.

Here we should mention something we say very often: For passwords managers, forget about online services. Store your data locally. They are more likely to hack a LastPass that attracts them by thousands because of its services rather than your computer.

Try the free app KeePass. It will store all of your passwords locally with satisfactory encryption. All you have to remember is a master code for opening the application.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.086 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).