Do you use LastPass? Announced Zero-day

A dangerous vulnerability in of LastPass allows attackers to gain remote access to user accounts.

Η LastPass αποθηκεύει τους κωδικούς πρόσβασης του χρήστη σε μια “ασφαλή” περιοχή και όταν χρειαστεί αναγράφει αυτόματα τα διαπιστευτήρια για σας στις σελίδες που το απαιτούν. Το σύστημα χρησιμοποιεί κρυπτογράφηση AES-256 bit με PBKDF2 SHA-256 και αλατισμένα (salted) hashes για να προστατεύει τα πολύτιμα δεδομένα που είναι αποθηκευμένα.LastPass

But according to well-known security researcher Google Project Zero Tavis Ormandy, the software contains "critical problems" that could put users' accounts at risk.

On Tuesday, the White Hat hacker revealed on Twitter that a quick look at LastPass security revealed "obvious" security problems.

So millions of users may be at risk until the problem is fixed. Of course you understand that if an attacker can hijack a LastPass user account, it gives them access to a treasure trove of credentials for other online .

Ormandy announced the and other critical safety issues without giving technical details.

The same researcher has discovered critical problems in the software of major companies such as Symantec, Avast and many others.

Here we have to mention something we say very often: For passwords managers forget about online services. You store your data locally. They are more likely to violate a LastPass that attracts thousands of hackers because of its services rather than your computer.

Try the free app KeePass. It will store all of your passwords locally with satisfactory encryption. All you have to remember is a master code for opening the application.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).