LastPass - TLDR Version

LastPass - TLDR Version

Some of you may be aware of a recent announcement from LastPass regarding a 2nd breach in which customer data (including accounts and passwords) were captured by hackers. I'm not going to rehash the events but thought I might provide a simplified message of what should be done if you were caught in the blast radius of the breach, either as a business customer or consumer. The answers will definitely vary.

Consumers:

  1. Change your master password immediately (regardless of current strength), make it strong but memorable. Bruce Schneier offers an effective method here. If not enabled already, add a strong Two-Factor authentication (2FA) method. I recommend Yubikeys but Basic solutions like Authy are good as well.
  2. Assume all of the accounts in your vaults are compromised and change them ASAP in order of risk priority: email, bank, retirement/financial/insurance, social media, etc.
  3. While executing on 2, enable Two-Factor authentication wherever possible. This is probably the best way, even in a breach condition, to protect your accounts to date.

Business Customers:

The answer is category depends on one key feature of your implementation of LastPass: whether SSO is enabled.

SSO enabled:

You're probably ok here, but I would work with LastPass to ensure you can refresh your keys for all users (and thus would re-encrypt all of their respective vaults).

SSO Not Enabled:

This situation mirrors the consumer scenario for the most part, so follow steps 1-3 above. Also, work with LastPass to turn on SSO ASAP. This has the effect of changing the master password for users and re-encrypting the user vaults.

I would also communicate with users to identify any privileged accounts that are in their vaults. While all passwords should be changed, you want your threat teams to be tracking accounts that may be at particular risk of additional damage in the enterprise.

Change vendors? I won't weigh in here. There are good arguments to be made in both directions but that isn't the purpose of this article. This is triage to manage your immediate risk. I hope it helped.

Mike Bruno

SDE II at PKI Solutions

2 年

Do you see LastPass recovering from this?

回复

要查看或添加评论,请登录

Lance Peterman, CIDPRO的更多文章

  • Consider Another Job - Poll Work

    Consider Another Job - Poll Work

    So, this is partially a jobs post and part PSA: consider volunteering to work your local elections. Yesterday was the…

    1 条评论
  • Turning the Page with IDPro

    Turning the Page with IDPro

    If you’re a member of IDPro, you already know part of this story, at least the professional version. Today marks the…

    9 条评论

社区洞察

其他会员也浏览了