lasspass Security Notification
Have you seen this? http://blog.lastpass.com/2011/05/lastpass-security-notification.html In looking at the DNS query logs, I see multiple queries yesterday from 140.221.8.88 for lastpass.com between 11:12 and 16:30. Don't know who the user may be or how important it is, but..
In this case, we couldn't find that root cause. After delving into the anomaly we found a similar but smaller matching traffic anomaly from one of our databases in the opposite direction (more traffic was sent from the database compared to what was received on the server). Because we can't account for this anomaly either, we're going to be paranoid and assume the worst: that the data we stored in the database was somehow accessed. We know roughly the amount of data transfered and that it's big enough to have transfered people's email addresses, the server salt and their salted password hashes from the database. We also know that the amount of data taken isn't remotely enough to have pulled many users encrypted data blobs.
If you have a strong, non-dictionary based password or pass phrase, this shouldn't impact you - the potential threat here is brute forcing your master password using dictionary words, then going to LastPass with that password to get your data. Unfortunately not everyone picks a master password that's immune to brute forcing.
Ouch...
participants (1)
-
rackow@anl.gov