gregmcc
Honorary Master
http://thenextweb.com/apps/2011/05/...acked-users-urged-to-change-master-passwords/
Free password management program LastPass, a browser extension that manages passwords and automates form filling, has been subjected to an external attack which could see user email addresses, their server salt and salted password hashes stolen by attackers.
Users with a “strong, non-dictionary based password or pass phrase” should not be affected, LastPass believes that to gain access to passwords, attackers will need to brute-force its user’s master passwords to gain access to user data.
LastPass urges all of its users to change their passwords to counter the threat and has brought into place an additional level of security to identify if the user is accessing the site from an IP address they have used before, also requiring email address to be validated. The company believes this could fox potential attackers if the access masters passwords, as they would not have access to a user’s email account or IP address.