Latest info on LastPass data breach

Anyone that had a weak master password should be shting themselves right now but the only consolation is if they try a brute force attack they won’t know upfront which accounts have weak passwords so hopefully first getting a few accounts with insane passwords will put them off.

How easy would it be to brute force crack a 12 character simple password?
By simple I mean it doesn’t have many weird characters or the stuff that define a “difficult” to crack password.
 
Why is 1Password better and is it free?
The general UX, the speed of cross-platform syncing, the speed with which the mobile app can fill in fields, the way it creates new logins for sites when you click in the password field, the way multiple accounts work together, the ease of creating 2FA one-time codes within 1Password and all sorts of subtle things that made the quality of the product so easy to appreciate. It feels like a paid product.

Why does it need to be free? Nothing wrong with paying a few bucks per year for something as essential as a password manager. Heck, I'd be concerned at a thing like that being free unless it was a first party solution like Keychain. Even when I used Bitwarden for several years, I had a premium subscription to support its development.
 
The general UX, the speed of cross-platform syncing, the speed with which the mobile app can fill in fields, the way it creates new logins for sites when you click in the password field, the way multiple accounts work together, the ease of creating 2FA one-time codes within 1Password and all sorts of subtle things that made the quality of the product so easy to appreciate. It feels like a paid product.

Why does it need to be free? Nothing wrong with paying a few bucks per year for something as essential as a password manager. Heck, I'd be concerned at a thing like that being free unless it was a first party solution like Keychain. Even when I used Bitwarden for several years, I had a premium subscription to support its development.

I don’t mind paying but not R600 odd pa.
 
Anyone that had a weak master password should be shting themselves right now but the only consolation is if they try a brute force attack they won’t know upfront which accounts have weak passwords so hopefully first getting a few accounts with insane passwords will put them off.

How easy would it be to brute force crack a 12 character simple password?
By simple I mean it doesn’t have many weird characters or the stuff that define a “difficult” to crack password.

Seriously long, like hundreds of years. Honestly it would be better to wait 20 years for technology to get better and than start.

A simple password with 12 chars, a upper case and a special symbol with take over 100 years probably more to crack.

You need to know who the person is then you can refine your criteria for brute forcing a password.

This breach will be like any other email breach where your email will be available on a list for spam/phishing attack.
 
I am so pissed. I have been using LastPass (paying) for such a long time , that I think it has to be more than 10 years.

I had increased all my security settings to the max when I was setting it up all those years ago. I made a few further changes when they allowed it ,like 2FA. However, the verge article talked about default password iterations being 100100. Guess what mines was , 20000!! That was the max I could set when I started with them, so even when they increased the default they never bothered to update their customers settings or tell us to do so.

I do have 2FA on all my important accounts, and my master password is 20 chars so I am hoping I am still protected but nearly done with migration to 1password. Resetting all email, financial and social to new passwords is so fscking time consuming ( my main email account has shown loads of unsuccessful logons on 22/12 from at least 20 countries - it's been relentless how much they have been trying - maybe not tied to LastPass)

Only thing I am worried about is I stored all passport , bank cards and legal documents in the vault and that info you can never change. Not to mention some service accounts for work.
 
I've also been using Lastpass for the last 10 + years.
My master-password was 26 characters long, so hopefully secure enough for a while.

Did go over to Bitwarden for $10 p/a .

To be on the safe side I basically changed all my passwords via Bitwarden.

A huge mission but at least I'm feeling safer.

Also ordered a Yubikey to keep my master-password offline and more secure.
 
I've also been using Lastpass for the last 10 + years.
My master-password was 26 characters long, so hopefully secure enough for a while.

Did go over to Bitwarden for $10 p/a .

To be on the safe side I basically changed all my passwords via Bitwarden.

A huge mission but at least I'm feeling safer.

Also ordered a Yubikey to keep my master-password offline and more secure.

How did you remember a 26 character password?

If for instance you had remembered a 10 digit password and just typed it twice to make it a 20 digit password how crackable would that 2 x 10 digit password be vs a natively 20 digit password?
 
How secure is Google password manager built into chrome
 
Top
Sign up to the MyBroadband newsletter
X