weirdwriter, to tech
gtbarry, to security
@gtbarry@mastodon.social avatar

LastPass users targeted in phishing attacks good enough to trick even the savvy

Password-manager LastPass users were recently targeted by a convincing phishing campaign that used a combination of email, SMS, and voice calls to trick targets into divulging their master passwords

https://arstechnica.com/security/2024/04/lastpass-users-targeted-in-phishing-attacks-good-enough-to-trick-even-the-savvy/

jeff, to random
@jeff@soapbox.hackdefendr.com avatar

So?

Does everyone remember ?

Welp!?

It happened again, but this time on the user side of the house. LastPass users targeted by attackers.

VISHING: the fraudulent practice of making phone calls or leaving voice messages purporting to be from reputable companies in order to induce individuals to reveal personal information, such as bank details and credit card numbers.

https://www.helpnetsecurity.com/2024/04/19/lastpass-vishing/

kubikpixel, to random German
@kubikpixel@chaos.social avatar

Ich hoffe, das Passkeys diesbezüglich nicht betroffen ist so wie Passwort-Manager wie @keepassxc, @bitwarden inklusive 2FA schon einen grösseren Schutz gegenüber der KI ergibt.

»GPT-4 kann eigenständig bekannte Sicherheitslücken ausnutzen:
Forscher haben festgestellt, dass GPT-4 allein anhand der zugehörigen Schwachstellenbeschreibungen 13 von 15 Sicherheitslücken erfolgreich ausnutzen kann.«

🤖 https://www.golem.de/news/mit-cve-beschreibung-gpt-4-kann-eigenstaendig-bekannte-sicherheitsluecken-ausnutzen-2404-184301.html


kubikpixel,
@kubikpixel@chaos.social avatar

🧵 …und nicht nur die vorhin erwähnten Tools nützen als Schutz diesbezüglich, sondern auch das nicht herein fallen gegenüber den "helfende Profis":

[ENG]
«LastPass users targeted in phishing attacks good enough to trick even the savvy:
Campaign used email, SMS, and voice calls to trick targets into divulging master passwords.»

🔓 https://arstechnica.com/security/2024/04/lastpass-users-targeted-in-phishing-attacks-good-enough-to-trick-even-the-savvy/


#passwort #keepass #lastpass #phishing #email #sms #masterpasswort #itsec #password #MasterPasswords #itsecurity

arstechnica, to random
@arstechnica@mastodon.social avatar

LastPass users targeted in phishing attacks good enough to trick even the savvy

Campaign used email, SMS, and voice calls to trick targets into divulging master passwords.

https://arstechnica.com/security/2024/04/lastpass-users-targeted-in-phishing-attacks-good-enough-to-trick-even-the-savvy/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

dustcircle,
@dustcircle@mastodon.social avatar

@arstechnica Can never bring myself to use .
I use . FREE and SECURE

Uraael, to random

Lastpass: The Last Password You'll Ever Trust.

lsdm, to email French
@lsdm@mamot.fr avatar

Cette nouvelle cyberattaque montre qu’il ne faut surtout pas recycler ses mots de passe.

De nombreux internautes continuent d’utiliser un même mot de passe pour sécuriser tous leurs comptes en ligne.

https://lsdm.live/modules/news/article.php?storyid=5032

redhotcyber, to IT Italian
@redhotcyber@mastodon.bida.im avatar
davidshq, to random
@davidshq@hachyderm.io avatar

I canceled premium years ago (while they were part of ), then they spun off or something and guess what - my premium subscription was reinstated 😡

I've successfully had the charges refunded by my CC at least 2 years now and the charge appeared again for this year.

I signed into LastPass and sure enough, a premium subscription was again associated with my account. I canceled it - again.

Did LastPass send me a cancellation confirmation email? No. Is there a way for me to

1/2

davidshq,
@davidshq@hachyderm.io avatar

2/2

prove I canceled it again? Not that I see.

Am I going to try and get a refund of premium this year? No. Does that mean I'm acknowledging that I made the purchase? Hell no. It's simply that #lastpass makes it a real pain to get a refund from them and the #creditcard companies don't make it much easier. I'd spend more "money" in time than I'd get back from disputing.

But...anyone know a good class action #lawyer if this happens next year? 🤬

GavinChait, to random
@GavinChait@wandering.shop avatar

Follow along with me on my adventures.

In 2021 I cancelled my subscription & migrated. I deliberately, & carefully, deleted my credit card information & all passwords from the account. I received email acknowledgement, & then I forgot about it.

That was a mistake.

Turns out, they continued to charge me. Every year. Even increased the fee.

governa, to firefox
@governa@fosstodon.org avatar

deleted_by_author

  • Loading...
  • islamicaudiobooks,
    @islamicaudiobooks@mastodon.social avatar

    @governa Recommends password manager... enough said.

    YourAnonRiots, to AdobePhotoshop Japanese
    @YourAnonRiots@mstdn.social avatar

    Users should be vigilant when downloading any app, even from vetted app stores.
    Read more: https://cnews.link/fake-lastpass-app-apple-cybernews/

    ilumium, to apple
    @ilumium@eupolicy.social avatar

    Haha while lobbyists are trying to convince the EU Commission that they are the only party in the world capable of running a secure app store, a fraudster uploads a fake app.


    https://arstechnica.com/security/2024/02/a-password-manager-lastpass-calls-fraudulent-booted-from-app-store/

    cybernews, to AdobePhotoshop
    SteveThompson, to apps
    @SteveThompson@mastodon.social avatar

    "A password manager LastPass calls 'fraudulent' booted from App Store"

    https://arstechnica.com/security/2024/02/a-password-manager-lastpass-calls-fraudulent-booted-from-app-store/

    "'LassPass' mimicked the name and logo of real LastPass password manager."

    @apple

    itnewsbot, to security
    @itnewsbot@schleuss.online avatar

    A password manager LastPass calls “fraudulent” booted from App Store - Enlarge (credit: Getty Images)

    As Apple has stepped up its pro... - https://arstechnica.com/?p=2002178

    AAKL, to Cybersecurity
    @AAKL@noc.social avatar
    simplelogin, to random
    @simplelogin@fosstodon.org avatar

    We asked our community at @Reddit when they find hide-my-email aliases most useful.

    Below are some of their tips:
    🧵⬇️ (1/11)

    simplelogin,
    @simplelogin@fosstodon.org avatar

    Replacing your actual email address with an alias also protects you in the case of a .

    Also, don’t use : https://proton.me/blog/is-lastpass-safe

    (3/11)

    soatok, to random
    @soatok@furry.engineer avatar

    What people tell you computer security research is like:

    Matrix
    Hackerman.jpg
    "I'm in"
    "Fuck yeah" etc.

    What it's really like:

    https://soatok.blog/2023/01/21/how-you-respond-to-security-researchers-says-everything-about-you/#lastpass

    WPalant, to random

    “Furthermore, added that it will also start checking new or updated master passwords against a database of credentials previously leaked on the dark web to ensure that they don't match already compromised accounts.”

    Wow, I really hope that they don’t choose the most straightforward approach to implement this feature. Given their security track record they actually might however, and it will be a disaster.

    Unless they implement it as some kind of client-side check, this will weaken master password security massively. Such lookups require unsalted hashes, and sending out your master password like that to any remote party is bad. As in: really bad.

    WPalant, (edited )

    Ok, I checked how the credential monitoring feature works, presumably it will be used for master passwords as well in future. I didn’t bother downloading the current LastPass version at this point, I’m looking at the one from May last year.

    Edit: I previously stated that hashes of passwords were being sent to a LastPass endpoint. I misinterpreted the code here however – it hashes usernames, not passwords. Also not great but far from being the disaster that sending hashed passwords would have been.

    arda, to bitwarden
    @arda@micro.arda.pw avatar

    Farewall Lastpass (premium), it was a rocky ride. I was 2 years late to delete my dormant account anyways.

    I had migrated to self-hosted and dockerized Vaultwarden ( Open source alternative @bitwarden backend ) last year, along with official clients. Loving the overall experience so far!

    Xavier, to random
    keirFox, to random
    @keirFox@furry.engineer avatar

    “Everyone! You need to login to your Dropbox account, go into settings, go into this menu, and disable their new AI trai—“

    Uh-huh. removes all files from Dropbox, deletes account

    I am really done playing these bullshit games with corporations like this.

    renoirb,

    @tailsy @keirFox also, if you used and had its password stored, it’s best to change all your passwords too.

    The breach was something huge. Every vault backup leaked, not everything is encrypted. URL, last visit (at time of breach), if it was auto-generated or not, and a few other fields. That’s really not “zero knowledge” when non zero fields are in the clear.

    It’s a stretch to tell anyone be the target. It’s a non zero chance now that it’s leaked. A matter of time.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • kavyap
  • DreamBathrooms
  • ethstaker
  • magazineikmin
  • InstantRegret
  • modclub
  • Youngstown
  • everett
  • slotface
  • rosin
  • khanakhh
  • ngwrru68w68
  • PowerRangers
  • provamag3
  • thenastyranch
  • Durango
  • cubers
  • normalnudes
  • vwfavf
  • mdbf
  • GTA5RPClips
  • tacticalgear
  • tester
  • Leos
  • osvaldo12
  • cisconetworking
  • megavids
  • All magazines