You dont have javascript enabled! Please enable it!
  • Tech News
    Nothing introduces Ear (2) wireless earbuds for RM599

    Nothing introduces Ear (2) wireless earbuds for RM599

    Inside WomHub’s creative space for female founders in Cape town

    Inside WomHub’s creative space for female founders in Cape town

    Factor[e] Ventures launches Africa-focused venture studio

    Factor[e] Ventures launches Africa-focused venture studio

    Registering to file tax returns with the LIRS eTax platform

    Registering to file tax returns with the LIRS eTax platform

  • Reviews
    TechEngage®

    An ambitious phone with Wild Camera & tricks

    TechEngage®

    Google Pixel 3 Review: Consistently Unbeatable Camera Lord

    TechEngage®

    Pocophone F1 review: “Flagship Killer” killer?

    Slim, Slick & Economically Premium

    Slim, Slick & Economically Premium

    TechEngage®

    NVIDIA’s Quadro RTX 4000 GPU to be a $900 graphics beast

    TechEngage®

    Xiaomi Mi 8 Pro review; Should we still go for Mi 8?

  • Noteworthy
    TechEngage®

    Russia to briefly “turn off” country’s Internet entry. But why?

    TechEngage®

    Sprint announces first solid plans to unveil 5G infrastructure at MWC19

    Drunk shopping could be a $45 billion industry

    Drunk shopping could be a $45 billion industry

    TechEngage®

    The advantages and benefits of electronic signature

    TechEngage®

    Father of “cut, copy, and paste” Larry Tesler, dies at 74

    TechEngage®

    How the use of modern technology is messing up our sleep

  • Science
    • All
    • Energy
    • Environment
    • Health
    • Space
    TechEngage®

    Asthma and technological innovations for treating it

    Virtual Healthcare; A revolution in medical technology

    Virtual Healthcare; A revolution in medical technology

    Revolutionizing Healthcare Management; Virtual Nurse

    Revolutionizing Healthcare Administration; Virtual Nurse

    TechEngage®

    Biotechnology 2018 trends that are a complete knockout

  • Opinions
    TechEngage®

    Fundamentals of Wealth Creation for Better Outcomes

    TechEngage®

    Change; The only Constant in this World

    TechEngage®

    Proactive & Reactive being two extremes of different worlds

    TechEngage®

    Walmart suffered cases of gender discrimination

    TechEngage®

    How Digital Education features; its Pros and Cons

    TechEngage®

    Impact of Violent Video Games on Youth

  • Applications
    TechEngage®

    Google Play Pass will give access to paid apps

    TechEngage®

    Quizlet reaches 50 Million Users milestone

    TechEngage®

    Eradicate Gender Inequality through Crowd mapping!

    TechEngage®

    How mobile phone apps can help pregnant women

    TechEngage®

    Apple News app will be broadcasting live election results

    TechEngage®

    TikTok becomes the most downloaded app on the App Store

  • Blockchain
    TechEngage®

    Common mistakes new crypto investors make

    TechEngage®

    Microsoft launches Azure Blockchain Dev Kit

    TechEngage®

    The mystery behind Twitter Bitcoin scams has been solved

    TechEngage®

    Make-A-Wish website hit with the cryptojacking plight

    Two-million-year-old DNA, oldest ever found, opens window to Greenland's past

    Two-million-year-old DNA, oldest ever found, opens window to Greenland’s past

    This Chinese electric car giant will produce in Europe and that could change a lot of things

    This Chinese electric car giant will produce in Europe and that could change a lot of things

  • Applications
    TechEngage®

    Google Play Pass will give access to paid apps

    TechEngage®

    Quizlet reaches 50 Million Users milestone

    TechEngage®

    Eradicate Gender Inequality through Crowd mapping!

    TechEngage®

    How mobile phone apps can help pregnant women

  • Culture
    Two-million-year-old DNA, oldest ever found, opens window to Greenland's past

    Two-million-year-old DNA, oldest ever found, opens window to Greenland’s past

    This Chinese electric car giant will produce in Europe and that could change a lot of things

    This Chinese electric car giant will produce in Europe and that could change a lot of things

  • Deals
    TechEngage®

    Save $400 on Apple’s last-gen 14″ MacE book Pro and new Mac Mini 2023

    TechEngage®

    New York Times joins with Scribd to offer an economical subscription bundle

    TechEngage®

    Motorola puts up some scary good deals for Halloween

    TechEngage®

    Lavender version of Samsung Galaxy Note 9 will be $140 off

  • Events
    TechEngage®

    Nokia to launch new smartphones on April 8th

    TechEngage®

    What to expect from Samsung Galaxy Unpacked event

    TechEngage®

    What to expect from the OnePlus 9 launch event

    TechEngage®

    What to expect from Apple’s WWDC21 event

  • How-to
    Two-million-year-old DNA, oldest ever found, opens window to Greenland's past

    Two-million-year-old DNA, oldest ever found, opens window to Greenland’s past

    This Chinese electric car giant will produce in Europe and that could change a lot of things

    This Chinese electric car giant will produce in Europe and that could change a lot of things

  • Roundups
    TechEngage®

    10 Best iPhone Wallpaper Apps 2023

    TechEngage®

    Best iPhone 12, 12 Pro Wallet Cases in 2023

    TechEngage®

    10 Best Wallpaper Apps for Mac in 2023

    TechEngage®

    Best Android Launchers of 2023

  • Startups
    Two-million-year-old DNA, oldest ever found, opens window to Greenland's past

    Two-million-year-old DNA, oldest ever found, opens window to Greenland’s past

    This Chinese electric car giant will produce in Europe and that could change a lot of things

    This Chinese electric car giant will produce in Europe and that could change a lot of things

    Techabout Banner

    TechAbout: A venture that adds life to your dreams

    Avatar Of Nur

    These 5 Startups Will Change the Future of Health-tech

Thursday, March 23, 2023
Tech News, Magazine & Review WordPress Theme 2017
No Result
View All Result
  • Tech News
    Nothing introduces Ear (2) wireless earbuds for RM599

    Nothing introduces Ear (2) wireless earbuds for RM599

    Inside WomHub’s creative space for female founders in Cape town

    Inside WomHub’s creative space for female founders in Cape town

    Factor[e] Ventures launches Africa-focused venture studio

    Factor[e] Ventures launches Africa-focused venture studio

    Registering to file tax returns with the LIRS eTax platform

    Registering to file tax returns with the LIRS eTax platform

  • Reviews
    TechEngage®

    An ambitious phone with Wild Camera & tricks

    TechEngage®

    Google Pixel 3 Review: Consistently Unbeatable Camera Lord

    TechEngage®

    Pocophone F1 review: “Flagship Killer” killer?

    Slim, Slick & Economically Premium

    Slim, Slick & Economically Premium

    TechEngage®

    NVIDIA’s Quadro RTX 4000 GPU to be a $900 graphics beast

    TechEngage®

    Xiaomi Mi 8 Pro review; Should we still go for Mi 8?

  • Noteworthy
    TechEngage®

    Russia to briefly “turn off” country’s Internet entry. But why?

    TechEngage®

    Sprint announces first solid plans to unveil 5G infrastructure at MWC19

    Drunk shopping could be a $45 billion industry

    Drunk shopping could be a $45 billion industry

    TechEngage®

    The advantages and benefits of electronic signature

    TechEngage®

    Father of “cut, copy, and paste” Larry Tesler, dies at 74

    TechEngage®

    How the use of modern technology is messing up our sleep

  • Science
    • All
    • Energy
    • Environment
    • Health
    • Space
    TechEngage®

    Asthma and technological innovations for treating it

    Virtual Healthcare; A revolution in medical technology

    Virtual Healthcare; A revolution in medical technology

    Revolutionizing Healthcare Management; Virtual Nurse

    Revolutionizing Healthcare Administration; Virtual Nurse

    TechEngage®

    Biotechnology 2018 trends that are a complete knockout

  • Opinions
    TechEngage®

    Fundamentals of Wealth Creation for Better Outcomes

    TechEngage®

    Change; The only Constant in this World

    TechEngage®

    Proactive & Reactive being two extremes of different worlds

    TechEngage®

    Walmart suffered cases of gender discrimination

    TechEngage®

    How Digital Education features; its Pros and Cons

    TechEngage®

    Impact of Violent Video Games on Youth

  • Applications
    TechEngage®

    Google Play Pass will give access to paid apps

    TechEngage®

    Quizlet reaches 50 Million Users milestone

    TechEngage®

    Eradicate Gender Inequality through Crowd mapping!

    TechEngage®

    How mobile phone apps can help pregnant women

    TechEngage®

    Apple News app will be broadcasting live election results

    TechEngage®

    TikTok becomes the most downloaded app on the App Store

  • Blockchain
    TechEngage®

    Common mistakes new crypto investors make

    TechEngage®

    Microsoft launches Azure Blockchain Dev Kit

    TechEngage®

    The mystery behind Twitter Bitcoin scams has been solved

    TechEngage®

    Make-A-Wish website hit with the cryptojacking plight

    Two-million-year-old DNA, oldest ever found, opens window to Greenland's past

    Two-million-year-old DNA, oldest ever found, opens window to Greenland’s past

    This Chinese electric car giant will produce in Europe and that could change a lot of things

    This Chinese electric car giant will produce in Europe and that could change a lot of things

  • Applications
    TechEngage®

    Google Play Pass will give access to paid apps

    TechEngage®

    Quizlet reaches 50 Million Users milestone

    TechEngage®

    Eradicate Gender Inequality through Crowd mapping!

    TechEngage®

    How mobile phone apps can help pregnant women

  • Culture
    Two-million-year-old DNA, oldest ever found, opens window to Greenland's past

    Two-million-year-old DNA, oldest ever found, opens window to Greenland’s past

    This Chinese electric car giant will produce in Europe and that could change a lot of things

    This Chinese electric car giant will produce in Europe and that could change a lot of things

  • Deals
    TechEngage®

    Save $400 on Apple’s last-gen 14″ MacE book Pro and new Mac Mini 2023

    TechEngage®

    New York Times joins with Scribd to offer an economical subscription bundle

    TechEngage®

    Motorola puts up some scary good deals for Halloween

    TechEngage®

    Lavender version of Samsung Galaxy Note 9 will be $140 off

  • Events
    TechEngage®

    Nokia to launch new smartphones on April 8th

    TechEngage®

    What to expect from Samsung Galaxy Unpacked event

    TechEngage®

    What to expect from the OnePlus 9 launch event

    TechEngage®

    What to expect from Apple’s WWDC21 event

  • How-to
    Two-million-year-old DNA, oldest ever found, opens window to Greenland's past

    Two-million-year-old DNA, oldest ever found, opens window to Greenland’s past

    This Chinese electric car giant will produce in Europe and that could change a lot of things

    This Chinese electric car giant will produce in Europe and that could change a lot of things

  • Roundups
    TechEngage®

    10 Best iPhone Wallpaper Apps 2023

    TechEngage®

    Best iPhone 12, 12 Pro Wallet Cases in 2023

    TechEngage®

    10 Best Wallpaper Apps for Mac in 2023

    TechEngage®

    Best Android Launchers of 2023

  • Startups
    Two-million-year-old DNA, oldest ever found, opens window to Greenland's past

    Two-million-year-old DNA, oldest ever found, opens window to Greenland’s past

    This Chinese electric car giant will produce in Europe and that could change a lot of things

    This Chinese electric car giant will produce in Europe and that could change a lot of things

    Techabout Banner

    TechAbout: A venture that adds life to your dreams

    Avatar Of Nur

    These 5 Startups Will Change the Future of Health-tech

No Result
View All Result
Tech News
No Result
View All Result

LastPass security attacked by rival company 1Password: ‘Passwords could be cracked for $100’

December 30, 2022
in Tech News
Home Tech News

Our mission is to provide unbiased product reviews and timely reporting of technological advancements. Covering all latest reviews and advances in the technology industry, our editorial team strives to make every click count. We aim to provide fair and unbiased information about the latest technological advances.
Share on FacebookShare on Twitter

The LastPass security breach controversy continues. After an independent security analyst described statements made by LastPass as “half-truths and outright lies,” rival password management company 1Password has also weighed in …

LastPass claimed that cracking users’ master passwords would take millions of years, but 1Password says that this isn’t true for most users. Indeed, it says, it would cost just $100 to crack the master password of a typical LastPass user.

Background

A LastPass security breach was revealed back in August. At the time, the company said that no customer data was accessed.

Two weeks ago, we detected some unusual activity within portions of the LastPass development environment. After initiating an immediate investigation, we have seen no evidence that this incident involved any access to customer data or encrypted password vaults.

Instead, said LastPass, an attacker took part of its source code and “some proprietary LastPass technical information.”

However, it subsequently emerged that the attacker then used this information to gain wider access to LastPass systems, and was then able to access customer data.

We have determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information.

LastPass last week revealed the extent of that data – and it was far worse than had been suspected.

The company has shared that copies of customers’ password vaults were obtained along with names, emails, billing addresses, phone numbers, and more.

The company went to great pains to point out that the password vaults used strong encryption, and could not be accessed without customers’ master passwords.

These encrypted fields remain secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user’s master password using our Zero Knowledge architecture. As a reminder, the master password is never known to LastPass and is not stored or maintained by LastPass.

However, independent security analyst Wladimir Palant this week took issue with no fewer than 14 of the claims made by LastPass, describing them as “full of omissions, half-truths and outright lies.”

See also  Alibaba to Donate $18.4M to Equip Chinese Villages With Oximeters

In particular, he said it wasn’t true that it would take “millions of years” to crack master passwords and get access to all of a customer’s logins. He estimated that the actual time needed for a targeted attack would be around two months.

LastPass security attacked by 1Password

1Password’s principal security architect Jeffrey Goldberg says in a blog post that even this over-estimates the difficulty – and says that if someone wanted to crack a typical LastPass customer’s master password, the process would cost only around $100.

Goldberg uses the same reasoning as Palant: real-life master passwords for most users are not random – and password crackers know this.

The cracking systems will try things like Fido8my2Sox! and 2b||!2b.titq long before they try things like the machine created [email protected]*7eL .

Passwords created by humans are crackable even if they meet various complexity requirements. So if you (or another human) created that 12-character password, it doesn’t matter if there are 272 different possible 12-character passwords. What matters is whether yours is going to be among the few billion that attackers try first. 

He says that most passwords can be cracked in fewer than 10 billion guesses, and that this could be done for around $100.

1Password master passwords cannot be brute-forced

Goldberg says that with LastPass, the user’s master password is the only thing needed to access all their logins – but this is not true of 1Password, which combines a user-selected master password with a machine-derived secret key. Both are needed to access a user’s password vault.

See also  iOS 16.3 lets you use a physical security key to secure your iPhone

The Secret Key is created on the user’s own device, and never leaves it. The user doesn’t know what it is. 1Password doesn’t know what it is. An earlier blog post explaining how it works uses the example of a hypothetical user Molly, who uses a weak master password.

Molly’s 128-bit Secret Key gets combined with her rather weak password on her own machine. It’s secret from us and our servers. Recall that no secrets are transmitted from Molly’s 1Password client to our servers when Molly signs into her account. It isn’t merely that we never store her Secret Key – we never even have the opportunity to acquire it.

This is similar in concept to how Apple Pay works. Your iPhone or Apple Watch tells the payment terminal that it has verified your identity on the device.

The Verge notes that LastPass hasn’t even required longer-standing users to update their passwords from the early days when security requirements were far lower. Additionally, the plain-text information stored by LastPass could itself prove risky to users – including the URLs of the websites they visit.

What if you used LastPass to store your account info for a niche porn site? Could someone figure out what area you live in based on your utility provider accounts? Would the info that you use a gay dating app put your freedom or life in danger?

9to5Mac’s Take

It’s clear that the LastPass security breach was not only far worse than initially revealed, but that the company engages in a number of practices I would personally consider unacceptable. These include storing a great deal of personal data in plain text, and making misleading statements about their security – such as suggesting that 100,000 PBKDF2 iterations is “stronger than typical” when it is, in fact, the absolute minimum standard that could be considered secure.

See also  The 1 major security precaution you should always enable on a new PC

1Password clearly has a financial interest in attacking its rival. However, the arguments made by the company are sound – especially when it comes to comparing a standalone master password versus the Secret Key approach. It’s similar to the way that iOS doesn’t ever actually know your passcode, or your Face ID data – it simply gets a yes or no response from the Secure Enclave.

Based on what we now know, I would not consider LastPass as a password manager. (And yes, I use 1Password, but pay full price for it just like any other user.)

Fortunately, passwords as a concept are finally on their way out, being replaced by passkeys. This relies entirely on on-device authentication, as we’ve previously explained.

  • A website or app asks you to identify yourself, and prove your identity.
  • Your iPhone receives that request, and activates Face ID.
  • If your face matches, your iPhone tells the website who you are,

    and that it has confirmed your identity.

FTC: We use income earning auto affiliate links. More.


Check out 9to5Mac on YouTube for more Apple news:

ADVERTISEMENT

…. to be continued
Read the Original Article
Copyright for syndicated content belongs to the linked Source : 9to5Mac – https://9to5mac.com/2022/12/29/lastpass-security-latest/

Tags: LastPassSecurity

Denial of responsibility! tech-news.info is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.
Previous Post

iPhone 14 Pro display longevity concerned Apple, but precautions were taken

Next Post

3D Touch was a better iPhone feature than Dynamic Island

RelatedPosts

Nothing introduces Ear (2) wireless earbuds for RM599
Tech News

Nothing introduces Ear (2) wireless earbuds for RM599

March 23, 2023
Inside WomHub’s creative space for female founders in Cape town
Tech News

Inside WomHub’s creative space for female founders in Cape town

March 23, 2023
Factor[e] Ventures launches Africa-focused venture studio
Tech News

Factor[e] Ventures launches Africa-focused venture studio

March 23, 2023
Registering to file tax returns with the LIRS eTax platform
Tech News

Registering to file tax returns with the LIRS eTax platform

March 23, 2023

Recommended.

  • All
  • Tech News
Nothing introduces Ear (2) wireless earbuds for RM599

Nothing introduces Ear (2) wireless earbuds for RM599

March 23, 2023
Inside WomHub’s creative space for female founders in Cape town

Inside WomHub’s creative space for female founders in Cape town

March 23, 2023
Factor[e] Ventures launches Africa-focused venture studio

Factor[e] Ventures launches Africa-focused venture studio

March 23, 2023
Registering to file tax returns with the LIRS eTax platform

Registering to file tax returns with the LIRS eTax platform

March 23, 2023
STELLAR WORKS and SONY PRESENT ‘STAYDREAM – A SURREAL REALITY’ FOR NYCxDESIGN 2023

STELLAR WORKS and SONY PRESENT ‘STAYDREAM – A SURREAL REALITY’ FOR NYCxDESIGN 2023

March 23, 2023
Oppo Find X6 Pro With Snapdragon 8 Gen 2 SoC, Hasselblad Cameras Announced

Oppo Find X6 Pro With Snapdragon 8 Gen 2 SoC, Hasselblad Cameras Announced

March 23, 2023

Tags

-Inch (41)amazon (78)Android (62)Announces (34)Apple (234)Apples (41)Black (44)ChatGPT (43)Chinese (62)Cyber (45)Deals (60)Digital (37)First (46)Friday (36)Galaxy (176)Gaming (59)Google (176)Heres (53)iPhone (99)Launch (56)launches (59)Lenovo (40)Microsoft (102)Motorola (33)NVIDIA (30)OnePlus (119)Phone (39)Pixel (54)price (30)Realme (62)Redmi (50)Review (98)Samsung (234)Security (32)series (40)Snapdragon (30)Tech News (363)Tesla (47)Twitter (78)unveils (37)Watch (69)Weekly (35)Windows (41)Xiaomi (99)YouTube (29)

Categories

Archives

March 2023
MTWTFSS
 12345
6789101112
13141516171819
20212223242526
2728293031 
« Feb  
© 2022 Tech-News.info
DMCA.com Protection Status
No Result
View All Result
  • Home 2

© 2022 Tech-News.info
DMCA.com Protection Status

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
error: Alert: Content selection is disabled!!
Go to mobile version

LastPass security attacked by rival company 1Password: ‘Passwords could be cracked for $100’