LastPass Got Breached and Im Not Panicking

LastPass Got Breached and Im Not Panicking

Tech News data breach lastpass password-managers security

Woke up Monday morning, checked my usual feeds over coffee, and there it was: LastPass posted on their blog that theyd detected "suspicious activity" on their network back on Friday, June 12th, and by June 15th theyd confirmed someone got in. Email addresses, password reminders, server per-user salts, and authentication hashes all got grabbed. The actual encrypted vaults with your real passwords in them? Those, they say, werent touched.

Ive been using LastPass since, honestly I dont remember exactly, sometime around 2012, back when I got tired of reusing the same three passwords for every site with a number appended when they made me add one. Ive paid the $12 a year for Premium since it let me sync to my phone, which back then felt like a genuinely useful thing to pay for instead of a subscription-model afterthought.

So my first reaction wasnt panic, it was mild annoyance that I was going to have to type out my main password on four different devices later that day. Which I did. Took maybe ten minutes total, changing the master password on desktop, then re-entering it on my phone and my work laptop and the browser extension on this ancient netbook I keep around for no reason I can fully explain.

Heres the thing that actually matters about how LastPass is built, and its worth explaining because I dont think most people get it: your master password never leaves your computer. It gets hashed locally before it even reaches their servers, so even if someone steals the authentication hash off their servers, which is apparently what happened here, they still cant open your vault without your actual master password, which they never had in the first place. Thats the whole point of the architecture. If your master password was something dumb like "spring2015" then sure, be worried, somebody could brute-force that eventually. If it was reasonably long and not a dictionary word, youre probably fine.

Doesnt mean Im thrilled about it. A breach is a breach, and "we think the important stuff is safe" is exactly the sentence every company says right up until it isnt true. But I ran the math here: the alternative to a password manager is what, exactly? My uncle keeps his passwords in a Notes app with zero encryption, synced to iCloud, titled literally "passwords." My coworker (name changed, he doesnt read this, probably) reuses one password across something like forty sites including his bank. A breach where the worst case is "rotate your master password and turn on two-factor" is a pretty good outcome compared to either of those setups.

I did turn on two-factor through Google Authenticator while I was in there anyway, which Id been meaning to do since I first set this up and just never got around to, the way you never get around to flossing more than the week before a dentist appointment.

What I do wish is that theyd been faster getting the actual details out. The blog post is light on specifics, how many accounts were affected, what "suspicious activity" even means in practice. I get that theres a legal reason companies write these posts the way lawyers want them written. Doesnt make it less annoying to read three paragraphs of hedge-everything corporate blog voice when what I actually want is one clear sentence: heres what happened, heres what you should do.

I know a few people already jumping to "this is why I just use the same password everywhere, at least I only have one thing to remember," which is exactly backwards, and I will die on this hill. One compromised site with a reused password means every site is compromised. One compromised password manager, built the way this one is, means you change one password and youre done. Its not close.

Anyway. New master password is in, two-factor is on, and Im not going anywhere. If this had happened to Dropbox or Evernote Id probably feel about the same. At some point you decide whether you trust the architecture of a thing or you dont, and I still trust this one. Ask me again if it happens twice in the same year.