由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
Hardware版 - lastpass被黑了,用的人赶紧去改密码吧 (转载)
相关主题
roboform不兼容fx4.0啊 怎么办问题请教: Drivelock Multibay Password
硬盘加密问题求助 asus wl-520gu 设置问题??
大家用Firefox的LastPass Add-on吗?问个IBM x60, embedded security chip password的问题 (转载)
DSM 6.1 released开机管理密码忘了,寻高手指点
John McAfee to Apple (转载)求救: Virtualbox Win Server 03 Adm Password
高手help!!Windows XP Professional default Administrator password是什么?
Intel新出的34nmSSD暂时不要买了unlock external hard drive
请问如何RESET 那个WINDOWS XP 的LOGON?请教,如何确定ROUTER password for ASUS WL-520GU
相关话题的讨论汇总
话题: lastpass话题: password话题: users话题: passwords话题: hackers
进入Hardware版参与讨论
1 (共1页)
l****z
发帖数: 29846
1
【 以下文字转载自 USANews 讨论区 】
发信人: lczlcz (lcz), 信区: USANews
标 题: lastpass被黑了,用的人赶紧去改密码吧
发信站: BBS 未名空间站 (Mon Jun 15 19:09:40 2015, 美东)
One of the most popular password security companies just admitted it was
hacked
Cale Guthrie Weissman
Jun. 15, 2015, 3:27 PM
LastPass, a popular password manager program, just admitted it's been hacked.
In a blog post published today, LastPass’s Joe Siegrist writes, "The
investigation has shown ... that LastPass account email addresses, password
reminders, server per user salts, and authentication hashes were compromised
."
LastPass works by having users choose one strong master password that they
must remember. When they log into LastPass, they use this strong
authenticator to gain access to a list of all of their other passwords,
which are stored in encrypted form on LastPass' servers.
LastPass’ servers do hold a list of all of its users passwords, but because
they are encrypted (meaning they are heavily ciphered making it nearly
impossible to crack), it's highly unlikely any hackers would be able to
decrypt LastPass' password trove.
Further, the encryption and decryption happens on the users' devices,
meaning that LastPass has no way to access any of its users' non-ciphered
passwords.
It's important to note that this breach does not mean that hackers have full
access to the passwords of every LastPass user. What it does mean, however,
is that if users use a weak master password or have used the same password
for another website, there’s a likelihood that hackers could gain access.
To fix this, all LastPass users should change their master password if it is
weak. Also, users should implement multi factor authentication, making it
even harder for hackers to gain access.
Users, however, need not have need to change the passwords stored in
LastPass.
R*R
发帖数: 2661
2
这个没办法。自己把自己的密码放在别人的服务器上,被hack是早晚的事。
x****0
发帖数: 902
3
任何一个这样的服务都是吸引hacker的磁铁。。。

【在 R*R 的大作中提到】
: 这个没办法。自己把自己的密码放在别人的服务器上,被hack是早晚的事。
k**o
发帖数: 15334
4
LastPass其实无所谓,都是自动生成的strong password,丢了也crack不了。
g*******t
发帖数: 7704
5
太恐怖了,
m******c
发帖数: 830
6
不用担心。HACKER破解不了密码。
e*****r
发帖数: 700
7
I use 2 steps authorization. no big deal.
1 (共1页)
进入Hardware版参与讨论
相关主题
请教,如何确定ROUTER password for ASUS WL-520GUJohn McAfee to Apple (转载)
联想笔记本FireFox内存泄漏高手help!!
pccntmon.exe 上载流量很大, 是病毒么?Intel新出的34nmSSD暂时不要买了
牛奶打翻到键盘上了 :(请问如何RESET 那个WINDOWS XP 的LOGON?
roboform不兼容fx4.0啊 怎么办问题请教: Drivelock Multibay Password
硬盘加密问题求助 asus wl-520gu 设置问题??
大家用Firefox的LastPass Add-on吗?问个IBM x60, embedded security chip password的问题 (转载)
DSM 6.1 released开机管理密码忘了,寻高手指点
相关话题的讨论汇总
话题: lastpass话题: password话题: users话题: passwords话题: hackers