All the latest UK technology news, reviews and analysis

LastPass acknowledges possible data breach

by Shaun Nichols

05 May 2011

Be the first to comment

  • Tweet this

Password management service LastPass has issued a warning after the discovery of a possible security breach.

The company said that it may have experienced a breach which could have led to the loss of 'master passwords', which customers enter to log-in to the LastPass service.

In an alert published on the company's blog, LastPass said that the issue occurred earlier this week, when it noticed suspicious traffic patterns on its servers.

Analysis of the traffic uncovered a second traffic pattern, which could not be accounted for.

While the exact impact of the incident is unknown, the company is treating it as a breach of its password system.

"We know roughly the amount of data transferred and that it's big enough to have transferred people's email addresses, the server salt and their salted password hashes from the database," LastPass said in the posting.

"We also know that the amount of data taken isn't remotely enough to have pulled many users' encrypted data blobs."

The incident comes at a time when data breaches and account thefts are dominating headlines in the technology world.

Sony is still struggling to recover from a major security breach which has knocked its PlayStation Network service offline for more than two weeks and led to the company being summoned by Congress.

Security expert Brian Krebs argued that LastPass has done a better job of spotting and handling its security breach than Sony.

"LastPass seems to have done a good job designing a secure service, but it looks like it dropped the ball in testing and hardening its internal infrastructure," Krebs wrote in a blog posting.

"Still, its (apparent) transparency about what happened is a refreshing change from the brand of disclosure practised in the wake of other, much larger breaches of late."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

40%

0%

10%

50%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Field Service Engineer - Dublin

The Role: As a Field Service Engineer working from...

Global Technical Support Representative - French Speaker

The Role: Make the most of your IT knowledge in one...

Head of IT / Infrastructure Manager (Marketing Services Group)

Head of IT / Infrastructure Manager (Marketing Services...

Business Development Executive

A Multi-national data analytic's and cloud computing...

To send to more than one email address, simply separate each address with a comma.