← Back to Gadget Pulse US

LastPass Hack Two Years Later: What They Still Aren't Telling You

Persona #4 ยท Vol: 0

When LastPass disclosed its 2022 breach, the company's timeline sounded clean.

An attacker stole source code and technical information in August, then returned in November for customer vault backups.

Case closed, lessons learned, move along.

Except the story never quite added up, and the people who actually understand encryption have been quietly screaming into the void ever since.

Here's the detail that should make every American with a password vault sit up: the stolen backups were protected by a master password and, for some users, default settings that used a shockingly low iteration count.

Iteration count is how many times your master password gets scrambled before it becomes a key.

More rounds means an attacker burns more time cracking it.

For older accounts, that number was set so low that security researchers described brute-forcing it as trivial on modern hardware.

LastPass eventually raised the default, but the damage was already zip-tied and shipped out the door.

The company's response has leaned hard on a comforting phrase: your data is encrypted, so you're fine.

That framing glosses over the fact that encryption is only as strong as the weakest master password in the dump.

If your master password was something like a pet's name plus a birthday, the encryption might as well have been a screen door on a submarine.

Attackers don't need to break the lock if they can guess the key.

What makes this saga worth revisiting is the pattern, not just the incident.

LastPass has been breached before, in 2011, and again in 2015, and again in 2017.

At some point, repeated incidents stop looking like bad luck and start looking like a business model that treats security as a marketing bullet point rather than an engineering discipline.

Consumers keep trusting the brand because the brand keeps saying "trust us" in a reassuring font.

First, if you're still on LastPass, migrating your vault to a competitor like 1Password, Bitwarden, or Dashlane isn't paranoia, it's basic hygiene.

If it's a phrase you'd use anywhere else, change it yesterday.

Third, turn on two-factor authentication with an app or hardware key, not SMS, because SIM-swapping is its own thriving American cottage industry.

And fourth, if you reused passwords across sites, change them now, not after the next headline.

The deeper lesson here isn't about one company.

It's that we've handed the keys to our digital lives to corporations that measure success in subscriber growth, not in whether your bank account stays yours.

The vault is only as strong as the company guarding it, and the company is only as strong as its willingness to tell you the whole truth before a journalist has to drag it out of them.

The uncomfortable reality is that most breach victims never learn the full scope of what was taken, because companies have every incentive to minimize and every legal team to help them do it.

Assume the worst happened, act accordingly, and stop waiting for a press release to tell you the truth.

Final Thoughts

Your digital life is yours to defend, because nobody else is losing sleep over it.

Continue Reading