Scammers hacking accounts - BE Careful!

Cotis

Well-Known Member
Joined
Nov 2, 2014
Messages
471
Location
Memphis, TN
I am not trying to plug for a particular Password manager, but I started using one about a year ago. There are many - 1Password, LastPass, etc. I personally use LastPass. I think it costs 30 dollars a year. You remember ONE master password, and use the software to generate these crazy custom unique passwords for each website you visit. There is an app for mobile phone, a plug-in on the browser on computer(s). It works on my business machine, personal laptop, iPhone and iPad. Amazing how much simpler life has become since I started using it. I highly recommend looking into one
 

UCStandSitter

Well-Known Member
Joined
Oct 20, 2021
Messages
5,497
Location
"Plataw"
I am not trying to plug for a particular Password manager, but I started using one about a year ago. There are many - 1Password, LastPass, etc. I personally use LastPass. I think it costs 30 dollars a year. You remember ONE master password, and use the software to generate these crazy custom unique passwords for each website you visit. There is an app for mobile phone, a plug-in on the browser on computer(s). It works on my business machine, personal laptop, iPhone and iPad. Amazing how much simpler life has become since I started using it. I highly recommend looking into one
Might wanna rethink Last Pass cowboy. They just had a breach…
 

Omega

Well-Known Member
Joined
Dec 16, 2018
Messages
7,604
Location
Clarksville, TN
Might wanna rethink Last Pass cowboy. They just had a breach…
I got the email, supposedly no passwords were lost, they are stored encrypted anyway and don't save my Master Password to access that data. Any software that touches the internet is subject to hacks, which is why more and more data is stored encrypted.
 

Cotis

Well-Known Member
Joined
Nov 2, 2014
Messages
471
Location
Memphis, TN
Might wanna rethink Last Pass cowboy. They just had a breach…
I know this cowboy, but it did not affect the password security. This is why I did not say I am recommending a particular one, just the advice to use the concept. I am not pleased their dev environment got hacked, but for now I am sticking with them. I understand their software architecture well enough to be comfortable still using them.

Quote from them:
We have determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers' information. Our customers' passwords remain safely encrypted due to LastPass's Zero Knowledge architecture.
 

UCStandSitter

Well-Known Member
Joined
Oct 20, 2021
Messages
5,497
Location
"Plataw"
I know this cowboy, but it did not affect the password security. This is why I did not say I am recommending a particular one, just the advice to use the concept. I am not pleased their dev environment got hacked, but for now I am sticking with them. I understand their software architecture well enough to be comfortable still using them.

Quote from them:
We have determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers' information. Our customers' passwords remain safely encrypted due to LastPass's Zero Knowledge architecture.
Live your life I guess. Was just tryin to help but it seems you'd rather be angry. Not sure what you do for a living but if it aint cybersec perhaps people here would be best to avoid your advice on password managers…
 

UCStandSitter

Well-Known Member
Joined
Oct 20, 2021
Messages
5,497
Location
"Plataw"
I got the email, supposedly no passwords were lost, they are stored encrypted anyway and don't save my Master Password to access that data. Any software that touches the internet is subject to hacks, which is why more and more data is stored encrypted.
Their storage was left vulnerable. That's a company I don't trust with my sensitive creds. Tells me they aren't conducting external pen tests regularly or this would've been found.
 
Last edited:

UCStandSitter

Well-Known Member
Joined
Oct 20, 2021
Messages
5,497
Location
"Plataw"
This is why I'm a 1Password fan for over 10 years now.
One of my colleagues is a big fan of them. I'm still too stubborn and cheap to use a pwd mgr 🤣. I go off a memory system I've used since about 99 that works pretty well for me. Never the same pwd twice between sites, domains, or systems and a little math differentiates them for me. The older I get the harder it gets though. Tried to explain it to my wife once how I create pwds and kept em straight. She looked at me like pickles were growing out of my ears so since then I just keep it to myself. 😃
 

Omega

Well-Known Member
Joined
Dec 16, 2018
Messages
7,604
Location
Clarksville, TN
Their storage was left vulnerable. That's a company I don't trust with my sensitive creds. Tells me they aren't conducting external pen tests regularly or this would've been found.
While I am not married to this software, I don't see any reason to change right now. Any password to a site that involves $, medical or security has 2-factor authentication so even if they are to crack my PW, they would have to have my phone/email info as well.
 

UCStandSitter

Well-Known Member
Joined
Oct 20, 2021
Messages
5,497
Location
"Plataw"
While I am not married to this software, I don't see any reason to change right now. Any password to a site that involves $, medical or security has 2-factor authentication so even if they are to crack my PW, they would have to have my phone/email info as well.
For a Security company to have a breach is egregious. Especially egregious when the breach was so easily preventable. If my company had a contract with this company it would be terminated. As security practitioners we tend to hold ourselves to a higher standard. LastPass has been the butt of a lot of industry jokes the last week or so
 

Omega

Well-Known Member
Joined
Dec 16, 2018
Messages
7,604
Location
Clarksville, TN
For a Security company to have a breach is egregious. Especially egregious when the breach was so easily preventable. If my company had a contract with this company it would be terminated. As security practitioners we tend to hold ourselves to a higher standard. LastPass has been the butt of a lot of industry jokes the last week or so
Sure if I was paying for the service I may, underline MAY, switch to another company, but as I am not, and again, my PW is safe, so I am ok with it at the moment.
 

UCStandSitter

Well-Known Member
Joined
Oct 20, 2021
Messages
5,497
Location
"Plataw"
Sure if I was paying for the service I may, underline MAY, switch to another company, but as I am not, and again, my PW is safe, so I am ok with it at the moment.
They told you it was. I wear a tinfoil hat by trade, trust isn't a luxury I can afford. Beauty of a free country though…

In God I trust. All others bring data
 

Rakkin6

Well-Known Member
Joined
Dec 1, 2013
Messages
7,036
Location
Clarksville
How do we know if any of the ads are from scammers? Are they just asking for electronic payments like has been mentioned? Any other things to look out for? Appreciate it, I changed my password and did the two-step authentication.
 

Kimber45

Well-Known Member
Joined
Jul 10, 2008
Messages
36,695
Location
Close to Jackson, TN
How do we know if any of the ads are from scammers? Are they just asking for electronic payments like has been mentioned? Any other things to look out for? Appreciate it, I changed my password and did the two-step authentication.
I would advise calling them, maybe talking to a member who knows them. Normally a conversation will scare off a true scammer.
 
Top