
Rival password manager 1Password has added its opinion into the mix, claiming that it would cost a hacker $100 or less to crack the master passwords protecting many LastPass vaults, such is the weakness of LastPass’ hashing methods.Īll of that has led Intego to state that, “given what we now know about LastPass - both how the company operates and its technology - we do not recommend using LastPass as a password manager.” How to keep your passwords safe According to security researcher Wladimir Palant, for example, LastPass’s statements were “full of omissions, half-truths, and outright lies.” One of Palant’s allegations is that LastPass’ implementation of a password-strengthening algorithm is not considered strong enough based on industry standards, making users’ vaults far too easy to hack into. However, Intego maintains that third-party analyses of the breach suggest a more troubling scenario. Questionable practices Ash Edmonds/Unsplash The only way I'm able to login to my account, and the forums to post this message, is via Chrome Icognito.Finally, in December, LastPass admitted the data accessed by the hackers was used to trick a company employee into handing over keys to some customer credentials, which were then used to access and decrypt customer data. ]Dropbox video link illustrating login loopįurthermore, "Preview Mode' of the forum editor is not displaying markup or url hyperlinks as expected. While not evidenced in my video since I was able to login with 3 attempts, Incognito is not a full solution. Incognito made may, or may not, fix the login loop. Having enable/disabled/deactivate both features as allowed, I'm not able to isolate the issue to one, the other, or any combination thereof with my meager skills. Sometime around the the first of the year 2020, the account login workflow begin initiating endless loops, at least in Google Chrome.Īs a starting point, I believe the endless login loop is somehow related to the Google Chrome password manager or the LastPass extension for Google Chrome.
