Was the LastPass security breach limited?
In its official statement, the company said the breach was limited to the development environment and failed to reach customers’ data and encrypted passwords. The company has not specified what information was accessed as the investigation is currently ongoing. It was further stated that the production environment is in a different physical environment than the development environment.
The last time there was unauthorized access, the company examined the production build and source code to check for any attempts to inject malicious code. It said that the developers or hackers could not push or transfer the source code from the development environment to the production environment. According to the company, the capability is limited to a specific team of the build release. The changes can only take place until a thorough review, testing and validation is completed. CEO Karim Toubba has ensured more robust measures to prevent further threats.
Frequently Asked Questions:
- Which company acquired LastPass in 2015?
GoTo, formerly known as LogMeIn, acquired LastPass in 2015. - How LastPass grants access when someone forgets the master password?
LastPass provides user-defined password hints in case the master password is missing.
Disclaimer statement: This content is written by an outside agency. The views expressed here are those of the respective authors/entities and do not represent the views of Economic Times (ET). ET does not guarantee, warrant or endorse its content and is in no way responsible for it. Take all necessary steps to ensure that all information and content provided is correct, updated and verified. ET hereby disclaims all warranties, express or implied, with respect to the report and its contents.