Since I’m writing a lot about #LastPass and #LastPassBreach lately, I realized that maybe I should disclose my financial ties to the company. I’ve received $20,500 via the LastPass bug bounty program for 9 security issues reported between 2016 and 2018. Another 3 reported security issues received no monetary reward.
Also, following my findings about LastPass’ inadequate account data protection in 2018 (https://palant.info/2018/07/09/is-your-lastpass-data-really-safe-in-the-encrypted-online-vault/), there was a discussion about a consulting agreement allowing me to do a more thorough review of the code. This agreement never materialized, and I suspect that it was part of their overall delay tactics or intended to make me write more favorably about them.