This is a great breakdown of LastPass’s blogpost about their security breach and everything left unsaid.

Even if you don’t blame them for being breached given how much of a high value target they are, you should blame them for downplaying the severity and not taking enough action to protect their customers.

https://palant.info/2022/12/26/whats-in-a-pr-statement-lastpass-breach-explained/

What’s in a PR statement: LastPass breach explained

The LastPass statement on their latest breach is full of omissions, half-truths and outright lies. I’m providing the necessary context for some of their claims.

Almost Secure

@carnage4life

Agreed.

But also, even if you don’t blame them for being breached you should blame them for being breached.

This wasn't a zero day, this was a security-focused company that (once again) failed to follow basic security protocols.