Greg Kutzbach 

144 Followers
76 Following
60 Posts
Digital Forensics and eDiscovery.
Mountains and dirt roads.
@Viss is discord based in a country that allows them to choose when to cooperate with legal orders? A lot of cryptocurrency scam groups and criminals use discord. It seems very discoverable.
@alethe boo.
@alethe I’m working on an Isc2 cert. They also use Pearson Vue, right?
Re: The Lastpass breach
This puts it simply.
Rotary Keyboard

Bodging a rotary dial into a mechanical keyboard

Squidgeefish
@GreenFire Read Thinking Security. It is timeless and forever true.
@SwiftOnSecurity are these videos designed to make us think about industrial control system security and SCADA?

@robpomeroy Here’s the opinion of Nicolas Chaillan… remove trust in SaaS for critical infrastructure. I don’t think most orgs can responsibly manage most infrastructure. This one brings a big sigh from me. Need to discuss.

https://www.linkedin.com/posts/nicolaschaillan_lastpass-hackers-stole-customer-vault-data-activity-7011815153495134208-Q33S?utm_source=share&utm_medium=member_ios

Nicolas M. Chaillan on LinkedIn: Lastpass: Hackers stole customer vault data in cloud storage breach | 29 comments

There you have it folks. I am now telling folks to stay away from multi tenant SaaS stacks for critical capabilities. This market will die due to cyber… | 29 comments on LinkedIn

@robpomeroy As a reminder to everyone.. use a strong master password.

To @robpomeroy, does using 2fa in any way influence a hacker’s process to brute force the encrypted data? Perhaps as some sort of salt?

https://support.lastpass.com/help/what-is-the-lastpass-master-password-lp070014

What is the LastPass master password? - LastPass Support

The master password is the password that you are prompted to create when you initially sign up for your LastPass account. When you log in to LastPass, you need your email address and master password to access your account. It is very important that you create a very strong master password that you will not forget.

On the LastPass breach.

So threat actors made off with "company names, end-user names, billing addresses, email addresses, telephone numbers, and ... IP addresses".

They also got "customer vault data ... that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields".

That's not great, whichever way you look at it.

https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/

#LastPass #Breach #SecurityBreach

Security Incident December 2022 Update - LastPass

We are working diligently to understand the scope of the incident and identify what specific information has been accessed.

The LastPass Blog