2 Followers
31 Following
41 Posts

Looks like we're getting more information on the most recent LastPass breach:

"To date, we have determined that once the cloud storage access key and dual storage container decryption keys were obtained, the threat actor copied information from backup that contained basic customer account information and related metadata including company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service.

The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data. These encrypted fields remain secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user’s master password using our Zero Knowledge architecture. As a reminder, the master password is never known to LastPass and is not stored or maintained by LastPass. The encryption and decryption of data is performed only on the local LastPass client. For more information about our Zero Knowledge architecture and encryption algorithms, please see here.

There is no evidence that any unencrypted credit card data was accessed. LastPass does not store complete credit card numbers and credit card information is not archived in this cloud storage environment."

They went on to say if you picked a weak master password, you should change the passwords it protects.
https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/

Security Incident December 2022 Update - LastPass

We are working diligently to understand the scope of the incident and identify what specific information has been accessed.

The LastPass Blog

Kann ich ls Norddeutscher mal eine Bitte äußern? ICH WILL VERDAMMT NOCHMAL APPS UND KIs in der NORDDEUTSCHEN VERSION!

Da heißt es dann statt: "An der nächsten Abzweigung in 500 Metern nehmen sie die Ausfahrt auf der rechten Seite, blablabla" einfach "RECHTS RAUS"

Dieses ganze unnötige Laber-Rabarber der Geräte MACHT MICH FERTIG. Ich hab meine Lebenszeit nicht im Lotto geschossen, ich will von Technik keine Frikadelle ans Ohr!

Und KIs the same. Einfach mal ein gepflegtes "Jo" tuts auch. Danke.

Ein irreführender Blogartikel über #Mastodon geht derzeit bei Elon Musks Fanboys und in rechten Kreisen viral – zuletzt auch in einer Publikation des Ex-Bild-Chefredakteur Julian Reichelt. Doch es handelt sich um Desinformation mit einer Art Mastodon-Pizzagate, die sich perfekt in die Verschwörungsideologie von QAnon einreiht. Ein Kommentar.

https://netzpolitik.org/2022/desinformation-wie-die-fanboys-von-elon-musk-versuchen-mastodon-zu-diskreditieren/

Desinformation: Wie die Fanboys von Elon Musk versuchen, Mastodon zu diskreditieren

Ein irreführender Blogartikel über Mastodon geht derzeit bei Elon Musks Fanboys und in rechten Kreisen viral - zuletzt auch in einer Publikation des Ex-Bild-Chefredakteurs Julian Reichelt. Es handelt sich um Desinformation mit einer Art Mastodon-Pizzagate, die sich perfekt in die Verschwörungsideologie von QAnon einreiht. Ein Kommentar.

netzpolitik.org
I've waited a few days to post this about the #mastodonmigration. Here is the evolution of the new accounts in #mastodon after the events in the last week. After each new ban/suspension in the #bluebird we see a spike in new accounts in #mastodon. But recent growth seems to be more steady at around 50k per day. Since the #bluebird purchase by Musk, more than 3 million new accounts were created in #mastodon.

Unfortunately I have to stop actively working on #Metatext for a while due to health issues. I really wish I could implement Mastodon 4 features and squash every bug, but it's not possible for me to do so right now.

I know the app has become important to a lot people, so I'm open to a new maintainer who can carry on its values of privacy and accessibility taking it over if there's interest and a fit. Email [email protected] if you (or your organization) are interested

🤪
Cybersecurity Pros Put Mastodon Flaws Under the Microscope

As the open source social media network grabs the spotlight as a Twitter replacement, researchers caution about vulnerabilities.

Dark Reading

I love the new #Twitter. From Forbes, the copyright enforcement system is broken and I can’t stop laughing.

“A user went viral for uploading the entirety of The Fast and the Furious Tokyo Drift in two minute chunks over a 50 tweet thread. While it’s offline this morning, here’s where things get weirder still…”

https://www.forbes.com/sites/paultassi/2022/11/21/twitters-broken-its-copyright-strike-system-users-are-uploading-full-movies/

Twitter’s Broken Its Copyright Strike System, Users Are Uploading Full Movies

Last night, it became apparent that Twitter's automated copyright strike/takedown system was no longer functional.

Forbes
Im Kontrast zum Mut der iranischen Nationalspieler, die ernsthafte Konsequenzen für sich und ihre Familien befürchten müssen, wirkt das Einknicken des #DFB in Zusammenhang mit der #OneLove-Armbinde nochmal eine Spur erbärmlicher.
Symbolbild Elon Musk.