LastPass fined £1.2M by ICO for data breach

ico.org.uk

21 points by edent 2 days ago


Havoc - a day ago

>>There is no evidence that hackers were able to unencrypt customer passwords as these are stored locally on customer devices and not by LastPass.

That's a highly sus statement. Firstly who says "unencrypt" and second there is a whole string of crypto hacks that had their details in Lastpass...and crucially the URLs were not encrypted so evildoers could see which accounts are worth throwing compute at

Plus the not stored by LassPass seems entirely wrong too? I can log in to their website and see my stuff...they very obviously store it

Very strange to have a regulator of databreaches get the basics so fundamentally wrong