Showing posts with label Password Vault. Show all posts
Showing posts with label Password Vault. Show all posts

Tuesday, 13 October 2015

Expert: Precautions LastPass Users After Purchase LogMeIn



Last Friday it was announced that the popular online password manager LastPass for an amount of $ 125 million was taken, but the new owner LogMeIn has caused some users worry. Reported that the Australian security expert Troy Hunt.

LogMeIn is a company that offers software that allows remote access to computers can be obtained. The company's image is not flawless. So let LogMeIn in 2011 that LogMeIn would always be free. Last year, however, the company announced the end of LogMeIn Free on. Another point is that the LogMeIn software is often used by telephone scammers posing as Microsoft employees. In early 2012 Hunt attention to the issue. "Unfortunately, three years later LogMeIn continues to be the preferred software of these crooks," he tells.

According to Hunt many people are also concerned about the direction that LastPass for the acquisition will go up. "Even though they say that the password manager remains independent and is not influenced, they now fall within a broader business vision and LogMeIn will influence the direction of LastPass," said security expert. He therefore anxious for LastPass users a roadmap put online that explains how simple of LastPass can be switched to 1Password, another popular password manager.

Saturday, 10 October 2015

LastPass Password Manager For Acquired 125 Million



Online password manager LastPass is today a cost of $ 125 million acquired by LogMeIn, a provider of software to log on to remote computers. LastPass is a cloud service where users their passwords for various websites in a "safe" to store.

The vault is then accessible from different devices, which should simplify logging in from a PC, smartphone or tablet. LastPass offers both free and paid versions of the software. In August there was a still a new use model introduced. Users can therefore choose which platform they want to use the software for free. Previously, users could install the password manager free only on their computers and then make it synchronize smartphone or tablet to be paid.

Both the free and paid versions LastPass will continue to support and further develop, so the company says. The software of Load Pass will now be added to the solutions of LogMeIn. Furthermore, users can expect in the coming months several new features. In June, LastPass was still a security incident to make. Attackers had managed to break into the network of online password manager and managed in order to steal users' data. It involved email addresses, reminders for passwords, user salts per server and authentication hashes. The contents of password vault would have been in no danger.

Thursday, 18 June 2015

LastPass: Password Vault Content Not In Danger


Users of the recently hacked online password manager LastPass who used a weak master password or had given a clear password hint at greater risk of attackers who knew the company to break into the master password know to figure out, but the contents of the Password Vault is not in danger.

That LastPass late in an updated statement about the attack. The attack on the online password safe were email addresses, reminders for passwords, user salts per server and authentication hashes captured. The master password is not immediately stolen by the attackers, but only the hash of this. Both the user's master password for Password Vault are hashed over 5,000 iterations of the PBKDF2-SHA256 hashing algorithm.

Creates a key that is hashed again, so as to make the authentication hash for the master password. This authentication hash is sent to the LastPass server as a user on his online password safe trying to login. "We then take that value and use a salt, a random string per user, and another 100,000 do hashing rounds and compare it with what is stored in our database in simple terms:. Cracking our algorithms is very difficult, even for the strongest computers, "said LastPass.

Advise

However, an attacker can try to guess the master password and then use the per-user salt and authentication hash to determine whether his guess was correct. Because of the large number hashing round, both locally and on the server, LastPass thinks that this will be a slow process for an attacker. If the user's master password is weak, however, whether he entered a password hint that makes it simple to guess, then an attacker much less effort required to retrieve the master password.

However, the contents of the safe password remains safe says LastPass. Once an attacker with the outdated master password namely trying to log on, he must first verify your email address. This measure applies to all login attempts from a new IP address or system.

Creak

Security expert Robert Graham investigated whether an attacker can crack the hashes. On his computer, he could guess more than 2500 passwords per second. "This may seem like a lot, but it's not as cracking passwords is exponentially difficult," said the expert. A password of five characters, with all possible characters are used and there are 64 possibilities for each character consists of up to 1 billion combinations.

A fast computer can crack this password quickly. Adding a character with 64 different options makes it 64 times harder to guess the password through a brute force attack. However, the cracking time can be shortened if a dictionary is used, says Graham. He advises LastPass users with a weak master password whatsoever to change that.