TL;DR: Last Pass is broken. All passwords at the time of the breach were taken. They also got internal secrets from a laptop and can now probably throw computational power at anything they want to decrypt.

Switch. Do not use. Change everything you have if you were using it. Treat everything as breached.

  • groundling20XX [none/use name]
    ·
    2 years ago

    OP doesn’t understand how LastPass functions. Even after this breach any passwords are still fine, but mfa should be rotated

    • Sphere [he/him, they/them]
      ·
      edit-2
      2 years ago

      Yeah as someone who uses LastPass, I'm not the least bit worried that my vault will be breached. My master password strength is over 121 bits; they're not gonna crack it.