{"id":14254,"date":"2025-11-08T12:39:23","date_gmt":"2025-11-08T19:39:23","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=14254"},"modified":"2025-11-08T12:41:14","modified_gmt":"2025-11-08T19:41:14","slug":"is-your-password-manager-owned-by-a-surveillance-company-lastpass","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2025\/11\/08\/is-your-password-manager-owned-by-a-surveillance-company-lastpass\/","title":{"rendered":"Is Your Password Manager Owned by a Surveillance Company? (LastPass)"},"content":{"rendered":"\n<p>I had no idea about the connection to a spyware company and how some of the label data wasn&#8217;t encrypted. I was aware of the hack, but I had a strong password which made brute-force attacks problematic, as well as changing sensitive passwords immediately, e.g. banking, credit card&#8230; And I had used 2nd factor authentication as well. I guess from the unencrypted labels, the hackers knew exactly what vaults held crypto credentials, a bad practice in addition to using custodial wallet accounts. Consequently, it&#8217;s pretty easy to export your credentials to another password manager, and <a href=\"https:\/\/bitwarden.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bitwarden<\/a> is only $10 per year, with paid account only needed for 2nd factor authentication. And they seem to have a better extension and android app, open source, and they <a href=\"https:\/\/bitwarden.com\/help\/is-bitwarden-audited\/\" target=\"_blank\" rel=\"noreferrer noopener\">conduct regular audits<\/a>, including source code and penetration testing of their network and servers. <a href=\"https:\/\/proton.me\/authenticator\" target=\"_blank\" rel=\"noreferrer noopener\">Proton has an authenticator app<\/a> that is much more trustworthy than alternatives for second factor authentication, which I employ along with <a href=\"https:\/\/www.yubico.com\/\">Yubikeys<\/a>. And once converted, <a href=\"https:\/\/lastpass.com\/delete_account.php\" target=\"_blank\" rel=\"noreferrer noopener\">deleting your LastPass account<\/a> is pretty easy.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"WARNING LastPass Breach Exposes Dark Secret About Its Owners\" width=\"1290\" height=\"726\" src=\"https:\/\/www.youtube.com\/embed\/OhmOUWiDG1s?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>I had no idea about the connection to a spyware company and how some of the label data wasn&#8217;t encrypted. I was aware of the hack, but I had a strong password which made brute-force attacks problematic, as well as changing sensitive passwords immediately, e.g. banking, credit card&#8230; And I had used 2nd factor authentication [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,7],"tags":[],"class_list":["post-14254","post","type-post","status-publish","format-standard","hentry","category-tech","category-world"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/14254","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=14254"}],"version-history":[{"count":3,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/14254\/revisions"}],"predecessor-version":[{"id":14257,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/14254\/revisions\/14257"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=14254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=14254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=14254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}