re’s tons of stories about the LastPass breech and most of them downlplay things saying your data is encrypted so the vaults getting stolen is not a big deal. Well that’s not true at all. I do not know if folks are purposefully downlplaying or they really do not understand how things work…but he truth is…most of the vaults are EASILY crackable…and 2FA is partly to blame. Watch the video below to see my take on this.
What happened is a LastPass developer had a media server on his home network running plex media server. Like most folks he left this media server exposed to the internet so he could stream his media files from home without having to pay another service. The developer did not keep the software updated and it got taken over. Once that happened the hacker then found the developer’s computer and compromised that machine. The hacker then was able to go from the developer’s computer to the LastPass network and compromise the system and leak all of the data vaults.
There are several basic mistakes made here:
- The company did not ensure the developer’s network was properly segmented. A simple router replacement like the Ubiquiti Dream Router 7 or a PFsense firewall could have provided this.
- The home network was not scanned for vulnerabilities before allowing such sensitive remote access
- Improper segmentation of the corporate network to prevent a developer form being able to have access to the data vaults in the first place.
Any one of these fixes would have either prevented or reduced the damage from this compromise. It’s also a lesson in basic network security that any company allowing remote access via a VPN should pay attention to. If you have any questions about the LastPass breach or your own network configuration, contact us for a no cost one-hour evaluation.