Sunday, January 8, 2023

LastPass

 Dear family & friends - Aaron here

I'm reaching out because a password manager I have previously recommended and perhaps you are using, called "LastPass" has had a major security breach. If you if you've never used LastPass you can ignore most of this email with the exception of reviewing that your master password (step 2) is good enough as I describe below. 


In addition to allowing Password vaults to be stolen, LastPass has not handled this breach well and many facts have come to light indicating it is not in the consumers best interest to stay with them as a password manager provider, including a class action lawsuits that has been filed. 


I am recommending you change to another password manager very soon following the below process. 


What password manager should you change to?

I would recommend bitwarden.com (my personal choice). It is easy to export from LastPass and import into Bitwarden. Alternatively, 1password.com may be a good alternative. 


Process

If you were using LastPass I also recommend the following actions. 


Today: 

1. Turn on two step verification for LastPass and all financial and buying sites. This is either a text message code or a code that comes from your banks app or an app like Authenticator. Lock your credit. 


This week: 

2. Develop a new master password at least 16 characters long with numbers and symbols . It should be based on the letters of a phrase (do not put this password into your LastPass or change your LastPass master password to this). Here is how to best do this: 


Choose a memorable quote or phrase and use

only the first letter from each word. Vary the

capitalization. Also include numbers and symbols, either as substitutions for letters or as a replacement for a full word($ for S, 8 for B). You want at least 2 numbers and at least 2 symbols. You can even add them to the beginning or end. (E.g., Wayne Gretzky’s “You will always miss 100 percent of the shots that you never take” becomes “ywAM100%ot$tyN+”.)

By today's computing power, this password would take 1 Trillion years to crack! Compare that with "P@ssW0rd123!" Which would take 0.05 seconds because it has a word in it. 


3. Setup a new account on your new password manager platform using your new master password. Turn on two step verification immediately. 


4. Migrate to your new password manager by exporting from LastPass and importing to your destination (you new password manager will have a guide on how to do this. This works very well on Bitwarden. (Dont forget to permanently delete the .CSV file you downloaded from LastPass!!! Use shift+delete (on windows) or command+delete (on Mac) to do this and bypass the trash or recycle bin.)


5. Change your financial and buying sites passwords. Then any passwords you reused between sites (stop reusing passwords while you're at it). 


6. Make it a point to change all your passwords as soon as possible, especially if your LastPass master password was less than what I describe in step 2. 


7. Be on the lookout for phishing emails which may use data from your password vault to convince you to take action. More on how to spot phishing emails here: https://www.itgovernance.co.uk/blog/5-ways-to-detect-a-phishing-email