Leaked backups yeLastPass mushandisi data

Vagadziri veLastPass password maneja, iyo inoshandiswa nevanhu vanopfuura mamirioni makumi matatu nematatu uye makambani anopfuura 33, vakazivisa vashandisi nezve chiitiko icho vairwisa vakakwanisa kuwana makopi ekuchengetedza ekuchengetedza nedata yevashandisi vesevhisi. Iyo data yaisanganisira ruzivo rwakadai senge zita rekushandisa, kero, email, foni uye IP kero kubva kwakawanikwa sevhisi, pamwe nemazita asina kunyorwa saiti akachengetwa mupassword maneja uye encrypted logins, mapassword, fomu data uye zvinyorwa zvakachengetwa mumasaiti aya. .

Kuchengetedza logins nemapassword kumasaiti, encryption yeAES yakashandiswa ne256-bit kiyi yakagadzirwa uchishandisa iyo PBKDF2 basa rakavakirwa pane master password inozivikanwa nemushandisi chete, ine saizi shoma yemavara gumi nemaviri. Encryption uye decryption ye logins nemapassword muLastPass inoitwa chete kudivi remushandisi, uye master password kufungidzira kunoonekwa sechinhu chisingaitiki pane zvemazuva ano Hardware, uchipihwa saizi yepassword master uye nhamba yakashandiswa yePBKDF12 iterations.

Kuti vaite kurwiswa, vakashandisa data yakawanikwa nevanorwisa panguva yekupedzisira kurwiswa kwakaitika muna Nyamavhuvhu uye yakaitwa kuburikidza nekukanganisa kweakaundi yemumwe wevagadziri vebasa. Iyo Nyamavhuvhu hack yakakonzera kuti vanorwisa vawane mukana wenzvimbo yekusimudzira, kodhi yekushandisa, uye ruzivo rwehunyanzvi. Gare gare zvakazoitika kuti varwisi vakashandisa data kubva kunharaunda yekusimudzira kurwisa mumwe mugadziri, semhedzisiro iyo vakakwanisa kuwana makiyi ekuwana kuchengetwa kwegore uye makiyi ekubvisa data kubva mumidziyo yakachengetwa ipapo. Iwo akakanganiswa makore maseva akagashira akazara backups ye data data yevashandi.

Source: opennet.ru

Voeg