Dashlane explains how attackers managed to download encrypted password vaults



That means the chances of the attackers decrypting one of the encrypted vaults they obtained is very small in the event the master password was strong, meaning long, randomly generated, and has high entropy. However, not everyone uses such master passwords. In the event the master password was included in word lists exchanged by password crackers, the chances of success would be higher, although still unlikely.

Broadly speaking, the incident has similarities to the 2022 LastPass breach, which also allowed attackers to obtain encrypted user vaults. Eventually, the attackers managed to obtain decrypted information from some of them. The success was the result of two things.

First, certain fields, such as website URLs, remained unencrypted in vaults. That meant attackers could read them even without the master password. Second, some of the stolen vaults used outdated algorithms that didn’t adequately intensify the process for converting the plain-text password into a hash. Dashlane has said that no user fields in vaults are unencrypted. Further, when algorithms are periodically strengthened to account for advances in cracking abilities, the process occurs automatically, with no interaction required. The algorithm update process for LastPass vaults at the time came with more user friction.

Dashlane’s initial notification left out key details of the attack and led to considerable confusion about the ongoing risk users faced.

Out of an abundance of caution, both master passwords and the contents of any of the recovered Dashlane vaults should be changed immediately to reduce the chance, however unlikely, that the attackers succeed in breaking the master password. Unaffected Dashlane users don’t need to take any such action.



Source link

  • Related Posts

    Cable lobby warns of chaos if FCC doesn’t relax ban on foreign routers

    AT&T pointed out in its successful petition that software and firmware changes “are not the only updates necessary to ensure continued functionality of previously approved devices.” But as of now,…

    Starz Promo Codes: $5 Off for June 2026

    I’ll say it: Starz is the “bad boy” of streaming platforms. Although competitor HBO is much better known, Starz’s content has a similar vibe, focusing on bold, oftentimes gritty, and…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Cable lobby warns of chaos if FCC doesn’t relax ban on foreign routers

    Cable lobby warns of chaos if FCC doesn’t relax ban on foreign routers

    Rumour: Persona 6 Images Supposedly Leak Online

    Rumour: Persona 6 Images Supposedly Leak Online

    2026 NFL offseason: Early trade deadline candidates to move

    2026 NFL offseason: Early trade deadline candidates to move

    Ireland’s Phil Hogan eyes European return with bid for top UN food job

    Friday briefing: How Gaza, Lebanon and Iran have found themselves caught in an escalation without end | Iran

    Friday briefing: How Gaza, Lebanon and Iran have found themselves caught in an escalation without end | Iran

    Starz Promo Codes: $5 Off for June 2026

    Starz Promo Codes: $5 Off for June 2026