Dashlane explains how attackers managed to download encrypted password vaults



That means the chances of the attackers decrypting one of the encrypted vaults they obtained is very small in the event the master password was strong, meaning long, randomly generated, and has high entropy. However, not everyone uses such master passwords. In the event the master password was included in word lists exchanged by password crackers, the chances of success would be higher, although still unlikely.

Broadly speaking, the incident has similarities to the 2022 LastPass breach, which also allowed attackers to obtain encrypted user vaults. Eventually, the attackers managed to obtain decrypted information from some of them. The success was the result of two things.

First, certain fields, such as website URLs, remained unencrypted in vaults. That meant attackers could read them even without the master password. Second, some of the stolen vaults used outdated algorithms that didn’t adequately intensify the process for converting the plain-text password into a hash. Dashlane has said that no user fields in vaults are unencrypted. Further, when algorithms are periodically strengthened to account for advances in cracking abilities, the process occurs automatically, with no interaction required. The algorithm update process for LastPass vaults at the time came with more user friction.

Dashlane’s initial notification left out key details of the attack and led to considerable confusion about the ongoing risk users faced.

Out of an abundance of caution, both master passwords and the contents of any of the recovered Dashlane vaults should be changed immediately to reduce the chance, however unlikely, that the attackers succeed in breaking the master password. Unaffected Dashlane users don’t need to take any such action.



Source link

  • Related Posts

    Police Have Yet To Catch A Thief Who Used A Waymo To Steal Yoga Clothes

    Believe it or not, this is not the first robotaxi-assisted theft. A burglar used a Waymo to steal a bunch of yoga clothes and seemed to have gotten away with…

    Valve’s Steam Machine: Summer Release Planned, Still No Price

    Valve is still determined to release its living room PC game console, called the Steam Machine, despite skyrocketing prices for gaming hardware across the board, including the company’s own Steam…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Police Have Yet To Catch A Thief Who Used A Waymo To Steal Yoga Clothes

    Police Have Yet To Catch A Thief Who Used A Waymo To Steal Yoga Clothes

    Pakistan’s Lyari defies Bollywood’s gangland label to rise as boxing haven | Media News

    Pakistan’s Lyari defies Bollywood’s gangland label to rise as boxing haven | Media News

    Quebec tables bill to extend French language rules to adult education, drawing backlash – Montreal

    Quebec tables bill to extend French language rules to adult education, drawing backlash – Montreal

    Raman Gains on Pratt in L.A. Mayor Race But Many Ballots Remain

    Raman Gains on Pratt in L.A. Mayor Race But Many Ballots Remain

    Senate in overnight session as Republicans debate limits on $1.8B Trump settlement

    Senate in overnight session as Republicans debate limits on $1.8B Trump settlement

    Almonty Industries Prices Oversubscribed US$700 Million Convertible Senior Notes Offering