LastPass Forces Users to Change Master Passwords Following Suspicious Activity
May 05, 2011
LastPass, one of the most popular cloud-based password management services, is forcing users to change their master passwords as a precaution after it discovered an unauthorized data transfer out of its network. In a post on its blog the company explains, in sufficient detail, what prompted this measure, why it was the best course of action and what it means for users. On May 3, the company detected larger than normal outbound traffic and immediately launched an internal audit to determine the source. Such transfers have been detected before, but each time the origin was determined to be an employee or an automated script. "In this case, we couldn't find that root cause. After delving into the anomaly we found a similar but smaller matching traffic anomaly from one of our databases in the opposite direction. "Because we can't account for this anomaly either, we're going to be paranoid and assume the worst: that the data we stored in the database was some...