I don't buy LastPass' statement that this breach of master passwords was due to credential stuffing. If that were the case, then LastPass users who feel victim would have been using their master passwords for something else. The victims who posted in the HN thread specifically said they did not do that.

LastPass Says It Didn’t Leak Your Master Password
howtogeek.com/776450/lastpass-

Follow

"But while LastPass claims the recent account compromises was the result of a credential stuffing attack, after this article went live, security researcher Bob Diachenko suggested that this might not be necessarily true, and that hackers simply used a database that leaked from a malware operation, which appears to have also contained LastPass account master passwords."

therecord.media/lastpass-confi

twitter.com/MayhemDayOne/statu

Sign in to participate in the conversation

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.