T
11

I finally stopped trusting my password manager after the Newark incident

I used the same LastPass vault for 4 years and thought it was bulletproof. Then I got a notice that someone tried to log into my banking from Newark, NJ, and they knew my master password prefix. That scared me straight, I moved everything to a hardware key and wrote my critical logins on paper in a locked drawer. Has anyone else gone backwards to analog after a near miss like this?
1 comments

Log in to join the discussion

Log In
1 Comment
carr.gavin
carr.gavin22d ago
Wait, how exactly did they get your master password prefix? Was it from a data breach leak or something more targeted like a phishing page that tricked you into typing it? Cause that changes everything about what the threat actually was. If it was just a breach dump, then writing stuff on paper does nothing because they already had the vault data, but if it was phishing, then your whole setup was already compromised regardless of the manager. I'm not judging the paper route, I just want to know what you think actually got popped here, cause that info matters way more than the tool you use.
4