SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • January 3, 2024
  • Rss Fetcher
A cartoon illustration shows a shadowy figure carrying off a red directory folder, which has a surprised-looking face on its side.
Keep your passwords safe from this guy. | Illustration: Beatrice Sala

Following a high-profile security breakdown in 2022, LastPass is finally imposing a 12-character minimum for customers’ master passwords.

BleepingComputer spotted a release from LastPass confirming the change that acknowledges 12 characters was already the default setting, but preexisting users previously had the option to set a shorter password. LastPass removed this option last April, requiring new customers and anyone resetting their master password to hit the 12-character requirement. But if your account had a shorter, less secure password, you’ll be forced to change it soon.

LastPass’ security woes are well documented — breaches in 2022 allowed hackers to steal customer vault data. If you were affected, this meant the only thing between a bad actor and all of your passwords was the master password used to secure your LastPass account. The company claimed that so long as customers followed its “best practices” when setting a master password, their data would be secure — even as some subscriber accounts were still using weaker passwords.

When all of this came to light a year ago — a year ago! — experts criticized the company for not enforcing the 12-character minimum on older accounts or updating other settings that increased security, like a new minimum standard for password hashing iterations. Now, both settings will be applied to older accounts, too. The company also says that it’s about to start checking “new or reset master passwords” against a database of credential breaches and alerting users if they choose one that matches login information that has already been exposed. This is vital because reused logins from other breaches can be used in “credential stuffing” attacks like the one that exposed many 23andMe users late last year.

LastPass says its customers still using shorter master passwords will be prompted to set a new one with a phased rollout this month, starting with Free, Premium, and Families accounts, followed by business customers. And even if you’re not a LastPass customer, consider this your sign to revisit critical passwords and double-check relevant settings. A few more characters could make all the difference.

Previous Post
Next Post

Recent Posts

  • Microsoft’s Satya Nadella is choosing chatbots over podcasts
  • MIT disavows doctoral student paper on AI’s productivity benefits
  • Laser-powered fusion experiment more than doubles its power output
  • TechCrunch Week in Review: Coinbase gets hacked
  • Epic Games asks judge to force Apple to approve Fortnite

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.