TSD #004: LastPass popped wide open. No worries.

You might have seen in the news this week, LastPass got breached (Source: LastPass). Hackers gained access to their corporate systems and obtained some of their proprietary source code. This will allow hackers to potentially figure out ways to attack the password manager in order to attempt to get access to end-user passwords.

So, if you’re a LastPass user, burn your phone and walk away. I’m kidding. Those passwords stored in your password manager are encrypted with your master password, which only you know (Source: LastPass technical guide).

They’re as safe as the gold in Fort Knox.

Like this:

However, there are several attacks those bad guys can perform to try and get a hold of your master password, through phishing or malicious Google Chrome extensions. I’d still advise that you keep using your password manager, LastPass or something else. It’s much better to have all your passwords managed by an app than for you to try and remember them.


  • passwords should be unique
  • passwords should be strong
  • passwords should be backed up with 2FA where possible

Everything seems to be fine with the LastPass breach, don’t cancel your subscription. But there’s one thing I’d recommend you do: pay attention to upcoming LastPass app updates. You just don’t know what the hackers will find or what bugs LastPass knew were in their source code that might be exploited down the line.

Stay frosty! 🥶

P.S. Some of the links in this newsletter are affiliate links and help support my content. Thank you for your support! ✌️

