Full Disclosure mailing list archives

Re: Lastpass Security Issue


From: Nick Boyce <nick.boyce () gmail com>
Date: Thu, 5 May 2011 21:35:29 +0000

On Thu, May 5, 2011 at 9:09 PM, Benji <me () b3nji com> wrote:

They've said nothing about what they're going to do to the server
with said anomaly. Wouldnt be happy until a full reinstall.

From http://blog.lastpass.com/2011/05/lastpass-security-notification.html :

  "We're rebuilding the boxes in question and have shut down and
  moved services from them in the meantime. The source code
  running the website and plugins has been verified against our
  source code repositories, and we have further determined from
  offline snapshots and cryptographic hashes in the repository
  that there was no tampering with the repository itself"

Is that what you meant ?

Nick
--
Current Earth status:   NOT DESTROYED

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: