Full Disclosure mailing list archives

Re: Lastpass Security Issue


From: Benji <me () b3nji com>
Date: Thu, 5 May 2011 22:40:11 +0100

Sorry, completely missed that part. My bad.

On Thu, May 5, 2011 at 10:35 PM, Nick Boyce <nick.boyce () gmail com> wrote:

On Thu, May 5, 2011 at 9:09 PM, Benji <me () b3nji com> wrote:

They've said nothing about what they're going to do to the server
with said anomaly. Wouldnt be happy until a full reinstall.

From http://blog.lastpass.com/2011/05/lastpass-security-notification.html:

 "We're rebuilding the boxes in question and have shut down and
 moved services from them in the meantime. The source code
 running the website and plugins has been verified against our
 source code repositories, and we have further determined from
 offline snapshots and cryptographic hashes in the repository
 that there was no tampering with the repository itself"

Is that what you meant ?

Nick
--
Current Earth status:   NOT DESTROYED

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: