Security experts accuse LastPass of announcing that there are 14:00 questions, avoiding key points and confusing users' eyes and ears.
CTOnews.com, December 28 / PRNewswire-Asianet /-- password management tool LastPass issued an announcement before Christmas admitting that hackers stole user data, including name, URL and password (encryption), during the security incident that occurred in November. A security research expert could not help but post when he saw the announcement, saying that there were 14 doubtful points in the announcement, concealing some details and confusing users in a half-truthful way.
Wladimir Palant, a security expert, posted on his security blog Almost Secure that there were 14 doubtful points in the announcement and refuted it one by one.
CTOnews.com learned that Palant believed that LastPass played down the risk and that there was "gross negligence". This covers everything from the company's claimed transparency to its own security practices.
One of the controversial claims is that LastPass told customers that "if you use the default settings above and use the commonly available password cracking technology, it will take millions of years to guess your master password." Palant said that for the average user's password, the whole cracking time may only take two months, rather than "millions of years".