Post AEsMmp0TMjI7a8P680 by thenewoil@freeradical.zone
 (DIR) More posts by thenewoil@freeradical.zone
 (DIR) Post #AEsMmp0TMjI7a8P680 by thenewoil@freeradical.zone
       2021-12-28T22:01:53Z
       
       1 likes, 4 repeats
       
       LastPass master passwords may have been compromisedhttps://appleinsider.com/articles/21/12/28/lastpass-master-passwords-may-have-been-compromised
       
 (DIR) Post #AEsO45RJcaZlQOkvCa by lnxw37a2@pleroma.soykaf.com
       2021-12-28T22:16:13.882074Z
       
       0 likes, 0 repeats
       
       @thenewoil @rysiek I think @tek mentioned yesterday someone seeing exactly that problem with their LP account.
       
 (DIR) Post #AEsOV6zFyZyu2iWB9c by threeoh6000@queer.party
       2021-12-28T22:20:50Z
       
       0 likes, 0 repeats
       
       @thenewoil KeePassXC or Bitwarden on your own server people!
       
 (DIR) Post #AEsad72WrXlPyOd8Hw by rysiek@mastodon.technology
       2021-12-28T22:17:51Z
       
       0 likes, 0 repeats
       
       @lnxw37a2 @tek @thenewoil the "reused old leaked passwords" angle seems plausible. But of course I would not be surprised if LastPass master passwords leaked somehow.Getting my 🍿 ready!
       
 (DIR) Post #AEsad7UBCjsjM9ZDO4 by tek@freeradical.zone
       2021-12-29T00:37:00Z
       
       1 likes, 0 repeats
       
       @rysiek @lnxw37a2 @thenewoil I'm wondering about the browser plugin angle. Like, did a bunch of people have the same malware plugin installed?(Side note: I'm all for Safari having a much tighter plugin API than Chrome for exactly that reason.)
       
 (DIR) Post #AEsr2bHd9ZFiHIrx56 by adz@mastodon.technology
       2021-12-29T03:40:52Z
       
       0 likes, 0 repeats
       
       @thenewoil @WPalant You know anything about this?
       
 (DIR) Post #AEssBaabCeQGgaak9w by lightweight@mastodon.nzoss.nz
       2021-12-29T03:53:40Z
       
       0 likes, 0 repeats
       
       @thenewoil ruhroh.
       
 (DIR) Post #AEt25Us0YM7ekhT5cm by mars@kolektiva.social
       2021-12-29T05:44:40Z
       
       0 likes, 0 repeats
       
       @thenewoil seems like it was effecting people reusing passwords from previous hacks
       
 (DIR) Post #AEtqNcHYjGhkf3FkuW by thenewoil@freeradical.zone
       2021-12-29T15:08:11Z
       
       0 likes, 0 repeats
       
       @tek @rysiek @lnxw37a2 Possible. Another article noted that some people were reporting continued access even after changing their passwords, suggesting the criminals are pulling passwords in real-time if this story is true. Therefore a malicious plugin seems like a good explanation to me.