[HN Gopher] LastPass breach could've been stopped with a 3-year-...
___________________________________________________________________
LastPass breach could've been stopped with a 3-year-old Plex update
Author : tech234a
Score : 18 points
Date : 2023-03-05 20:14 UTC (2 hours ago)
(HTM) web link (www.androidpolice.com)
(TXT) w3m dump (www.androidpolice.com)
| MisterKent wrote:
| The _sole_ responsibility for this issue starts and ends with
| LastPass.
|
| For a security focused company, there is no excuse for a threat
| model to not include insider threats, vulnerable software inside
| an employees network, and potential phishing of employee
| credentials.
|
| If it wasn't going to happen through Plex, it would have happened
| through something else.
|
| Them pivoting like this is such a bad faith attempt at pinning
| the blame on a company that did everything right with regards to
| security. They should own up, and not try and throw another
| company under the bus. Even naming and Plex as part of the attack
| chain seems disingenuous at best.
___________________________________________________________________
(page generated 2023-03-05 23:01 UTC)