Sunday, December 23, 2012

Check your LastPass logins for security breaches...here's how

LastPass recently introduced LastPass Sentry, a new feature to help LastPass users be more proactive about their online security by alerting them when their email address is included in the latest breaches of online sites and services (think LinkedIn).

The update means that a full check can be performed locally against your entire LastPass vault to look for accounts that may have been affected by a breach, in addition to the ongoing monitoring of your LastPass account email address.

How LastPass Sentry now works:

  1. Sentry still performs daily checks, with the latest updates to the PwnedList database, to see if LastPass account email addresses are on the list.
  2. If a match is found, an email notification is sent to the LastPass user, notifying them of the domain that was breached and the potential risk. 
  3. Users can also run the LastPass Security Challenge (from the LastPass Icon's Tools menu) and select the option to look for breaches of their stored accounts. 
  4. If any matches are found between the PwnedList database and the data in your vault, notifications are sent to the affected email addresses with information on the breach and a reminder to update your passwords.
  5. We then recommend updating the password for any affected accounts, and any other accounts using that password (which the Security Challenge will help you identify), using LastPass to generate a new, strong password.

No comments:

Post a Comment