Dec 11, 2014

The Scariest Retail Breaches of 2014

2014 isn't over yet, but some are already dubbing it the "year of the retail breach". About 20 major retail chains in the US were hit with big breaches from the end of 2013 to present. Those are just the ones we know about! And now the biggest shopping season of the year is underway in the US. The scale of these breaches means it's more important than ever to be proactive about data security.

The incidents shown in the infographic below largely affected payment information, but passwords and usernames remained the most exposed record type in 2014 so far. That's why it's also critical to:
Just how bad of a year was it for retail breaches? Click the infographic below to see a full-sized version:

Dec 9, 2014

Introducing Auto-Password Changing with LastPass

In the wake of major security incidents like Heartbleed, there was one piece of advice delivered over and over again: Change your passwords. Change them now. And create much, much stronger ones.

We saw many people struggling with where to begin that process. Even for those already using a password manager like LastPass, it still required setting aside time to navigate through each account and update passwords one by one. Until now.

We’re excited to announce that the Auto-Password Change feature we released to our Pre-Build Team last week is now available for all users in beta. LastPass can now change passwords for you, automatically. We’re releasing this feature for free to all our users, on Chrome, Safari, and Firefox (starting with version 3.1.70).

Maintaining your privacy and security is our top priority. That’s why we’re doing this differently. We’ve implemented this feature to make password changes locally on your machine, ensuring we stay true to our mission and never have access to your data. All of your sensitive information is encrypted on your computer before syncing, and your encryption key is never shared with LastPass.

Auto-Password Change already supports 75 of the most popular websites, including Facebook, Twitter, Amazon, Pinterest, Home Depot, and Dropbox. When clicking “edit” for a supported site, a “Change Password Automatically” button appears:

Once clicked, LastPass opens a new tab where it logs in for you, creates a new password, and submits the changes on the website, while also saving them to LastPass. Next time you log in to that website, LastPass will autofill with the newly-generated password. And all you had to do was click a button!

We’re committed to making password management easier, faster, and even more practical. We’re building features that help you minimize the impact of breaches. Give Auto-Password Change a try. We think you’ll find it life-changing, too.

Dec 1, 2014

2014's Naughty eRetailers: Who Made the List?

Cyber Monday is here, and that means shoppers everywhere will be hunting for the best deals online today. But watch out - not all e-retailers are "nice" when it comes to password security! We did a little digging into the password requirements and data practices of the top 10 e-retailers in the US, and it looks like a few will be getting coal this year.

We analyzed each website on a set of 6 criteria, on a scale of 0 to 10 points for each depending on how well those criteria were met. Each retailer then received a total out of 60 points based on their password requirements, how much information they store, and how much effort they put into helping customers follow good password security practices.

See our results in the infographic below, and follow our do's and don'ts for keeping your data safe this holiday season:

How'd We Get These Results?

The study was conducted by LastPass in November 2014. We compared the websites of the top 10 retailers in the US chosen per Top 500 Guide’s Top 500 e-Commerce sites and the National Retail Federation’s Top 100 Retailers.

Each site was analyzed based on a set of 6 criteria, with a scale of 0 to 10 points based on whether the criteria were met, and how well they were met. We tested password requirements, including minimum and maximum number of characters allowed & variety of character types allowed.; whether these requirements were shown up front for the consumer; if the websites employed a password strength meter to encourage longer passwords; use of security questions, and the obscurity of the questions asked; whether HTTPS is used when any information is entered; how much personal information is collected (name, birthday, address, email, phone); how accessible that data was when you’re logged in; and whether payment information is stored in the online account, and how accessible that is when you’re logged in (ie were only the last four digits revealed, or was the full card number accessible in plain text). See the full scoring table here

Nov 21, 2014

Game Site Accounts Hacked: Action Required

A hacking group has obtained login credentials for PlayStation Network, 2K Game Studios, and Windows Live. The hackers, known as DerpTrolling, have released a subset of the data to confirm their claim, which LastPass has reviewed and determined the leaked credentials are valid. This group has also claimed responsibility for a DDoS (distributed denial-of-service) attack on Blizzard Entertainment in which they overloaded their servers and shut down the service to users over the weekend.

According to the hacker group, the motivation for the attack was to demonstrate to the gamer community the vulnerability of their information and to compel these large companies to further protect the information of their customers. The breadth of the leaked information could be vast. A member of the group claimed "We have 800,000 from 2K and 500,000 credit card data. In all of our raids we have a total of around 7 million usernames and passwords...We have around 2 million Comcast accounts, 620,000 Twitter accounts, 1.2 million credentials belonging to the CIA domain, 200,000 Windows Live accounts, 3 million Facebook, 1.7 million EA origins accounts, etc."

Action Required

LastPass has deactivated the exposed accounts who reused their LastPass master password with these services. Remember... if you’re reusing passwords, especially your LastPass master password, you’re inviting trouble. We recommend immediately changing the passwords for these affected sites and if you reuse passwords on more than one site, you should take action to change those duplicate passwords as well. Use the password generator in LastPass to create a strong, unique password for every account.

As always, we will stay vigilant and do what we can to protect our users and their information.

Be Secure,

The LastPass Team

Nov 18, 2014

LastPass’ App Fill on Android Gets an Update

At LastPass, we’ve always believed in making it as easy as possible to practice good password security on all your devices. We’re furthering that mission with our latest update on Android, which brings near-universal support for logging in to apps and web sites.

Until now, the structure of some apps, like banking and financial apps, required extra steps to get logged in. Today we're releasing the App Fill Helper, which can fill your credentials in almost any app or web site. It's there when you need it, but can just as easily be disabled or enabled for any or all apps.

The App Fill Helper appears on the edge of your screen, in browsers and selected apps. The helper can be dragged to either side of your screen, so it stays out of the way while being easily accessible to assist with your login.

When you tap the helper, LastPass displays matching logins for the web site or app. In the cases where the web site or app doesn’t allow LastPass to autofill, as we sometimes see with financial apps, the app fill helper will offer convenient copy-paste options instead.

Overall, this update allows us to help you log into more web sites and apps than ever before. Now you’re typing less and getting an improved mobile experience, because LastPass can better handle the huge variety of apps and mobile web sites.

Available in the Google Play Store, the updated LastPass app supports filling logins in Android mobile apps and a number of mobile browsers, including Chrome, Opera, Yandex, Boat Browser, InBrowser, Amazon's Silk Browser, and Javelin.

The LastPass for Android app is part of our Premium service for $12 per year, with a free two-week trial for you to test out the features before upgrading. Or, upgrade today for unlimited mobile sync and even more password management features.

Nov 17, 2014

8 Tips to Protect Your Credit Card This Holiday Season

Gearing up for some online shopping this holiday season? With Black Friday and Cyber Monday only a couple weeks away, now’s a good time to ensure you’re set up for efficient, secure shopping as you check things off your holiday to-do list.

Here are 8 tips to keep you safe - and productive - as you shop online:

1. Don't store cards in browsers or online accounts.

Shopping online involves a lot of tedious forms, which means a lot of repetitive typing as you fill out your name, your address, your phone number, your email, and so on, with every single purchase you make. LastPass Form Fill saves time by filling all that for you. Storing and encrypting your credit cards with LastPass means you don’t need to put your credit cards at risk by storing that information in your web browser or your online accounts.

2. Shop at familiar companies, or research well.

If it’s your first time shopping with a vendor, conduct some research to ensure it’s a legitimate seller. Look for merchant reviews online or ask for feedback amongst your trusted peers. Look for social proof of an unfamiliar vendor by searching for them on Facebook or Twitter to see how legitimate they are. Familiarize yourself with the vendor’s refund policy and contact information, and look at the privacy policy to understand how your information may be used.

3. Look for a locked HTTPS connection.

Before entering your personal or financial information on a website, ensure the website is using a secure connection with SSL. LastPass Form Fill warns you before entering information on a non-HTTPS site. You can also look in the browser’s URL bar to see that there’s a padlock showing, and that the web address begins with HTTPS, confirming that you have a secured connection on that website. Using a secured connection ensures your data is transferred safely when you make a purchase.

4. Give as little personal information as you can.

Many websites won’t let you checkout without confirming some personal details. Choose the option to checkout as a “guest” when you can, or ensure you only fill out the required fields and nothing more. Understand what information they’re asking for and how that data may be used according to their privacy policy. If a website makes it optional to store your credit card, don’t keep it on file. The less information the website stores about you, the less there is at risk of being leaked in case of a data breach.

5. Create a strong, random password when you register.

Every single online account you sign up for should have a different password. When using a password manager like LastPass, it’s easy to create a new one with the LastPass Password Generator as you’re registering for a new online account. You can also login to existing online accounts and update old passwords at any time. And since LastPass does the remembering for you, you don’t have to worry about forgetting any of those new passwords - even if you don’t shop at those sites again for a year or more.

6. Keep an eye on credit card statements.

As soon as your credit card statements are available, review them for any unauthorized charges. If you print receipts from online purchases or save the records sent via email, it’s easier to compare your bank statements against your online purchases. If there’s any discrepancy, it’s best to contact your bank and report the issue immediately.

7. Only connect with secure WiFi.

As you’re submitting your personal and financial information online, it’s important to use an Internet connection that you know is secured. Even if you’re connecting to the website via HTTPS, on an open network it’s much easier to be tricked or phished into revealing passwords, credit cards, and other personal information you submit to a website. You don’t know how well the hotel or cafe secured their open WiFi, so it’s better to leave any transactions and sensitive account logins for later.

8. If it’s too good to be true, it probably is.

It’s thrilling to chase those great deals, especially on Cyber Monday, but be wary of anything that sounds so good that it’s unbelievable from vendors you don't know. Cyber criminals try to lure shoppers with unbelievable prices, fantastic rebates, or free promotions - including mobile apps that claim to give you perks, like free texts or calls, in exchange for logging in or posting something. Unsolicited emails, texts, calls, or social media messages could be an attempt to get you to hand over an account login or credit card information. When in doubt, play it safe.

Nov 6, 2014

Now Use Touch ID to Unlock Your LastPass App

Less than two months after our first app update for iOS 8, which debuted support for the LastPass Safari extension and Touch ID integration, we’re thrilled to let our community know that you can now unlock your LastPass app with Touch ID, too.

Following our initial release, we listened to your feedback and focused our efforts on bringing the features you’ve asked for, further improving the overall experience on iOS. That’s why our update focused on Touch ID improvements that include clearer settings and a simplified way to unlock the LastPass app with your fingerprint.

When first logging in after the update, you'll be given the option to use Touch ID to login to LastPass. Once you opt in, Touch ID is automatically enabled for your LastPass app. You can manage your preferences at any time in the app’s menu under “Settings” where you can toggle “Use Touch ID”.

Next time you multitask back to the LastPass app, you’ll be prompted to enter your fingerprint in place of entering your master password or PIN code. It’s a more convenient experience for you, while maintaining the security and privacy of your LastPass account.

The app update features additional usability improvements, including better interface support on the iPhone 6 and iPhone 6 Plus, as well as new copy-paste notifications that eliminate the need for an additional touch. When using the LastPass built-in browser, the matching sites menu is updated to allow for easier filling of passwords and form fields, too.

Grab these new features by downloading or updating the LastPass app from the App Store on your smartphone or tablet running iOS 8. If you’re not using LastPass Premium yet, a free 2-week trial is available for the LastPass app so you can try these features before you upgrading for unlimited mobile access and sync.

Nov 3, 2014

Are You Ready for the Online Shopping Season?

With Halloween behind us and Cyber Monday four weeks away, the holiday shopping season is officially here. This year, 56% of shoppers are expected to buy online and spend $800 on average. That’s a lot of purchases! And every gift purchased means reentering your personal details over and over again as you complete the buying process.

That’s why it’s essential to have LastPass ready to help you, so you can make this year’s shopping easier. Form Fill simplifies online shopping by instantly filling in those repetitive shipping, billing, registration, and payment details for you. It also means you're not restricted to the major e-commerce sites that already have your credit card details saved. The best deals are often found outside the major Internet retailers!

Start preparing now with these tips on using LastPass Form Fill, so you can save precious time this holiday season:

Add a Form Fill Profile.

You can add a Form Fill profile at any time from the LastPass Icon’s Form Fills menu, or from the LastPass vault under the “Actions” menu.

Complete the profile with your first and last name, email address, shipping address, credit card, and more. Use the “Name” field to clearly label each profile, so you’ll know which one you need at a glance.

If you have more than one credit card or debit card, or more than one shipping or billing address, simply create a profile for each so you can mix and match as you shop online.

Use a Form Fill Profile.

Once you’ve created your Form Fill profiles, you’ll be able to use them on any form. When you’re checking out, for example, you’ll see a profile icon in one of the fields on the page.

Clicking the profile icon opens a menu listing your stored profiles, and you simply click the profile you want to use for that form. LastPass instantly fills in all the details for you!

If the Form Fill icon doesn't appear in the field, you can also fill at any time from the LastPass icon Fill Forms menu and select your profile of choice.

The Easiest Way to Shop.

LastPass Form Fill is a life-saver as you shop online this holiday season. Using Form Fill means less typing, less reaching for your wallet, less hassle as you make your purchases. It also means LastPass is there to help you create and store any new online accounts.

Add a profile today and set yourself up for a more enjoyable online shopping experience this holiday season!

Oct 27, 2014

How Secure Is Your Workplace?

Think your personal security habits only affect you? Think again. The lines between personal and work are more blurred than ever as more companies transition to a BYOD (Bring Your Own Device) environment. What does that mean for cyber security? Below, we’ve rounded up alarming statistics showing the increased cyber security risks businesses are facing:

Employees are the weakest link due to both bad passwords and the risks of phishing. LastPass Enterprise addresses both issues and helps strengthen the first line of defense in protecting corporate data and consumer records. Start a free trial of LastPass Enterprise today, so your employees can use a generated password for every online account, without sacrificing productivity.

Oct 22, 2014

Open Sourced LastPass Command Line Application Now Available

There’s big news here at LastPass! We’ve released and open sourced a new command line client application. Whether you work as a developer, or in IT operations, or are just a tech-savvy LastPass user, our command line application makes it easier for you to get to data stored in LastPass on the terminal on Mac, Linux, and Windows under Cygwin.

The LastPass command line application brings both better security and convenience by allowing you to access, add, modify, and delete entries in your online LastPass vault, all from the terminal. You can also generate passwords for every server you use and securely store those passwords directly in LastPass. LastPass Enterprise features are supported as well, including Shared Folders.

Diving Into the Details

Users who prefer the command line can access their data directly with “lpass ls” then using “lpass show -c --password Sitename” to put the Sitename password on the copy buffer. You can utilize “lpass show” to store passwords used in scripts, rather than putting passwords in the scripts themselves. LastPass can also be used as you work within the command line to help you login to servers. We’ve included some example scripts below.

The new tool is beneficial for LastPass users who want to use the command line to login to other machines as they work. There are examples such as contrib/examples/ which shows automated password changing on a server. You could run it automatically on a nightly basis, regularly changing the password on the server as a security measure.

The command line application is hosted on Github at where we will continue to develop it for further applications and uses. We’d be happy to accept pull requests for further examples and increased capabilities.

lpass, like git, is comprised of several subcommands:

lpass login [--trust] [--plaintext-key [--force, -f]] USERNAME
lpass logout [--force, -f]
lpass show [--sync=auto|now|no] [--clip, -c] [--all|--username|--password|--url|--notes|--field=FIELD|--id|--name] {UNIQUENAME|UNIQUEID}
lpass ls [--sync=auto|now|no] [GROUP]
lpass edit [--sync=auto|now|no] [--non-interactive] {--name|--username|--password|--url|--notes|--field=FIELD} {NAME|UNIQUEID}
lpass generate [--sync=auto|now|no] [--clip, -c] [--username=USERNAME] [--url=URL] [--no-symbols] {NAME|UNIQUEID} LENGTH
lpass duplicate [--sync=auto|now|no] {UNIQUENAME|UNIQUEID}
lpass rm [--sync=auto|now|no] {UNIQUENAME|UNIQUEID}
lpass sync [--background, -b]

You can view the full documentation in the manpage,
'man lpass' or view it online.