|
|
|
|
|
by WarOnPrivacy
1637 days ago
|
|
>Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. As a result, we have adjusted our security alert systems and this issue has since been resolved. This added bit hints that these emails were erroneously sent in response to the wrong password being attempted against the master account (which normally doesn't rate an email). It isn't fully spelled out tho. LP spends most of the blogpost going on about bad user practices - which feels a lot like gaslighting in this context. edit: I'm leaning toward accepting LP's incomplete, forced explanation and that hackery isn't in play here. |
|
This seems likely. After the original HN post, I went to delete my LastPass account as I've been using Bitwarden for several years. I initially used the wrong password, but then successfully logged in.
I got the alert email in question, so either it was sent in response to the wrong password (incorrectly) or it was sent in response to the full login, which of course wasn't blocked. The former seems more likely to me.