Hacker News new | ask | show | jobs
by JoshuaEN 1274 days ago
Not passwords, but the hackers have some unencrypted data because LastPass did not encrypt all vault data client-side:

"The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs" - https://blog.lastpass.com/2022/12/notice-of-recent-security-...

The "such as..." without enumerating everything is very ominous as well.