What happens to the serial security recidivists? Where are the regulators? LastPass has had security incident after security incident, how are they still allowed to operate?
back
3 comments
I think at this point, they need to get purchased by Experian, so they can combine into such an ugly mess of problems, that identity laws get overhauled.
They failed to secure sensitive user credentials, that must’ve broken some law.
Also, people can store notes on lastpass, did those get leaked too?
Yes
"that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data."
https://blog.lastpass.com/2022/12/notice-of-recent-security-...
I would not be surprised if such sensitive details could ruin someones life, and that is now in hands of a bad actor.
Would this sort of thing fall under GDPR?
And probably CCPA in that case?
What regulation? Nobody will ever prosecute them.