New Issue: Orbital Catastrophe Ahead? Read Now

Avoid Being Hacked: Lessons from Recent Data Breaches

This week I’m going to cover some of the high profile hacks that have happened recently, including Lastpass, Kaspersky and the White House’s Office of Personnel Management (OPM). My hope is that by learning more, you can avoid being hacked, stay more secure and know what to do if you have been hacked

Join Our Community of Science Lovers!

Scientific American presents Tech Talker by Quick & Dirty Tips. Scientific American and Quick & Dirty Tips are both Macmillan companies.

Just as predicted, there have been a huge number of hacks this year, including very notable ones like Lastpass, Kaspersky, and the White House’s Office of Personnel Management (OPM). Here are some lessons learned from those hacks in order to help you stay more secure, as well as tips for what to do if you've been hacked..

Lastpass
The first and most recent hack I want to talk about is in regards to Lastpass. I’ve done a podcast on Lastpass in the past for using it as a way to securely manage your passwords for all of your web accounts and payment information.


On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


First of all, if you are using Lastpass to store your passwords, you should go change your master right now. Go on, I’ll wait for you ...

Alright and we’re back! According to Lastpass, on June 15th, they publicly announced that they noticed suspicious traffic on the network and stopped it immediately. They assured users that their encrypted data was not taken, and that the only user emails, hashed master passwords, and secret questions were stolen. Now, that’s pretty bad for a company whose sole business is to secure your information.

However, it’s not as bad as it could have been. Although information was stolen, the most important part was that the master password was still hashed. If you’re not familiar with how Lastpass works, you basically have to remember one password, which safeguards every other password that you use online.

When Lastpass stores your master password, it hashes it just in case something just like this happens. Without going into the nitty gritty of hashing and cryptography (if you’re interested I have a podcast on that subject), basically the hackers would have to break your hashed master password.

Due to the fact that Lastpass uses an extremely long and slow hashing function, if an attacker were to focus its efforts to break a user’s hashed password, it would take an extremely long amount of time. I’m talking hundreds of thousands of years. Without your master password, the hackers would only have your email, security question, and that unusable password, which isn’t much to go off of. Still it is recommended that you change your password, and set up some form of two factor authentication.

>> Continue reading on QuickAndDirtyTips.com

Subscribe to Support Independent Journalism

Great science journalism requires human expertise, time, effort and creativity. And it costs money. That’s why I and the journalists here at Scientific American hope you’ll join our community.

When you subscribe, you are supporting staff and freelance journalists who are passionate about telling science stories that are true, important and compelling. Our editors and reporters are often experts in their fields, which means they understand the nuances of big discoveries and can untangle the breakthroughs from the hype. With a subscription, you are also supporting rigorous fact-checking to ensure the words we publish are precise and accurate. And you’re supporting original illustrations, graphics and photos that bring you closer to an advanced laboratory, an ice sheet in Antarctica or a space mission in orbit. You’re helping us craft other types of high-quality journalism as well: Our newsletters are carefully written, edited and curated by staffers you have or will come to know and love. Our Science Quickly podcast is based on original reporting, collaboration with editors and scientists and exacting production.

Subscriptions keep this engine running so we can continue to deliver thoughtful, rigorous and independent science journalism to you. In an era of viral misinformation, this work is crucial. If you value what we do, I hope you’ll consider joining us as a subscriber

Thank you,

Jeanna Bryner, Editor in Chief, Scientific American

Subscribe