LastPass has informed customers that they are now required to use more complex master passwords that are at least 12 characters long, in an effort to strengthen the security of accounts .

Although there has been a requirement for a 12-character master password since 2018 (the default setting), users have had the option to override the recommended settings and use a weaker password with fewer characters.
However, LastPass began requiring a 12-character master password starting April 2023 for new accounts or password resets, but this change did not affect older accounts. Starting this month, however, all accounts are required to implement a stronger password.
See also: Google Chrome: Automatically scans for compromised passwords
“Starting January 2024, LastPass will require all customers a master password with at least 12 characters.”.
The benefits of using LastPass master passwords with 12 characters are many. First, longer passwords are more complex, making them harder for someone to guess or crack.
Then, longer passwords increase the number of possible combinations, which significantly slows down a brute force.
Additionally, LastPass said it will start checking new or updated passwords against a database of credentials previously leaked on the dark web. If a match is found, customers will be notified and asked to choose another password.
In May 2023, the service also began a process of enforcing multi-factor authentication (MFA).
See also: What mistakes are you making with passwords?
Master password
These measures are the direct result of two LastPass security breaches that were revealed in August and November 2022.

In August, the company confirmed that its developer environment had been compromised through a compromised developer account. During the breach, source code, technical information, and some internal LastPass system secrets were stolen
The stolen information was later used for the next breach, when vault data was also stolen.
See also: The most used passwords of 2023, are yours on the list?
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In October 2023, hackers stole $4.4 million from more than 25 victims, using private keys and passphrases they were able to extract from LastPass databases (which had been stolen in LastPass breaches in 2022).
According to experts, attackers can now crack stolen LastPass master passwords to gain access to the password. Using this access, attackers can then search for cryptocurrency wallet passphrases, credentials, and private keys and use them to steal funds.
Source: www.bleepingcomputer.com
