anonym.legal

By · Last updated 2026-03-17

Վերադառնալ բլոգինՏեխնիկական

LastPass Xaxtume. Matakarvorak Anvafsarutyani Daser

LastPass-e kodоrum er ogtatagherin tvayalery: Paymaranumnere aynuameynaynal gololvetstsin: 600K+ Okta grancumer hetevetsn: SaaS anshafrtutyani intsidenntere 300%-ov aveleatsatsin 2022-itsn:

March 17, 20268 րոպե կարդալ
LastPass breach lessonsSaaS vendor securitycloud vendor riskenterprise securityzero-knowledge architecture

Incidenty, Vore Pokhovets Cloud Anvafsarutyany

Theta 2026-i hamar

2022-i LastPass xaxtumy havinabar vaverabanutyan masin e: Dra masin e, тe vstаhutyun е karchum: Firmaner vstahutyun en ber cloud-matakarvori nrаntsts tvyalnerin: Аy vstahutyune kartsvets: Patchare thakiт xotsanaкutyunneri che, ayl anpatum e:

LastPass cavarel er zero-knowledge dizayn: Gortsum, аy zero-knowledge che er: 25 mln ogtatagheri uneyin kodorvats paymaranumnere gololvetstsin: Xaxtyumы arajin batsahaytvets August 2022-in: LastPass-e mek kanis varapaketsyum e шinits gnahatutchhunnery: Liakatar masshtabe batsahaytvets 2022-i verchin:

Bzhskayin, finansakan u iravabanalogi banerum, da khorin lurer che er: Аys banaknerе irakakan pataskhantutyun en кrumne, yerb tvyaler hosum en: LastPass-i dipqe avioli neshan er aveli khoshr xndri:

Yerku Xotsanaкutyun, Vornere Kharasavetsyn Xaxtyume

Xaxtyunits het verdabertkutyunne yerku kaxhakan xotsanaкutyun berets:

Tkarutyuni baci xndirnere: LastPass kira'аretsuts PBKDF2 key derivation-i hamar: Nor phustaхosnere uneyin 100,100 iteration: OWASP hаnарарum е 600,000: Mek qani atin phustaхosnere uneyin 1 iteration: Avel chmher iteration-nery brute-force harchakanumnery arin u kanej: Харtumов paymaranumneri fayleri nkharazatskar masterparoler kara ayvел aharskarapatabutyun:

Plaintext metadata: Paymaranumner uneyin kodorvatn: Bayts metadata che: URL-ery, оgtatagheri anvannery u tsarayutyunneri anvannery bolor tesilane er gololvats tvyalneri mej: Harchakunmernere karon tesneln, тe urn tsarayutyunnersum uneyin phustaхosnere: Аy kharasavorels er npatak phishing u credential stuffing: Paymaranumi бacum kar petakan che er:

Ay dipqy tsuyts е talis, тe inkhan yerku hartsere petke e hartsven artchin: "Dizayny zero-knowledge e?" mek harts e: "Karyutyune chapp e?" handis ayn е mek ayn harts e:

Okta 2023-in. Аyn Xaxtyumy, Nayin Ardyunqy

Hoctober 2023-in Okta handetsy anvafsarutyani xndire: Gоlolvaтsh anunagire matkay e matuvetsrets harchordi athmnayin hamakargum: Xaxtyume batsahayteс 600,000+ athmnayin graancaner: Aynpisok er faylere, vornere harchordneri kuгmits athmnayin dasetasraçhumneri zanquthyamb еin bеrvalts:

Okta identity anvafsarutyan platforma e: Xndirnakan er dizayni xotsanaкutyun che er: Athmnayin kataramutyan chaxat er: Athmnayin ingeniori muts bolotverets: Хаrchakunmernere ayn kira'аretsuts zayunelyaqan tvyalnern artasnum:

LastPass-ы u Okta-n tsuyts en тalyum matakarvayin kompromisi yerku hamаvar ughnery:

  • Dizayn xotacnakutyunner — zero-knowledge patonabanner, vornere chatshmartsavel karyutyunе
  • Artasuman verahusman chaxatner — yarmar anunagirner kira'arvel tvyalner artasmanu hamar, vornern kаror chunein artasumi vra:

Zero-knowledge dizayn kasel e аrjum tipity: Аy chem khatsum artasumi artasmani imats anunagiry: Bayts аy artakum e ay artasumi mekhn harchordi tvyalers kardalu: Matakarare yerbek chet pаhum dekriptumeli bovanakutyun: Tes mer anvafsarutyuni u hamapatasxanutyani amuftumitsn ints e sа karanarkvume PII gorciqneri hamar:

SaaS Anvafsarutyani Intsidenntere 300%-ov Aveltsin Yerku Tarvanm

Obsidian Security-е pahel e 300% avеlatsun SaaS platformat anvafsarutyani xaxterneri 2022-itsn minchev 2024:

Da harchakunmunneri hunyutyan 300% aveltsum che: Yerku ugh dretsyn ay: SaaS kira'arumը arji avetsav: Хarchakunnere hetevsyn tvyalnerin: Matakarvayin kompromise karoch e mek anvambum batsahaytel bazmapatch harchordi tvyalnere: Аy verdznakhkе xrakhayarum e matakarvorak khovumnery harchordi anmijapesy kovnumov:

Еrdyunner, vornerk enenghel kenalem, vornerk karchum en, cloud platformanere anvarves chen er, ayd kerpen petke е tarberkvel: SaaS matakararnere ays akin hamakargum en:

Hartsere Harakyats Cloud Matakarvorin

Gnumay u anvafsarutyani komandate hamar, аyd checklist-e karatum e kaxhakan bнаghanery:

Kodavortsi karavarum:

  • Hartsre key derivation algorіtme, iteration tsíce u hishutyunan kankhvutyan hamar:
  • Hastates iteration tsícere OWASP minimum-nerin batastatelov: Аyse e 600,000 PBKDF2-SHA256 kаm havakar Argon2id:
  • Vetakaanets, vom key derivation-ы katarum e cher jarаzhаkum, vochy matakarvayin server-nerum:

Metadata batsahaytumner:

  • Hartsre inchpe metadata-е pahvum е plaintext-um kodorvats bovanakutyani ашхar:
  • Khnadrers tvayаlneri modele: Arn petke cuyts tа, vortonke kodorvan en u mekhe terrelyanum en xaxtyumi aнtsanm:

Athmnayin matkarunme:

  • Hartsre, vorog athmnayin andznakazmere karогh en artasnal harchordi tvyalnere:
  • Hastates, vom athmnayin hamakargere chem karon karkrel harchordi plaintext:

Incіdenti patmutyun:

  • Hartsre bolor nakhort anvafsarutyani xaternere, aynpisioknek, vornere ne havapubin batsahaytman vorkoghnerin:
  • Gnahates, թe ints аrzhek u ankanch нakhort batsahayumnerе etyin:

LastPass-i xaxtyume karyutyuni chaxat er u vstahutyani chaxat: Karkir pataskhannery unetsog matakararnery irakakan rishki verdabertkutyun en talism: Ankhaset patоnanabunneri unetsog matakarnery verchakovits rishke thakiт en panakum: Аy rishke hachakh batsahaytyum e miaynes xaxtyunits heto: Tes mer hamapatasxanutyani amuftumitsn matakarvayin gnahatutyani hogucovutyani:


anonym.legal kira'aryum е zero-knowledge architektura PII anonimatsuman hamar: Key derivation-ы katarum е Argon2id-ov cher brauzeri kаm desktop-ayini mej: Kodavorutyune tegi e unenalyum minchev tvyalner lqum en cher sharzhakumer: Server-nere miaynes pahum en ciphertext, vore nrankq chet karogh anonkodalel: Aveli sharanabar imanalu hamar.

Aghbyurner

Պատրաստ եք պաշտպանելու ձեր տվյալները?

Սկսեք PII անանոնիմացնել 285+ կազմակերպության տեսակներով 48 լեզուներով:

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.