Atgal į BlogąTechninė

[LT-02] Why 'We Encrypt Your Data' Is Not Enough...

[LT-02] $438M stolen from LastPass users after their 'encrypted' vaults were breached. A £1.2M ICO fine followed.

March 16, 20268 min skaityti
zero-knowledge evaluationvendor security assessmentLastPass breachcloud encryption claimsGDPR Article 32

[LT-02]

The Gap Between the Claim and the Architecture

Every cloud vendor handling sensitive data makes some version of the same claim: "We encrypt your data." The claim is almost always true — and almost always insufficient.

The LastPass breach of 2022 is the definitive case study. LastPass encrypted their users' password vaults. They used encryption. The claim was accurate. And yet 25 million users had their encrypted vaults exfiltrated, and $438 million was subsequently stolen from Last...

Pasiruošę apsaugoti savo duomenis?

Pradėkite anonimizuoti PII su 285+ subjektų tipais 48 kalbomis.