بلاگ پر واپس جائیںGDPR اور تعمیل

صفر علم بمقابلہ صفر اعتماد: کیوں آپ کا 'انکوڈ شدہ'...

LastPass نے اپنے صارفین کے ڈیٹا کو بھی انکوڈ کیا—اور $438M چوری ہو گیا۔

March 3, 20269 منٹ پڑھیں
zero-knowledgeencryptionGDPRdata protectionSaaS securityLastPass

The Encryption Illusion

In December 2022, LastPass announced a breach. The official statement included reassuring language: user passwords were "encrypted." Vault data was "secured."

By 2025, over $438 million had been stolen from LastPass users — drained directly from their supposedly encrypted vaults.

How? LastPass held the keys.

This is the critical distinction that every enterprise security team must understand before selecting any cloud-based tool that handles sensitive data — including PII anonymization platforms.

Server-Side Encryption vs. Zero-Knowledge Architecture

Most cloud tools that claim to "encrypt your data" use server-side encryption (SSE). Here's what that actually means:

PropertyServer-Side EncryptionZero-Knowledge Architecture
Where encryption happensOn the vendor's serverOn your device (browser/desktop)
Who holds the keysThe vendorOnly you
Vendor can read your dataYesNo
Server breach exposes dataYesNo (ciphertext only)
Vendor can be compelled to produce dataYesNo (they don't have it)
Regulators/law enforcement accessVia vendorNot possible without your key

LastPass used server-side encryption with keys they controlled. When attackers breached their infrastructure, they obtained both the ciphertext and the means to eventually decrypt it — through social engineering of employees, brute-forcing weak mast...

کیا آپ اپنے ڈیٹا کی حفاظت کے لیے تیار ہیں؟

48 زبانوں میں 285+ ادارتی اقسام کے ساتھ PII کی گمنامی شروع کریں۔