When it comes to online privacy and security, one of the topics that
we always emphasize on is using a VPN service. Using a VPN, you can make sure that your online privacy is secured
as you can browse the web anonymously. In case you are looking for a
VPN service for a similar reason, you should not really be looking for
the free stuff. A paid VPN service is what would be ideal in such a
situation. You might have to compromise on speed and privacy breach
might also be an issue. Read our piece on the dark side of free VPN for the risk attached that comes with these free VPNs.
However, at times, you just want to bypass the country restriction
while trying out a new service on Android, or you just wish to install
an app not yet available in your country. In these scenarios buying a
VPN service doesn’t really makes sense. A free VPN app would be ideal to
bypass these restrictions. But here also you should be choosing a
service which is comparatively secure and trustworthy.
So here are 5 free VPN services that can help you bypass country restriction on Android and at the same time protect privacy.
1. Betternet for Android
Betternet for Android
is one of the best free VPN services for Android. The app has some ads
to support its free services, but the ads are not at all irritating.
From the homepage, you press the Connect button and wait for the connection to establish.
One thing to note here is that you cannot select the server/country
you wish to connect to manually. The app will auto-connect you to the
best server using a load balancer. Most of the times, it’s US or Canada,
but at times, you might also connect to servers at Singapore,
Netherlands, and the UK. We have already covered all the details about the app in one of our previous posts which you can have a look at for more details.
2. FlinchVPN
FinchVPN
is another free VPN service for Android that you can try. You need to
create a free account and after successful activation, you will get a
monthly bandwidth of 3 GB. FlinchVPN allows you to select the
server/location from US, Canada, and France.
There are no ads in the app and as long as you are using the free
servers and don’t need more than 3 GB of free data in a month, FinchVPN
will work like a charm. However, for just $1 per month, you can get
access to many fast servers and extend monthly data limit to 25 GB. For
those who would like unlimited data, it would just be $3 per month.
3. Hideman VPN
Hideman VPN
gives you a long list of countries to choose from even in the free mode
and you don’t need to create an account to start the VPN service. Also,
if you are looking for a VPN to download torrents, Hideman can help you
with that. There are a few free servers which support torrents and
there will be an icon next to the server which will denote the support
for them.
You get a few free hours on the app and you can share links for the
apps and do a few other things to get the time extended. For paid
membership, there are hourly packages available for users who would like
to have a reliable VPN service for just a few hours.
4. Hotspot Shield Free VPN Proxy
Hotspot Shield Free VPN Proxy,
unlike the other apps, give you the power to start the VPN service
automatically when a specific app is launched on your Android. This is
apart from the usual overall VPN service that it provides. The advantage
of using Hotspot Shield on just a few apps will provide more security
and privacy.
In the free plan, you can change different countries/servers, but
there is some time limit and also the app has ads. However, there is an
option to upgrade to monthly and yearly elite plans to get better speed
and an ad-free experience.
5. Tunnel Bear
Tunnel Bear
is one of the most trusted names when it comes to VPN and if your
monthly usage is anywhere less than 1.5 GB, you can trust this service
even on blindfolds. There is a long list of servers/countries to choose
from even in a free account and there are no ads in the app.
You get 500 MB of free usage every month on the limited account and a
tweet asking Tunnel Bear for free data will give you another 1 GB of
free data every month. The interface is one of the best when compared to
other VPN apps available for Android. If you are looking for a premium
VPN plan, I would definitely recommend this one because of its speed and
security. Furthermore, if you’re looking for Android only plans, they
have it at cheaper rates.
Conclusion
So those were some of the top free VPN services you can install on
Android to bypass country restrictions. I would again suggest you to use
these free services on a limited basis and look for a secure, paid
service if you want to round the clock security and privacy.
We all love privacy. It gives us our peace of mind that there’s no
one going through our stuff. Albeit, it’s the biggest issue in all
fields of technology. No matter how hard you try, some or the other way
it will be endangered. However, we should never stop trying. If you
believe in that, then let me show you how you can hide your “personal
stuff” stored in those specifically partitioned disk drives on Windows. The hidden disk drive | Shutterstock
Here, I’ll show how you can password protect your disk drives and
keep your sensitive data safe. So, without further ado, let’s dig in.
Hide Disk Drives in Windows
So, the software we are going to explore today is Hidden Disk. In the past, we had shared with you how you can hide a secret partition in your USB flash drive.
But, today using Hidden Disk I’d like to show you how to hide disk
drive and it’s content. And, not just hide but also add a password to
it.
Download and Install the software to begin with. It does work well on
Windows 10. And, using this software is really simple. So, let’s do it.
Step-1: Create Disk
On the home screen of the software, you’ll see a Letter X. Those are
actually disk drive letters. You can choose whatever you want. Next,
after you’ve chosen your disk letter click on Create Disk.
Now, the disk will be created and it should show you a warning that
you shouldn’t format your system drive or reinstall your system. If you
do so then the disk you created will get removed (along with the files
stored in it). Also, with this warning, there’s an important point to
note. The files that you store in this disk drive are being stored
somewhere on your System drive. That is why you’ll see the new drive you created will be named same as your System drive.
Also, you can create other drives by changing the drive name in the software. Step-2: Hide the Drive
Now in order to hide the drive click on Disable Disk. Before doing so don’t forget to add your files in the drive. After you’ve disabled it, the drive will disappear.
Also, another way to make it invisible is to shut down your PC. The
disk will disappear every time you shut down. So now, how do you get it
back? Step-3: Open Hidden disk and Click on Create Disk again to make the hidden disk visible.
If you had added any files in the hidden drive then you’ll get them back in the drive after you hit Create disk (again). Yeah, that is a little time consuming but privacy comes at a cost bro.
Now, let’s see how you can add a password to this hidden drive.
Password Protect the Hidden Drive
Well, actually you won’t be adding a password to the Hidden disk but to the Software. Step-1: Click on Create/Update Password
And, on the next screen add your password and recovery email. The
email ID will be used to send you your password in case you forget it. Step-2: Accessing Software with the New Password.
You can now test out if it works. Disable the disk drive and close
the software. Next time when you open it, it should ask you for the
password.
So you’ve now password protected your files and folders and also made them invisible.
DuckDuckGo is a fantastic search engine if you’re fed up with the spying eyes of Google
and other search providers. The service vows to never collect
information about you and certainly never sell your searches to
advertisers. Check out these four tips to make the most of DuckDuckGo’s privacy and security features | Shutterstock
While that’s enticing in itself, there are features within DuckDuckGo
you can take advantage of to enhance your privacy and security even
more. The search engine is highly customizable, so that puts the control
in good hands: your own. Make the most of DuckDuckGo with these useful tips to boost your privacy online and intensify your security.
1. Turn on WOT Icons
Enabling WOT icons in your search results means you’ll be able to stay away from potentially dangerous websites. WOT stands for Web of Trust,
which is a service that analyzes the possible security threats from
each website. A green circle means it’s in the clear (safe), yellow
means take caution before visiting the website and red means avoid at
all cost.
Since DuckDuckGo has this functionality built in, you can turn this on from the Advanced Settings. Click the Menu icon at the top right of the DuckDuckGo homepage and choose Advanced Settings. Click the Appearance tab, then scroll all the way down to find the WOT Icons option. Click Offto then turn it on and be sure to click Save and Exit to apply the changes.
Tip: All tips in this article will require you to first click the Menu icon and choose Advanced Settings so keep that in mind for later.
2. Ditch Google Maps
If you’re particularly anti-Google and don’t want any aspect of your
online life tracked, then you probably don’t want DuckDuckGo using
Google Maps to find you directions. Depending on your current settings,
however, this might be the case.
To ensure that DuckDuckGo uses a different provider for directions, head into your DuckDuckGo Advanced Settings to pick something different. Under the General tab, scroll to find Directions Source.
Then pick your preference: either Bing Maps, Google Maps, HERE Maps
or OpenStreetMap. Apple Maps is also available if you’re using a Mac.
3. Prevent Websites from Knowing How You Got There
DuckDuckGo has a nifty little feature called Redirect. With
Redirect enabled, websites won’t be able to track which search term you
used to land on the page. This is because when you click a link,
DuckDuckGo temporarily redirects to a subdomain before bringing you to
the website. (You won’t even notice.) Note: While this prevents the websites from
gathering information about your search, it can still gather your
information just from the browser itself. Check out our guides for
enabling Do Not Trackin Google Chrome and Internet Explorer to stop this snooping activity as well.
Head to the Advanced Settings on DuckDuckGo, click the Privacy tab then click to ensure that Redirect is on to enable this feature. Click Save and Exit to apply.
4. Anonymous Cloud Save
Since DuckDuckGo doesn’t collect information about you, that means it
can’t always recognize that it’s you performing your search. However,
if you’re one to tweak with settings (like the ones above) or the theme,
you might want to keep these settings in sync across multiple devices.
That way you don’t have to go back and make the changes every time.
DuckDuckGo’s Cloud Save feature is completely anonymous, so it still
won’t collect information about you. When you have all your settings
lined up that you want to sync, just click Save Settings under Cloud Save in the Advanced Settings. This will prompt you to Enter a pass phrase that you’ll need to remember for the future to restore your data later. Click Save and you’re all set.
Now, when you want to restore your DuckDuckGo preferences, you can do so in the same spot: click Load Settings under Advanced Settings and enter in that pass phrase.
Maybe you’re the guy who fixes computers or a generous friend wanting
to help his less geeky friends. You must be using a USB Flash drive
with some most important rescue software.
And, one of them must be an antivirus software. It’s one of the most
important software you need to have on your external drive. Well, if you
don’t have one then here I’d like to show you some of the most used and
free portable antivirus software that you can add to your portable
software repository. Portable Antivirus Software | Shutterstock
Let’s dig in.
1. ClamWin
ClamWin
is one the most popular portable antivirus software. You can quickly
plug in your flash drive and scan for viruses. You get to select which
drive or which folder you’d like to scan. There is no limitation with
scanning. The real-time scanner is not available. Also, scheduled scan
is disabled because that’s not useful in a portable environment.
You can filter out specific extensions from scans and also limit your scan to a given number of files. Also, you can send yourself email alerts if any virus is detected. Most important is that the virus definition database is regularly updated.
2. Spybot – Search & Destroy
Spyware is one of those things that sometimes antivirus software
can’t track down. So an antispyware is a must in your flash drive. Spybot – Search and Destroy
is one of those most used portable antispyware available on the
internet. You can perform a system scan or a particular file scan.
Spyware gets quarantined and there after you get the statistics of the
scan.
3. Kaspersky TDSSCleaner
Rootkits are one of the major problems
in a computing system. Rootkits hide the existence of malware and
antivirus software can’t scan them. In such case, an anti-rootkit
software is also necessary. Kaspersky TDSSKiller
provides the security and prevents the rootkit from exploiting the
system. It can remove some of the common and known rootkits that might
have affected your system.
You just have to start the scan and it will generate the report. You
can change the parameters of scan where you can filter out system
drivers and system memory from the scan. Also, you get additional
options to check the digital signature of each software.
4. HijackThis
HijackThis
finds out if any malware has made any changes in the Registry or in the
system settings. It creates a log file and displays which files have
been modified. You can then further reset the values that were changed.
Along with the software, you get a bunch of tool including Uninstall Manager, Host file manager and Process manager.
5. FileAssassin
You might have come across warning like ‘Access is denied’ or ‘Cannot
delete this file’ while performing deletion of files. This occurs when a
malware has affected that file and it won’t let you delete it. In this case, FileAssassin
can be your rescue. It will not just delete the file but also terminate
the processes that were affected by it. You just have to select the
file and hit Execute.
If you want to delete the file from the software itself then you’ll
have to select the option for it. Otherwise, it will just unlock the
file for you to manually delete it.
Did We Miss Any?
These were some of the popular portable antivirus software of each
and every group. Right from rootkits to malware that won’t let you
delete files. If you think I missed an antivirus that is worthy of this
list then do let us know in the comments.
Apple's computers and mobile devices could be targeted more heavily by hackers in 2016, experts predict
Cybercriminals are increasingly
targeting Apple devices and 2016 will see a rise in attacks on its
operating systems, security experts suggest.
According to security
firm Symantec, the amount of malware aimed at Apple's mobile operating
system (iOS) has more than doubled this year, while threats to Mac
computers also rose.
Security firm FireEye also expects 2016 to be a bumper year for Apple malware.
Systems such as Apple Pay could be targeted, it predicts.
Apple is an obvious target for cybercriminals because its products are so popular, said Dick O'Brien, a researcher at Symantec.
While
the total number of threats targeting Apple devices remains low
compared with Windows and Android, Symantec is seeing the range of
threats multiply.
Last year, it was seeing a monthly average of between 10,000 and 70,000 Mac computers infected with malware.
"This
is far fewer than Windows desktops and we don't want to scaremonger.
Apple remains a relatively safe platform but Apple users can no longer
be complacent about security, as the number of infections and new
threats rise," said Mr O'Brien.
The
number of unique OS X computers infected with malware in the first nine
months of 2015 was seven times higher than in all of 2014, its research
found.
A significant amount of this spike is accounted for by
so-called greyware - applications that may not have malware attached but
can still be annoying to users, by serving up unwanted ads or tracking
their web-browsing habits.
Symantec also found seven new threats
aimed at Apple's mobile iOS platform, with jailbroken devices - those
that have been unlocked - being particularly vulnerable.
And hackers are also increasingly targeting corporations, where Mac use is now more prevalent.
A
corporate espionage group known as Butterfly which attacked
multi-billion dollar companies in 2015 developed malware tools that
attacked both Windows and Apple computers.
Walled garden
Traditionally
iOS has been seen as a more secure platform than Android because of the
more closed community that Apple runs for its apps but that is
changing, according to FireEye.
While it found that the vast majority - 96% - of mobile malware is targeted at Android devices, iOS is no longer immune.
According
to Bryce Boland, chief technology officer at FireEye, attackers are
increasingly "finding ways into Apple's walled garden, and that will
ramp up next year".
FireEye recently discovered that XcodeGhost,
iOS malware that Apple acted quickly to remove from its app store, had
found its way into the networks of 210 US businesses.
The attack was thought to be the first large-scale attack on Apple's app store.
The
introduction of new payment systems, such as Apple Pay, will add a
financial incentive for hackers, making it worth their "time and effort"
to develop new malware, FireEye said.
Mr O'Brien said: "We
haven't yet seen any threats targeting Apple Pay but anything that
involves a financial transaction will be of interest to hackers."
If you haven’t heard, LastPass has been sold to LogMeIn. Now, in tech circles, this happens all the time. But if you’re a LastPass user, you need to care about this sale because it could lead to problems in your future. LogMeIn has a bad rep. The service used to be free with a pro paid tier.
Suddenly, they cancelled the free tier. That in itself isn’t bad. It was the way they handled it. Customers only had 7 days to act and because thousands of users depended on it, they had to pay an ungodly amount just for the luxury of using a familiar service.
Time to say the last goodbye? | Image via Shutterstock.
And LastPass isn’t just any other service. It’s where all your passwords live. You don’t want to keep all this data at a place you don’t feel comfortable with.
All that said, LastPass has repeatedly said that the sale doesn’t change anything. That LastPass will work the same way it has before and it will work independently from LogMeIn.
But if you’re looking for alternatives, we’re here to help you out.
If you’re willing to pay for a software that’s well designed and puts security above all else, go for 1Password. Yes, the $50 Mac/Windows apps and the $10 pro upgrades for the iOS and Android apps might sound steep but once you buy them, there’s no additional cost.
Plus, 1Password doesn’t use the cloud to save your passwords. It’s just a database file that you are free to save anywhere (if you choose, you can save it on Dropbox which makes it easy to access it from other devices).
Because the 1Password database file lives on your device, it is much harder to hack. The hacker would need to access your device physically.
Here’s a rundown of all the important 1Password features.
2-factor authentication support.
iOS and Android apps.
Sync passwords over local Wi-Fi instead of using the internet.
Save everything that’s important – passwords, documents, credit cards and more.
Browser extensions for easily filling in passwords on desktop.
2. KeePass
This one’s for the pro users and the geeks. KeePass is based on the same 1Password philosophy. But it’s not as easy to use. Syncing passwords between devices isn’t easy and there’s no good Chrome extension for auto fills.
But KeePass is completely free and open source. If you know what that means and appreciate it, then KeePass is for you.
The average internet user should probably stay away from KeePass.
3. Dashlane
Dashlane has been climbing the popularity chart for the past couple of years. It’s the closest option you have to LastPass. Your passwords are saved in Dashlane’s cloud – they are encrypted of course.
Dashlane also has some pretty sweet features like easy sharing of passwords with your colleagues, quickly updating your password at a service and more.
The only problem is Dashlane’s pricing structure. The free account only lets you use Dashlane from the device you signed up with. So if you sign up using your iPhone, you can’t access passwords on your PC. To do that, you’ll have to pay the steep $39.99/year subscription fee.
Instead, just pay $50-70 for 1Password for all your devices and be done with it.
How to create strong passwords that you’ll actually remember: Don’t know? We can help you out.
Newer, Smaller Alternatives
The three options above are pretty established. They’ve been tested by thousands of users and are bound to work. You can also add iCloud Keychain and RoboForm to that list.
But recently I’ve been seeing new smaller password management services pop up. Some of them are open source, some of them are not. Some of them are only available on Mac and iOS, some are on all platforms. I have not personally tested these services yet.
But if you’re looking for something new or an open source password manager that’s actually pleasant to use, the links below are worth checking out.
I know 1Password sounds like a big investment and a bit alien but once you get started, you’ll get a hang of it pretty easily. Just export your passwords from LastPass, add them to 1Password, or any other service that you choose, and you’ll be on your way.
Out of curiosity, which service did you choose? Or are you still looking? Share with us in the comments below.
Macintoshes don’t have the same problems as Windows computers with malware or adware, but that doesn’t mean they are immune. The attacks are different on a Mac, but just as annoying. Luckily, there are a few ways to remove unwanted Mac programs and prevent them from coming back.
The most popular infections I see in the wild are Genieo and InstallMac. They usually tag along with legitimate programs downloaded from software repositories. Typically someone searches for a popular program and clicks on one of the top search results, which is an ad.
Once the problem software is on the Mac, Safari or another browser’s search engine changes and ads are injected. Sometimes the computer isn’t infected, but an intrusive ad pops up and prevents the user from surfing. These ads either take advantage of the Mac’s resume feature or use a JavaScript that prevents Safari from going further.
Scareware window? Use Safe Mode to Get Un-Stuck
Some of these infections start as a Safari ad that won’t go away until you click a link or call a special number. The window might claim you are being watched by the FBI, like PC Ransomware. A few of these ads will start talking to you. Don’t fall for that scam. To get Safari back in order, first you’ll need to force quit Safari.
Hold down the Command + Option + Esc keys all at the same time. That brings up the Force Quit Menu. Select Safari and then Force Quit. Sometimes the Safari window is stuck and the Force Quit option doesn’t work. In that case, press control+option and click on Safari from the dock and select Force Quit. That stops the annoying ad in Safari. The same steps work for Firefox and other browsers on the Mac.
Need to Force Quit a Mac Application?: Check out other ways of stopping any Macintosh application. As ads get more sophisticated, it may be harder to quit Safari or other browsers.
Some browsers are set to re-open the last window that was active before closing, so you’ll face the same problem again. To fix that in Safari, hold down the shift key while opening up Safari. That prevents any previous windows from coming up.
With Firefox, holding down the option key opens it in safe mode and disables the start screen. With Chrome, you’ll need to start in incognito mode, but you may need a program to help with that. Then you can move onto removal.
Download Adware Medic to Remove the Infections
When you have a working browser, the best program for removing Mac adware is Adware Medic. It’s designed to remove browser plugins that redirect search results and inject ads. The program is free. It requires Mac OS X Lion 10.7 or higher.
Users of 10.6.8 Snow Leopard or below will need do a manual removal. Adware Medic’s site has a great guide for manual removal. For Snow Leopard, the Sophos Anti-Virus for Mac Home Edition does a good job of removing malware and is also free.
Apple’s Removal Guide: Apple has its own guide for removing Mac adware, but it’s hard to follow and covers just the operating system and Safari.
Prevent Future Infections with Smart Browsing
Mac infections don’t usually come from the same sources as PC infections. They’re unlikely to be attached to an email or embedded in a pdf. They’ll either be part of what appears to be a legitimate download or otherwise trick a user in download the payload with an ad. Software that automatically installs by just going to a website is pretty rare.
The most popular trick I see is an ad that convinces the user that Adobe Flash Player is out of date. I almost fell for that trick once. My Mac warned me before I installed it.
If you need to download software for your Mac that isn’t available in the App store, surf directly to the manufacturer’s website. Avoid searching for the product name since that may bring up ads. Search for the manufacturer and then find the product on their website. As an example, instead of searching for Adobe Flash Player, search for Adobe.
Apple’s Antivirus is Built-in: Apple’s Xprotect keeps your Mac from getting infected most of the time. It updates itself when Apple updates the MacOS.
Install Blocking Software
Scamzapper is a Safari Extension designed to prevent ads from locking up the browser. It blocks those JavaScript windows that prevent the user from moving forward in the browser. If you or someone you know keeps getting hit by those ads, Scamzapper will keep you clean.
Otherwise, blocking ads and Flash whenever possible reduces the risk you’ll be tricked into downloading something you didn’t intend to. Two extensions I recommend are ClickToFlash andAdblock Plus. They prevent the annoying ads from coming through, including infected ads.
Safe Than Sorry
Malware and scams will continue on the Mac because the criminals are successful with it. A few programs installed in advance can protect you and your family from these internet nasties.
We had loved LastPass so much that we had actually called it The Best Password Manager. So, when the story of the hack broke out a while ago, we were all in a state of shock. But, does that mean everyone ought to ditch LastPass and use something else? Are your passwords safe in the cloud? Can we trust the company again? That’s what we’re trying to find out.
Needless to say, this is the first thing that needs to be done. Panicking, or worse, spreading false information via any medium, is just not the right way to respond to any crisis. While it’s natural to feel scared when you read a news like this, you have to realize that unnecessary panic just does not serve any purpose. In their blog post, LastPass have made it clear, and I quote,
In our investigation, we have found no evidence that encrypted user vault data was taken, nor that LastPass user accounts were accessed.
Yes, it does go on to say that
The investigation has shown, however, that LastPass account email addresses, password reminders, server per user salts, and authentication hashes were compromised.
But, what does this mean, you ask? Simply stated, it means while all your passwords are safe, other info may not be. For which, again, the blog post has already stated a few helpful tips.
Yes, the data from password managers is stored on the cloud, but the information is encrypted right on your computer. And even though the cloud computing architecture does involve a slight risk, you can still rest easy knowing that all encrypted data is never stored there. Which includeall your passwords.
Helpful Tip: Check out our Ultimate Guide on passwords to know everything about creating and managing passwords on the internet.
Prevention is Always Better Than Cure
This old adage could never be more relevant than in these times of internet snooping and loss of privacy. Here are some steps that you should follow when it comes to your LastPass account, to ensure you don’t lose your sleep over such incidents.
Change the Master Password
To change the Master Password of LastPass, simply click on Preferences, where you will find the Account settings section on the left. Clicking that will give you the option to Click here to launch account settings as shown below.
Clicking that will open a new tab, where all you need to do is hit the Change Master Passwordbutton and go for a newer (and stronger) alternative.
That’s it, the most important step that you should be doing after this incident is done!
2-Factor Authentication and Other Security Options
We feel it is a good idea to use 2-Factor Authentication wherever possible, and especially in places where sensitive data is stored. LastPass is absolutely correct in suggesting the use of this service and we feel that you should do this right away, after changing your master password. In fact, while you’re at it, do consider adding the 2-Step Authentication Factor to all the services you use which hold sensitive data.
In LastPass, you will find Multifactor Options in Account Settings (see above). This is where you will find options to further secure your LastPass account. You will also see the Grid Authentication option that we have written about before.
Country-based Restriction
Another layer of security that LastPass entails its users to explore is the country-based restriction policy. Once enabled, this will enable only devices originating from the country of your residence to access your LastPass data. If a device from any other country tries to access it, they will show an error message. We’ve covered this in much detail and you should definitely read it, if you haven’t already.
Still Worried?
Don’t be. There’s nothing more to be done here. LastPass has already updated their security and is already prompting users to be verified via email, if they are using a new device or a new IP. To verify this, we tried just that and were happy to report that this step works just as advertised.
Existing users are also being prompted to change their Master Password, but even if you don’t get that prompt, we urge you to do it anyway. Lastly, we’d like to quote Jeremi Gosney (a password security expert at Stricture Group) who spoke to Ars Technica about the hack –
On an NVIDIA GTX Titan X, which is currently the fastest GPU for password cracking, an attacker would only be able to make fewer than 10,000 guesses per second for a single password hash. That is proper slow! Even weak passwords are fairly secure with that level of protection (unless you’re using an absurdly weak password.) And this doesn’t even account for the number of client-side iterations, which is user-configurable. The default is 5,000 iterations, so at a minimum we’re looking at 105,000 iterations. I actually have mine set to 65,000 iterations, so that’s a total of 165,000 iterations protecting my Diceware passphrase. So no, I’m definitely not sweating this breach. I don’t even feel compelled to change my master password.
In fact, quite a few members of our own team use the tool and we have done exactly the same things that we have stated above. And now we wish to spread the knowledge to as many people as possible.
Want To Try Alternatives?
Okay, if you feel that you have lost faith in LastPass because of all this, then of course, there are always alternatives. If you’re willing to invest a little money (and some of that lost faith) then there’s always 1Password. It’s the same architecture and security measures at play, but Agilebits, the company behind 1Password, does have a better track record than LastPass. By that, we mean that it’s never been hacked. Hasn’t been reported, to be more precise. Yet.
Even though it is not as convenient as 1Password, if you’re willing to play around, a few plugins can be added to match the functionality of its paid peer. It does take some patience, though, so be prepared.
Our 2 Cents
It’s very easy to blame a company and say they weren’t careful with your data. But that’s as good as blaming banks when there is a robbery. People haven’t stopped putting their money there and neither should you stop trusting password managers, just because one was hacked.
We’re not even saying that the security was lax on LastPass’ part, but they definitely need to pull up their socks. It wasn’t the first time a threat was detected in their system, but both times nothing major was stolen/lost. They acted quickly and promptly notified users and have already dealt with the security issue which lead to this. With a little more precaution yourself, you can ensure a much happier state of mind. If you can spend all that time thinking about your bank balance, we’re certain you can spare a few thoughts for the passwords that keep them safe, too?