How Do Password Safes Like “LastPass” Provide Security?

Roughly speaking, how exactly do the password managers to whom we entrust our login information, address and bank card information on 50 sites protect our information?

We used it in the era when computers started to enter every home. with 123456789 And with QWERTY The reason why we abandon our passwords and switch to new passwords that are quite complicated compared to them is cyber security They had concerns. More and more every day website and app Since it is available, the number of passwords we need to remember is increasing.

That’s why most of us either use the same/similar password everywhere or have to keep a lot of different passwords in our minds. However, when some applications ask us to change the password periodically, everything can go upside down. For this reason and because the number of passwords is increasing, many people password manager He is undecided whether to use it or not.

The most basic question: What is this password manager?

Password managers; They are digital safes that allow you to store information such as address, phone number and bank card in addition to your passwords. This safe, which contains your passwords, stores your password and address information when you want to log in somewhere. automatically It makes filling in easier.

When you want to make a purchase, use your wallet. take out your card You can transfer your card information without having to enter the numbers. Although all this sounds good, we need to enter one of these applications where we enter our data. cyber attackers Imagine reaching it. Can’t these people, who only have access to one application, easily obtain all our passwords?

Let’s explain why this is extremely difficult, without getting confused.

Avoid these password managers because they are so common. LastPass Let’s take it as a basis. When you want to store your passwords here, you first create a LastPass account and create a password for this account. master password You determine. Of course, this is different from the password you use for Webtekno membership, for example.

When you create your account plugin or app As a password manager, it asks for permission to save your user information on the sites you visit. In this way, your information is placed in your private safe. Then Google automatic form filling LastPass can take over the feature.

Since LastPass itself is a cloud-based service, your LastPass vault containing your passwords On LastPass servers hiding. So how is security here ensured?

When you want to access your password safe, you first create a key to open this safe. To do this, you first enter your master password. After the verification step, your master password and e-mail address will be sent to you with the latest updates. out of 600,000 combinations passing by one safe key It creates.

After this, all that remains is to access our vault on the server. For this, the password formed by combining our e-mail address and password 600,000 times is again entered into 600,000 combinations with our master password and transmitted to the safe on the server. without seeing our master password He realizes that we are the ones trying to access the safe.

As a result, we obtain one verification and one safe key. verification key to the vault on the server While it provides us with access, the safe key also enables us to open it. To ensure the security of both keys, your master password must be strong.

In other words, while a key you create opens a key leading to the safe, the other key you create in addition to it helps you open that safe.

Locker Password Manager

And you need to enter the password needed to create this key in the first place. LastPass You do not forward it to password managers such as. Therefore, even if a copy of your safe is compromised, as we will discuss shortly, it is almost impossible to open it. “AlmostThe ” part is important at this point.

“So can we trust them right now?” Although the question will come down to a personal decision, let’s touch on the unfortunate events that LastPass has experienced recently.


source site-33