TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Rotating Your Passwords After a Password Manager Breach

Kassie Kimball · 2023-11-02 · Read original ↗

ATT&CK techniques detected

2 predictions
T1552.004Private Keys
79%
"keys that were exposed ( e. g. ssh, gpg, tls ). - prioritize ones without encryption or where the encryption password was also stored. - this is probably the biggest headache of all because it involves revoking key signatures and removing ssh keys from all systems where it was ad…"
T1555.005Password Managers
60%
"what i realized was that it wasn ’ t all or nothing ; not all these dusty old accounts were of the same value to me ( or an attacker ). i decided to make a prioritized list for me to work through. this turned out to be a much more fruitful exercise than just hoping the problem wo…"

Summary

| Ethan Robish It’s been nearly a year since Lastpass was breached and users’ encrypted vaults were stolen.  I had already migrated to a different password manager for all my […]

The post Rotating Your Passwords After a Password Manager Breach appeared first on Black Hills Information Security, Inc..