The Worst Cyberattack I've Ever Seen...

Поделиться
HTML-код
  • Опубликовано: 27 дек 2024

Комментарии • 1,1 тыс.

  • @SomeOrdinaryGamers
    @SomeOrdinaryGamers  Год назад +191

    Check out the newest episode of the podcast:
    ruclips.net/video/0S1QPBnp8BM/видео.html

  • @ThioJoe
    @ThioJoe Год назад +193

    Bruh. Not only did the guy not update plex in years, but presumably also had that OPEN TO THE INTERNET. What in god’s name is he doing working at a security company.

    • @ikjadoon
      @ikjadoon Год назад

      LastPass also never upgraded its password hashing for 10 YEARS on some customers. LastPass is still adding "noindex" HTML tags to its breach notices, so people can't find them on Google. LastPass as a policy does NOT encrypt site URLs (hello anyone with an AshleyMadison login saved). This company is a scam, trying to milk anyone that doesn't understand how dangerous they are.

    • @RazvanHardcore
      @RazvanHardcore Год назад +2

      ​@@Instabruh.User.. you talk about the Macv-Sog?
      man we no longer are in Vietnam

    • @RazvanHardcore
      @RazvanHardcore Год назад

      @@BlockedUser420 no shit

  • @skrounst
    @skrounst Год назад +608

    My work laptop given to me by my company restricts basically everything from being installed onto it. I can get VERY basic things from THE COMPANY'S app store, but the Microsoft store isn't even installed on it, so this EXACT scenario doesn't happen. You'd think that a company that deals with safeguarding people's passwords would be even more strict than my company when it comes to potential risk. Unreal.

    • @ThatLoudCockatoo
      @ThatLoudCockatoo Год назад +45

      My work laptop is the same way. We can't install anything that isn't already cleared by security. Anything new has to go through a whole audit process. It blows my mind that bot all companies do this.

    • @whothou9154
      @whothou9154 Год назад +50

      That's probably because you're a non-IT employee.
      Engineers/IT typically get local admin rights to their and everyone elses computers though to be able to install almost anything.
      Though I wonder if a Dev OPs Engineer would get local admin as their technically not IT but software.

    • @MagosVeridian
      @MagosVeridian Год назад +10

      Mine's the same. Can't even plug USB sticks into it. The fact that this was even possible is shocking.

    • @FragITFPS
      @FragITFPS Год назад +8

      @@whothou9154 yes typically software engineers will get local admin for virtualization/debugging/deployment

    • @makarambles
      @makarambles Год назад +21

      ​@@whothou9154 I'm an entry level software engineer and have local admin rights on my computer but not on dev environments (remote desktops). Only a few people at the company have the ability to generate admin passwords for dev environments and those passwords last for 6 hours. This is a small business, less than 50 people.

  • @evillecaston
    @evillecaston Год назад +1009

    I wouldn't call it the worst cyberattack, but it's definitely one of the most pathetic. The fact that someone with high security clearance would use an obviously unauthorized app on a work device and then not update it for years....Normally I don't like the idea of industry blacklists, but this person went above and beyond to earn a spot there.

    • @YumiNeeosu
      @YumiNeeosu Год назад +57

      @Don't Read My Profile Picture sure

    • @grzegorzdomagala9929
      @grzegorzdomagala9929 Год назад +22

      I suspect he didn't update it because it was unauthorized and could not reach update server :)
      Sometimes overly aggressive security policy may incentivie user to do really stupid things...

    • @mattstorm360
      @mattstorm360 Год назад

      @@grzegorzdomagala9929 Im impressed they managed to install it.

    • @HeavyMedals
      @HeavyMedals Год назад +1

      @@YumiNeeosu lol these accounts have to be one of the lamest attempts at getting attention I’ve ever seen .. smh makes me wonder who wastes time doing this or programming a bot to do this and what their median age is lol.. i dont get it ¯\_ (ツ)_/¯

    • @NazzyDragon
      @NazzyDragon Год назад +99

      @@grzegorzdomagala9929 stop using non work programs on work machines, it's that goddamn simple.

  • @graumail
    @graumail Год назад +831

    As a fellow engineer, I’m screaming into the void at this entire situation.
    A 2020 CVE!?!?

    • @epicm999
      @epicm999 Год назад +20

      Saw this before going in the video. I'm having a hard time accepting this...

    • @mhtate3626
      @mhtate3626 Год назад +54

      There's some 2013 CVE's that have either resurfaced or been republished, for various reasons of course. You don't have to go far to even find "top companies" in whatever industry skimping on this kind of stuff, because IT is only ever seen as a cost center. I'd still be shouting into the void if I weren't so tired.

    • @TaylorWilmes
      @TaylorWilmes Год назад +5

      This clickbait is hella cringe lol.

    • @kristiyanivanov7414
      @kristiyanivanov7414 Год назад +2

      noobs, sir, noobs

    • @ayushmanthapa_onion
      @ayushmanthapa_onion Год назад +8

      During my pentest engagements, i still find eternal blue ALL THE TIME.
      Businesses and people really beed a LOT of help securing themselves

  • @BiakMusic
    @BiakMusic Год назад +2943

    I swear muta puts out a the worst hack ever video at least once a month

    • @microsoftdeveloper8396
      @microsoftdeveloper8396 Год назад +43

      true 🤣

    • @supersam5802
      @supersam5802 Год назад +306

      hackers must be looking for the one piece

    • @grassmonkeyO5
      @grassmonkeyO5 Год назад +99

      THE ONE PIECE IS REAL!

    • @Sebastianator01
      @Sebastianator01 Год назад +65

      Damn man seems like technology and hackers are getting better every day to the point muta has to be the one to call them out

    • @EnaTenkiyoGamer
      @EnaTenkiyoGamer Год назад +5

      ​@@grassmonkeyO5 😂

  • @chrits3396
    @chrits3396 Год назад +286

    So in summary. Don't mix personal with work. This includes mixing your company data with your personal data.

    • @epicm999
      @epicm999 Год назад +9

      Thanks for the reminder 👍

    • @randomuserame
      @randomuserame Год назад +6

      This includes your personal life with your work life too. Work is not your friend, and your coworkers are not family.

    • @Ew4ya
      @Ew4ya Год назад

      what about a spontaneous urge to wack one out?

    • @chrits3396
      @chrits3396 Год назад +1

      @@Ew4ya that's why you wack one before you get to work.

    • @cwill2127
      @cwill2127 Год назад

      @@Ew4ya do it to memory

  • @NETCORRUPTER1776
    @NETCORRUPTER1776 Год назад +903

    Cyber attacks are a crazy thing, the thing that surprises me the most is even allied countries are attacking each other non stop everyday. Trust no one.
    Don’t go into the comments it’s a cringe cesspool in this thread.

    • @ImTheWarlock64
      @ImTheWarlock64 Год назад +109

      There is not such thing as allies in the modern society, just bussiness partners.

    • @furret1_
      @furret1_ Год назад +65

      @ItzSyakirin r/youngpeopleyoutube

    • @sanjuansanjuan4023
      @sanjuansanjuan4023 Год назад +14

      Well allied countries are allies as long are there’re any benefits. Also the alliance is of course made by the previous president or previous head of the country.
      An example would be the Philippines. Just a few years ago the president strengthened their alliance with the US. But the following presidents either dislikes the US or values the alliance with China more. But the Philippines still has an alliance with the US even with all the stuff that happened.

    • @thizlam4810
      @thizlam4810 Год назад +10

      @ItzSyakirin this is the cringiest thing I’ve read. You have got to be no older than 8 years old.

    • @damintten
      @damintten Год назад +1

      Sounds like your part not of the muscular class so I'll enlighten you, it's called steal sharpened steal duuuuu.

  • @murmer_
    @murmer_ Год назад +106

    I need a "Worst Cyberattack Tier List" that Mutahar has covered to date. Please.

    • @Kahrak
      @Kahrak Год назад +3

      Now thats a good video idea

    • @NETCORRUPTER1776
      @NETCORRUPTER1776 Год назад

      This would be awesome!! Everyone upvote this!!

  • @LordyT34
    @LordyT34 Год назад +28

    It just goes to show that hacking isn't so much "cracking code" as much as it is exploiting negligence and ignorance

  • @invisibledog93
    @invisibledog93 Год назад +189

    I blame the company for hiring irresponsible, no-good engineers in senior positions.

    • @Labyrinth6000
      @Labyrinth6000 Год назад +30

      They can’t even find good employees to replace old engineers, that’s why. They ask for too many tasks and responsibilities which increase the odds of this happening.

    • @user-qr4jf4tv2x
      @user-qr4jf4tv2x Год назад +1

      ​@@Labyrinth6000 this

    • @decmade
      @decmade Год назад +7

      cronyism side-effects if you ask me. a buddy hires a buddy but your buddy sucks at his craft so now this. and yeah, the job descriptions HR come up with are always ridiculous so they have an excuse to hire who they like the most without getting sued

    • @raylax7056
      @raylax7056 Год назад +1

      nah its just idiocy some dude had his pw updates probably set to not update due to some work based restrictions initially and forgot to ever update his policy once his issue was resolved, lol 3 years too late

    • @PizzaCologne3
      @PizzaCologne3 Год назад

      sometimes, its the lack of growth/innovation & sometimes its the job descriptions responsibilities over little pay, no one wants to work there, sometimes the case they end up hiring unqualified or not experienced enough to handle the position without any help.

  • @canonicalheat2376
    @canonicalheat2376 Год назад +10

    According to the article at Ars Technica, it was the developer's home computer. Apparently "only" 4 senior devs were allowed to access the vaults via their home computers which really, really made my head explode.

  • @athing8523
    @athing8523 Год назад +23

    Can somebody get a compilation of Muta saying something along the lines of "And no I'm not exaggerating THIS is the worst hack" it would be beautiful. Not as a flame, as a lovely memory

  • @shadic1988
    @shadic1988 Год назад +246

    This is why pen and notebook is crucial. But yes Lastpass should be sued

    • @JamesSheldonUnofficial
      @JamesSheldonUnofficial Год назад +56

      @ItzSyakirin "look mommy I can get people's attention too"

    • @swide2750
      @swide2750 Год назад +17

      you can easily host a offline encrypted vault of passwords

    • @RogueAmendiaresyourgirl
      @RogueAmendiaresyourgirl Год назад +10

      Me: *laughs in KeePass*

    • @MenchieExtrakt
      @MenchieExtrakt Год назад +11

      Are you gonna bring that password notebook to work? What if your colleagues or someone else steals it.
      Pen and paper clearly has higher risks.

    • @manehattgeeheck
      @manehattgeeheck Год назад +2

      @@g2jxGhF5G8z1gL7S it’s not tho 😂

  • @DirtyPlumbus
    @DirtyPlumbus Год назад +112

    So this company was proven unreliable a year ago and the US Marshalls continued to use it?

    • @amberdent651
      @amberdent651 Год назад +12

      Having had to interact with USMS, I'm not surprised.

    • @someonethere1122
      @someonethere1122 Год назад +52

      The US Government will use outdated technology until they are forced to upgrade. The jail in my town was primarily running on Windows 95 until 2010

    • @breguera77
      @breguera77 Год назад +6

      @Broskisnowskinot necessarily. You should see the price tag on some of the hardware and software they use. It feels like they go for the most expensive but least effective stuff. It’s wild

    • @dhairya8238
      @dhairya8238 Год назад +5

      ​@@breguera77 The government never pays consumer prices. They're quoted higher amounts because of their (pretty much) unlimited budget. 'Military grade' things for the consumer will be priced lower but they'll be priced wayyyyy high when they're sold to the military. Which makes them opt for 'bottom of the shelf' equipment sometimes.

    • @puddi_Cat
      @puddi_Cat Год назад +3

      ​@Broski Snowski nah, it means the supplies from the biggest lobbier.

  • @chriswaller8780
    @chriswaller8780 Год назад +23

    You forgot about the 4th option. Writing them down in a secure location (like a locked diary or something). And option 5, encrypting and storing your own passwords on your own.

    • @sinonimo8719
      @sinonimo8719 Год назад +1

      Yes...no, big nope. Might work, perhaps even worse than remembering passwords you can lose it too, someone else can take it, it can be damaged by a flooding idk too many things

    • @chriswaller8780
      @chriswaller8780 Год назад

      @@sinonimo8719 Why are you storing your passwords in only one place?

  • @GGSmile1
    @GGSmile1 Год назад +40

    The fact that they let a cyber sec engineer use any type of personal shit on the same device that is used to access company data is crazy

    • @raylax7056
      @raylax7056 Год назад +1

      you can't physically stop a worker from it, its kinda not possible

    • @AJ-po6up
      @AJ-po6up Год назад +3

      He was working from home so there was no way to stop him.

    • @aeghohloechu5022
      @aeghohloechu5022 Год назад +6

      ​@@raylax7056 you can audit them, you can educate them, you can punish them

  • @treebush
    @treebush Год назад +9

    This is why hard paper is still king and I majority use paper to keep track of everything like an old school mobster accountant

  • @Rahenno
    @Rahenno Год назад +11

    My IT instructor drilled in my head, "Always stay updated."

  • @DawnOfTheOzz
    @DawnOfTheOzz Год назад +6

    My brain still glazes over whenever Muta talks about cyber attacks. But him mentioning that streaming movie app seemed interesting. I dunno how safe it is but that's certainly one thing to keep on my radar.

  • @o0Hidden0o
    @o0Hidden0o Год назад +3

    “Muta this the 4th time you’ve shown the class “the worst cyber attack you’ve ever seen” this year”

  • @chungushimself3712
    @chungushimself3712 Год назад +3

    Bro, i had the notif on my iphone for this upload for three minutes, and i came to the channel home page on my pc and i literally couldn't find this video. I had to search for it word by word in the search bar. That's weird.
    Anyways. Love the content as always. Truly give us the widest range of interesting internet hermit shit i've ever had the joy of accessing.

  • @aaronleonard641
    @aaronleonard641 Год назад +52

    Tbh I use a copy book as a password manager, people say it's waste of time to write down my passwords into it every time I create an account on something but it's shit like this that only makes my case stronger 😅

    • @R3AL-AIM
      @R3AL-AIM Год назад +13

      People literally forget it takes 30 seconds to a minute to write down an email, password and title to what the account is for. Also, you can't hack a note book in someone's closet...

    • @electron6825
      @electron6825 Год назад

      KeePass.
      Just use KeePass.

    • @steventalavera1995
      @steventalavera1995 Год назад

      Same

    • @katraven981
      @katraven981 Год назад

      same

    • @context.Background
      @context.Background Год назад +1

      @@R3AL-AIM a house fire can

  • @guestguest9
    @guestguest9 Год назад +38

    I’ve recently started watching you btw and I do like the style of these. They feel fairly personal, they’re usually shot at night too which is similar to my sleep schedule, and it’s just like having a chat and laughing about news nowadays. Keep it up, love the relaxed feel to these types of vids.

    • @jahjoeka
      @jahjoeka Год назад +1

      Relaxed?

    • @robinjonk
      @robinjonk Год назад +1

      You've just perfectly described why I've been watching Muta for years now! 😅

  • @PlanetTapZoid
    @PlanetTapZoid Год назад +3

    This reminds me I need to reflash my rooted phone to update the security on it soon.

  • @whiteflagstoo
    @whiteflagstoo Год назад +7

    You know once upon a time around high school I was a last pass user. When I got disillusioned about security in "The Cloud" (someone else's computer) I decided to store my passwords myself with keepass. Probably not the greatest thing but not the absolute worst.

    • @m0-m0597
      @m0-m0597 Год назад +1

      i use keepass, too :c)

    • @heyhackurs
      @heyhackurs Год назад

      Anything at this point is better than LastPass

  • @Supervhizor
    @Supervhizor Год назад +1

    Im a senior engineer and rarely update my stuff. Bleeding edge bites you too. Just don’t use the work pc for non-work things.

  • @johnsmith-mo6kz
    @johnsmith-mo6kz Год назад +7

    There is also a fourth option... just writing down your passwords on pencil and paper 🙄

    • @heyjeySigma
      @heyjeySigma Год назад +3

      efficient until Jamal in the hood comes to your house with a wrench and beats you up and takes your papers lol.
      or worse yet -your house burns or gets flooded.
      lets be honest there is no such thing as a 100% failproof solution.. maybe 95-99%

    • @johnsmith-mo6kz
      @johnsmith-mo6kz Год назад

      @@heyjeySigma I agree but I mean who in their right mind ever thought that paying a company to store all of your passwords would be a smart idea. They say that it is only stored on your computer sometimes but facebook says they don't sell your data.

  • @WaylandYT
    @WaylandYT Год назад

    I can't remember how many friends and family I warned to stay away when LastPass did their huge social media advertisement campaign because how could they not be painting a huge target on their back from square one? Sure the zero knowledge model helps delay compromises, but you can bet bad actors with enough funding can crack them. It does suck that at this point it boils down to "I told you so" which can hurt the reachability of the people who need to heed the warnings most.
    Keep fighting the good fight Muta.

  • @ChosenHawk64608
    @ChosenHawk64608 Год назад +4

    This is why I save my important accounts on a separate drive with my car keys and useless stuff in pass managers

    • @sommerforrest2694
      @sommerforrest2694 Год назад

      How do you do that? I'm keen to know how to stay safe.

    • @ChosenHawk64608
      @ChosenHawk64608 Год назад

      @@sommerforrest2694 Just have some notepad files and save it into a flash drive or something. I didn’t label which account is which either so if someone steals it, it wouldn’t make any sense

  • @maartentoors
    @maartentoors Год назад +1

    Wiser words have not often been uttered.
    I (for one) am glad LastPass has been open about the extent of the intrusion.
    Keep spreading the gospel, I testify.

  • @Tokena14
    @Tokena14 Год назад +4

    17:00
    youre a real one muta. thanks for bringing a smile to my face, im poor and lonely but you always stay real and make it feel like ur talking to us as a friend.

  • @Dizzz127
    @Dizzz127 Год назад +1

    I keep seeing ads for all sorts of password storage apps but I keep reminding myself that nothing on the internet is safe and putting all your passwords into one single database is just asking for trouble.

  • @Kannonify
    @Kannonify Год назад +6

    Honestly my favourite video from you so far Muta, imho your best work yet. Good stuff my friend

  • @AaronNewton
    @AaronNewton Год назад +1

    This was the best Cybersecurity related video to date by muta, funny and informative. This channel in the last several years has been a big part in why I'm getting my masters in Cybersecurity right now. Keep up the good work!

  • @theinquisitor18
    @theinquisitor18 Год назад +8

    Bitwarden FTW. I let Bitwarden manage my vault. While I'd like to run my own Bitwarden server, I just don't have the energy to do IT work off the clock. I love this industry, and I love Linux so much that I run it as a daily, but sometimes I just want to step away after work.

  • @dillonteakell5365
    @dillonteakell5365 Год назад +1

    As a student in cybersecurity, I love watching Muta

  • @NodSquad
    @NodSquad Год назад +7

    Bitwarden with a Yubikey for 2fa is my personal favorite

  • @david.cutipa
    @david.cutipa Год назад +11

    You know it's a mutahar vídeo when mutahar is in it...

    • @MrAw3sum
      @MrAw3sum Год назад

      you know it's a video when moving pictures

  • @PlanetTapZoid
    @PlanetTapZoid Год назад +3

    Had a botnet get into an apartment complex I was living in not super long ago. Had me paranoid to the point where I was having a hard time differentiating between actual things related to the attack and my own imagination reaching for connections. Ended up having to move after having to close my bank account and opening a new one. Thankfully, nothing was stolen. I feel bad for the people still living there.

  • @Pers0n97
    @Pers0n97 Год назад +192

    Still laughing my ass off at the very idea that anyone would think that hosting all their credential behind a single account, thus creating a single point of failure, was a good idea.

    • @owacs_ender
      @owacs_ender Год назад

      I think there is some merit to the idea. If the password manager you use is remotely competent, that single account (more accurately, a username/password combination) is used to derive an encryption key that is not stored anywhere. That encryption key is used to encrypt and decrypt your password manager's vault.
      Now, the obvious caveat is that if someone gets access to your vault, they have a pretty good way of attacking it by brute-forcing the username/password combination.
      But here's the kicker, when you remove the need to put a lot of thought into generating a hundred plus different passwords and instead just have one password, you can focus your energy on making that single password a lot stronger.
      Of course, this is reliant on the fact that you know how to do this, but this can be remediated with devs that know what they're doing and good documentation on how to make good passwords. You may also opt to add a pepper to your passwords (i.e. have a random string you add to every password that you don't write down), wherein even if the vault gets compromised, the attacker still has to figure out what your pepper is, and that adds additional effort of compromising other databases or brute forcing account logins.
      Additionally, if you don't trust a cloud database hosting all of your passwords even if they're end to end encrypted, you can always opt to self-host, which significantly increases the difficulty of compromising your vault (since, you know, someone would have to get into your network, compromise your Bitwarden database, and THEN brute force the username/password combo. And you can always opt to use a password book, but usually that succumbs to a similar problem with more of a headache and no possibility for encryption.
      One final note: Brute forcing these vaults is often more difficult than brute forcing an individual password because again, if the provider knows what they're doing, the derived encryption key should be made with an algorithm that takes time and resources to generate. Of course, in a single attempt a few extra milliseconds is negligible, but when we're dealing with millions and billions of attempts? That can be the difference between losing your vault and an attacker giving up and moving on to an easier target.
      That said, yeah, I completely get the hesitation with "putting your passwords in the cloud."

    • @naughtyhieroglyph669
      @naughtyhieroglyph669 Год назад +16

      The sad bit is cybersecurity "experts" still screech that you need to use a password manager.

    • @daverules
      @daverules Год назад +16

      better then using the same 8 character password over and over.

    • @itwsntme
      @itwsntme Год назад +9

      And the other option is.... ?

    • @Mina-Ashido97
      @Mina-Ashido97 Год назад

      @@naughtyhieroglyph669 Using a password manager is factually the best option out there, just not one hosted by a company, host your own Bitwarden server or just use KeePass and make backups of the files, done, no more security risks.

  • @knolsey
    @knolsey Год назад +2

    a WitSec leak would be catastrophic, even if no one was harmed. the amount of resources that would need to be expedited to save everyone would be staggering.

  • @josueveguilla9069
    @josueveguilla9069 Год назад +2

    "Why am I not surprised?" - John Stewart/Green Lantern (Justice League Animated)

  • @raymondkey1952
    @raymondkey1952 Год назад +5

    This could have a lot of security risks for all kinds of institutions and companies. Imagine how that data could be correlated, I hope this isn’t a domino effect about to go down. WEF and FDIC talking about cyber attacks and here this happens…

  • @tombear2675
    @tombear2675 Год назад +1

    Babe wake up new "the worst cyber attack ever" lore just dropped

  • @KnightSlasher
    @KnightSlasher Год назад +94

    It's amazing a password manager subscription got hack so that being said lets be honest it could've been a lot worse, at least it was targeted towards certain people and not everyone

    • @swaggamesph3342
      @swaggamesph3342 Год назад +2

      We really don't know. Any subscription company can sell information to other companies. And in case those other companies will need more information on a certain user from the subscription company, the best excuse is getting hack while providing the information to those other companies. Getting hack is really a good excuse nowadays for companies.

    • @ryderostby
      @ryderostby Год назад +19

      having a subscription to an online password manager sounds like the dumbest idea ever

    • @WildCharger
      @WildCharger Год назад +1

      The attacker got access to cloud backups. That’s pretty bad.

    • @razorback9999able
      @razorback9999able Год назад +8

      Guess saving passwords on a piece of paper works better than a password manager.

    • @villager736
      @villager736 Год назад

      @@razorback9999able That and something like a titan security key are probably the most secure way you can store/secure your passwords

  • @toupac3195
    @toupac3195 Год назад +1

    The worst I've ever seen is a ransomware hack that destroyed my dad's successful company after 30 years of hard work.

  • @skylerjade9093
    @skylerjade9093 Год назад +9

    I love when Muta gets pissed off 😂

  • @GravityTrash
    @GravityTrash Год назад +2

    I honestly have no idea how Password Vault programs don't ring any alarm bells. To any decent hacker, how is that not just a lootbox for them.

  • @tjbrower
    @tjbrower Год назад +5

    I was hoping you had some info on the dish ransomware attack!

  • @ethanking9805
    @ethanking9805 Год назад +1

    I would like to remind people reading the comments to leave a like for this man, he has worked hard for this video and has taken time out of his own personal schedule just to keep us updated and safe from cybersecurity threats.
    You have earned my sub!

  • @sethboyle90
    @sethboyle90 Год назад +45

    Welcome to cyberpunk where there's always cyber attack. (That's what it feels like anyway)

  • @LinusTechT1ps
    @LinusTechT1ps Год назад +1

    The moment they switched to a one type of device per free account only system, I immediately left them for Bitwarden, a free password manager that lets you store as many passwords to your heart’s content, and does not lock the all device access for Bitwarden app behind a paywall, they have some more advanced features in their pro version, and I respect them for putting all the necessities on the free tier, I would gladly donate to them. Shame on you, lastpass.

  • @gd2234_
    @gd2234_ Год назад +42

    The irony is I was considering getting one of these cause I’m fucking lazy. Ended up choosing not to do so cause I was like, what if it gets hacked. Oh how the turn tables

    • @steveballmersbaldspot2.095
      @steveballmersbaldspot2.095 Год назад

      There's an open source one that comes bundled with some Linux distros whose name has slipped my mind, that one might be the best cloud/electronic option. But yeah your best bet is just a notebook stashed away somewhere in your house.

    • @MollyHJohns
      @MollyHJohns Год назад

      The classic way is the safest way

  • @MaxBeaulieu
    @MaxBeaulieu Год назад

    As someone new to the security industry it’s crazy how much human failure is responsible for so many attacks .

  • @vexedbat5487
    @vexedbat5487 Год назад +8

    Muda just because your MySpace has been hacked doesn’t meant it’s the biggest cyberattack

    • @cdvideodump
      @cdvideodump Год назад +3

      Muthony Dartano here, the internet's busiest tech nerd

  • @jacobdorian-vincent5408
    @jacobdorian-vincent5408 Год назад

    Yo muta if ya see this comment i wanna say thanks for helping me through some dark times your content always helps me sit back and clear my mind of my anxiety and extreme ocd much love muta

  • @hellboy30098
    @hellboy30098 Год назад +3

    Yeah I got hit by the last pass hack, however I was so lucky that I got lazy and only used it for my steam and like 1 account that was easy to reset. I actually was going to use it MORE but it's like nowhere is safe

  • @FreakyDudeEx
    @FreakyDudeEx Год назад +2

    the icing on the cake is the fact that they ran an outdate codes from a program on their work machine for their personal use.... its like basic 101 of any type of IT team from all of their department is never mix personal and work devices...
    i also BYOD for my work but i don't connect to the network or if i need connect to the network for some god damn reason, they had already isolated my BYOD machine to be unable to access the internet and other devices on the network except my work laptop... i also use different OS on those 2 devices just to screw with any potential software running in the background on either machine....
    the ironic part was i was arguing with some fans of some youtuber who was an IT security guy who was promoting last pass.... and i was arguing how stupid people are to trust an online password manager to store your login credential to all your sites... and look at how the tables have turned.... how ironic the world is.... how moronic these people must now feel....

  • @MelissaM83
    @MelissaM83 Год назад +7

    For their safety anyway I'd be moving every witSEC on the roster !! This is so scary

  • @Syd448
    @Syd448 2 месяца назад

    The fact that a corporate company hack happened bc an update wasn’t done is wild to me. I work in insurance, we don’t get to choose yo update or not. My system updates weekly

  • @d3v4nsh444
    @d3v4nsh444 Год назад +6

    muta back with another banger, let’s goo !!

  • @vincecanino6119
    @vincecanino6119 Год назад +1

    This is why it’s frustrating when people try to put non work applications on work computers. I don’t trust an employee to update the software unless it stops working or already configured it to automatically update. Yet IT isn’t going to update software not business critical. Despite this, its crazy how people don’t see the problem with this.

  • @magnetsec
    @magnetsec Год назад +3

    Kind of a useless hack. Even if they get the whole S3 dump, what's the point when the generated password is always random? Except for a fraction of cases where the users are making up their own password, they could build a rainbow table or dictionary for later attacks. Unless they're targeting the people immediately, the long-term ROI or the value of the dump in the marketplace is pretty low. Not recommended.

  • @felix0r309
    @felix0r309 Год назад +2

    this is the worst cyber attack i've seen ever

  • @stephenbyers6173
    @stephenbyers6173 Год назад +5

    Thank god the witness data wasn't leaked.

  • @jordanw2009
    @jordanw2009 Год назад

    I figured you would have covered marshals but glad you got us now. I been wondering what you would say for days.

  • @Sketchy_2
    @Sketchy_2 Год назад +11

    who would've thought storing your passwords onto an online database was such a bad idea?

  • @Eleanor_Ch
    @Eleanor_Ch Год назад

    When a breach happened a while ago, I canceled auto renewal. Perfectly timed, today, my subscription ended. LastPass account nuked.

  • @TimPortantno
    @TimPortantno Год назад +3

    WinGet would have solved all of this...
    Supposedly Microsoft is working on restartless security updates, too.

  • @sillybeanthing
    @sillybeanthing Год назад

    A buddy of mine used to work with the Marshall's user website, he would always say it was a huge mess, and the coding he had to maintain was a security nightmare. He also said things about the fact that he had to make the website very nice for a few uber rich people that sat at the desks at the Marshalls and not for the public and it just wasn't for him, he hated the feeling he got from it.

  • @MagnonEntertain
    @MagnonEntertain Год назад +1

    My approach for passwords is the lazy route. For frequently used sites I use unique strong passwords I remember
    For everything else, i sign up, use a unique password, forget about them and if I need to log back in, password forget function. Works like a charm.

  • @Matthiasthehillbilly
    @Matthiasthehillbilly Год назад +16

    Man is our best source of info in these times.

  • @nefwaenre
    @nefwaenre Год назад +2

    i cannot in good conscience, ever sympathise with a company. That being said, sometimes hearing that a certain company got hacked does scare me, not for their sake, but for all of us who may have had our data stolen bcuz of this.

  • @RozayMalikOG
    @RozayMalikOG Год назад +8

    Another banger of a vid mutahar🙏🎮

  • @JacobGunner
    @JacobGunner Год назад

    I actually used LastPass for quite a while, and the first breach news didn't worry me too much... then it just kept getting worse and I was like "WELP. I'M OUT."

  • @Addonzs
    @Addonzs Год назад +5

    Love your videos ❤

  • @wonkehcheetah1138
    @wonkehcheetah1138 Год назад +1

    I just use a random notebook and a pencil. For a one-time payment of like 5 dollars, I can have a completely unhackable password manager that can potentially store thousands and thousands of passwords.

  • @aura_baller2166
    @aura_baller2166 Год назад +10

    Mutahar never fails to make amazing videos

  • @owensthethird
    @owensthethird Год назад

    Having good OpSec is like being faster than your bad OpSec friend while you both are running away from a vicious hacker grizzly bear.

  • @GarGhuul
    @GarGhuul Год назад +5

    … Muta low-key implying they are in the Wit-Sec database? (j/k)

  • @CharlesTheFearsomeTrain117
    @CharlesTheFearsomeTrain117 Год назад +1

    The worst cyberattack I have seen was the launch of Cyberpunk 2077.

  • @lirich0
    @lirich0 Год назад +17

    You know it’s serious when Muta doesn’t laugh at the beginning of the video

  • @makarambles
    @makarambles Год назад +2

    I'm lucky I stopped using lastpass a year or so ago, all my important accounts have updated passwords since then... the crazy thing is the only reason I stopped using it was because it didnt let me use mobile AND desktop anymore and it was a hassle

  • @abyss9316
    @abyss9316 Год назад +3

    Not surprising everyday there will be new loopholes new security breaches new people clicking on links they shouldn't LOL

  • @sammyfromsydney
    @sammyfromsydney Год назад +1

    Half the time updates break stuff or introduce new requirements that make using the software a lot less convenient. I completely understand the "if it ain't broke" mentality of running old versions.

  • @sue-silvermist1199
    @sue-silvermist1199 Год назад +3

    U should be a dungeon master in d&d u have the voice for it lol😅

  • @untitled7549yt
    @untitled7549yt Год назад +2

    Very cool mutahar, can’t wait for the worst cyberattack ever next week

  • @johnr797
    @johnr797 Год назад +5

    This better be about the chapters indigo plum points cyber attack. I want 5 dollars off of my ridiculously overpriced books dammit

  • @multitablez7825
    @multitablez7825 Год назад +2

    I use last pass. do i need to delete everything and get a new password notes manager?

  • @electro8561
    @electro8561 Год назад +8

    I think we all see things that make us mad

  • @gonkxcx733
    @gonkxcx733 Год назад +1

    my school district recently got hacked and we were all snowed in so there wasnt much communication as to why everything was down

  • @chitz3852
    @chitz3852 Год назад +15

    It feels like every 3-6 months SOG tells us about the new worst cyber attack
    shits crazy

  • @_trashvis_
    @_trashvis_ Год назад

    as someone who is beginning to study cybersecurity, this makes me visibly frustrated.

  • @Ostro-goth
    @Ostro-goth Год назад +7

    You look very mutah today mutah

  • @semi-senioritis
    @semi-senioritis Год назад

    Last Pass is one of the first companies where instead of just not using their service anymore I actively deleted my account.

  • @bivinsclips
    @bivinsclips Год назад +20

    dam

  • @unknxwnplxcemxnt
    @unknxwnplxcemxnt Год назад

    thank god muda has talked about this subject even more

  • @Zeyek1
    @Zeyek1 Год назад +3

    no views but theres comments how is that possible

    • @Zeyek1
      @Zeyek1 Год назад +2

      @ItzSyakirin you mean Script kiddies AKA Bun Bun Girls

  • @dgmang92
    @dgmang92 Год назад

    Remember kids: devops does not equal security minded. As a cyber security engineer, this whole situation is a giant facepalm.