logo

LastPass is now encrypting URLs in password vaults for better security

ID: d9a1ab7b-e528-5df3-b21a-2c9626e4e3ea

STIX ID: report--d9a1ab7b-e528-5df3-b21a-2c9626e4e3ea

Feed Name: Bleeping Computer

Date Published: 2024-05-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

LastPass will start encrypting all URL fields in user vaults to enhance privacy and align with its zero-knowledge model, reversing a 2008 decision to leave URLs unencrypted for performance reasons; phase one in June 2024 encrypts primary URL fields and removes duplicate/legacy fields, while phase two in H2 2024 covers six additional URL-related fields (URL rules, equivalent domains, deny/allow lists, and legacy SSO URLs). Motivated in part by lessons from the 2022 breaches that exposed unencrypted URLs and enabled brute-forcing of weak master passwords, the change requires no user action, with guidance to be sent via email.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.