Technologies
If You Use LastPass, You Need to Change All of Your Passwords ASAP
You’ll probably also want to find a different password manager, considering the severity of the latest LastPass data breach.

LastPass, one of the world’s most popular password managers, suffered a major data breach in December, putting customers’ online passwords at risk and endangering their personal data.
On Dec. 22, LastPass CEO Karim Toubba acknowledged in a blog post that a security incident the company first disclosed in August eventually led to an «unauthorized party» stealing customer account information and sensitive vault data. The breach is the latest in a lengthy and troubling string of security incidents involving LastPass that date back to 2011.
It’s also the most alarming.
An unauthorized party was able to gain access to unencrypted subscriber account information like LastPass usernames, company names, billing addresses, email addresses, phone numbers and IP addresses, according to Toubba. That same unauthorized party was also able to steal customer vault data, which includes unencrypted data like website URLs as well as encrypted data like the usernames and passwords for all of the sites customers have stored in their vaults.
If you’re a LastPass subscriber, the severity of this breach should have you looking for a different password manager, because your passwords and personal data are at serious risk of being exposed.
What should LastPass subscribers do?
The company didn’t specify how many users were affected by the breach, and LastPass didn’t respond to CNET’s request for additional comment on the breach. But if you’re a LastPass subscriber, you need to operate under the assumption that your user and vault data are in the hands of an unauthorized party with ill intentions. Though the most sensitive data is encrypted, the problem is that the threat actor can run «brute force» attacks on those stolen local files. LastPass estimates it would take «millions of years» to guess your master password — if you’ve followed its best practices.
If you haven’t — or if you just want total peace of mind — you’ll need to spend some serious time and effort changing your individual passwords. And while you’re doing that, you’ll probably want to transition away from LastPass, too.
With that in mind, here’s what you need to do right now if you’re a LastPass subscriber:
1. Find a new password manager. Given LastPass’ history with security incidents and considering the severity of this latest breach, now’s a better time than ever to seek an alternative.
2. Change your most important site-level passwords immediately. This includes passwords for anything like online banking, financial records, internal company logins and medical information. Make sure these new passwords are strong and unique.
3. Change every single one of your other online passwords. It’s a good idea to change your passwords in order of importance here too. Start with changing the passwords to accounts like email and social media profiles, then you can start moving backward to other accounts that may not be as critical.
4. Enable two-factor authentication wherever possible. Once you’ve changed your passwords, make sure to enable 2FA on any online account that offers it. This will give you an added layer of protection by alerting you and requiring you to authorize each login attempt. That means even if someone ends up obtaining your new password, they shouldn’t be able to gain access to a given site without your secondary authenticating device (typically your phone).
5. Change your master password. Though this doesn’t change the threat level to the stolen vaults, it’s still prudent to help mitigate the threats of any potential future attack — that is, if you decide you want to stay with LastPass.
LastPass alternatives to consider
- Bitwarden: CNET’s top password manager is a highly secure and open-source LastPass alternative. Bitwarden’s free tier allows you to use the password manager across an unlimited number of devices across device types. Read our Bitwarden review.
- 1Password: Another excellent password manager that works seamlessly across platforms. 1Password doesn’t offer a free tier, but you can try it for free for 14 days.
- iCloud Keychain: Apple’s built-in password manager for iOS, iPadOS and MacOS devices is an excellent LastPass alternative available to Apple users at no additional cost. iCloud Keychain is secure and easy to set up and use across all of your Apple devices. It even offers a Windows client, too, with support for Chrome and Edge browsers.
How did it come to this?
In August 2022, LastPass published a blog post written by Toubba saying that the company «determined that an unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information.»
At the time, Toubba said that the threat was contained after LastPass «engaged a leading cybersecurity and forensics firm» and implemented «enhanced security measures.» But that blog post would be updated several times over the following months as the scope of the breach gradually widened.
On Sept. 15, Toubba updated the blog post to notify customers that the company’s investigation into the incident had concluded.
«Our investigation revealed that the threat actor’s activity was limited to a four-day period in August 2022. During this timeframe, the LastPass security team detected the threat actor’s activity and then contained the incident,» Toubba said. «There is no evidence of any threat actor activity beyond the established timeline. We can also confirm that there is no evidence that this incident involved any access to customer data or encrypted password vaults.»
Toubba assured customers at the time that their passwords and personal data were safe in LastPass’s care.
However, it turned out that the unauthorized party was indeed ultimately able to access customer data. On Nov. 30, Toubba updated the blog post once again to alert customers that the company «determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information.»
Then, on Dec. 22, Toubba issued a lengthy update to the blog post outlining the unnerving details regarding precisely what customer data the hackers were able to access in the breach. It was then that the full severity of the situation finally came to light and the public found out that LastPass customers’ personal data was in the hands of a threat actor and all of their passwords were at serious risk of being exposed.
Still, Toubba assured customers who follow LastPass’s best practices for passwords and have the latest default settings enabled that no further action on their part is recommended at this time since their «sensitive vault data, such as usernames and passwords, secure notes, attachments, and form-fill fields, remain safely encrypted based on LastPass’ Zero Knowledge architecture.»
However, Toubba warned that those who don’t have LastPass’s default settings enabled and don’t follow the password manager’s best practices are at greater risk of having their master passwords cracked. Toubba suggested that those users should consider changing the passwords of the websites they have stored.
What does all of this mean for LastPass subscribers?
The initial breach ended up allowing the unauthorized party to access sensitive user account data as well as vault data, which means that LastPass subscribers should be extremely concerned for the integrity of the data they have stored in their vaults and should be questioning LastPass’s capacity to keep their data safe.
If you’re a LastPass subscriber, an unauthorized party may have access to personal information like your LastPass username, email address, phone number, name and billing address. IP addresses used when accessing LastPass were also exposed in the breach, which means that the unauthorized party could also see the locations from which you used your account. And because LastPass doesn’t encrypt users’ stored website URLs, the unauthorized party can see all of the websites for which you have login information saved with the password manager (even if the passwords themselves are encrypted).
Information like this gives a potential attacker plenty of ammunition for launching a phishing attack and socially engineering their way to your account passwords. And if you have any password reset links stored that may still be active, an attacker can easily go ahead and create a new password for themselves.
LastPass says that encrypted vault data like usernames and passwords, secure notes and form-filled data that was stolen remains secured. However, if an attacker were to crack your master password at the time of the breach, they would be able to access all of that information, including all the usernames and passwords to your online accounts. If your master password wasn’t strong enough at the time of the breach, your passwords are especially at risk of being exposed.
Changing your master password now will, unfortunately, not help solve the issue because the attackers already have a copy of your vault that was encrypted using the master password you had in place at the time of the breach. This means the attackers essentially have an unlimited amount of time to crack that master password. That’s why the safest course of action is a site-by-site password reset for all of your LastPass-stored accounts. Once changed at the site level, that would mean the attackers would be getting your old, outdated passwords if they managed to crack the stolen encrypted vaults.
For more on staying secure online, here are data privacy tips digital security experts wish you knew and browser settings to change to better guard your information.
Technologies
Zelle App Is Gone. Use These Alternatives to Send Money Digitally
You still have lots of free ways to send money to friends and family electronically.

If Zelle has been your go-to app for sending money digitally, it’s time to find a new method. The digital payment app shut down on April 1.
That doesn’t mean you can’t use Zelle altogether, however. Zelle has only discontinued its standalone app. You can still send money using Zelle if your bank belongs to the Zelle network. You’ll just need to do it through your bank’s app or website. You also have other services to choose from. Here’s what you need to know about this change and your options moving forward.
TAX SOFTWARE DEALS OF THE WEEK
-
$0 (save $0)
-
$56 (save $24)
-
$83 (save $32)
-
$28 (save $10)
Why the Zelle app is shutting down
When Zelle launched in 2017, only about 60 US financial institutions offered the service by the end of that year. Today, that number exceeds 2,200. As a result, less than 2% of Zelle transactions occur through the standalone app. Zelle has been phasing out the ability to make transactions on its mobile app since October 2024.
«Today, the vast majority of people using Zelle to send money use it through their financial institution’s mobile app or online banking experience, and we believe this is the best place for Zelle transactions to occur,» Zelle said in an October 2024 press release.
In December, Zelle was in the spotlight when the Consumer Financial Protected Bureau sued the company and three of the largest US banks for failing to protect consumers from widespread fraud on the peer-to-peer payment network. The lawsuit has since been dropped.
Other ways to send money digitally
You can still use Zelle through your bank’s app or website if it belongs to the Zelle network. You can also switch to another digital payment app, such as:
- Apple Wallet
- Cash App
- PayPal
- Venmo
Take some basic precautions when using Zelle or any other digital payment service. These apps are a frequent target for scammers, and Chase Bank has started blocking some Zelle payments it believes could be fraudulent. Only send money to people you know and trust, and watch for red flags like an urgent message claiming to be from your bank or an online ad for concert tickets that seem impossibly cheap.
Technologies
Marvel Rivals Season 2 Starts Next Week, Devs Drop Big News
Emma Frost and Ultron are joining the Rivals roster in season 2, and developers are upping the pace to one new hero per month starting with season 3.

After surviving the endless night in New York City with the Fantastic Four, Marvel Rivals players are getting invited to the shores of Krakoa for the start of season 2 on April 11. The game dropped the first trailer for the new season, giving us our first official look at the new heroes, and a developer vision video dropped major news about the future of hero releases.
The trailer features the former foe and sometimes-leader of the X-Men, Emma Frost, inviting people from across Rivals’ various timelines to the mutant nation of Krakoa, where everyone gets dressed up for a fancy gala — even Wolverine puts on a white tux. The event, however, is unceremoniously interrupted when Ultron shows up preaching extermination.
We also got a look at some of the cosmetics in season 2, though it’s unclear which are from the shop and which might be in the battle pass. In addition to the dressed-up Wolverine, we also got looks at Magik and Psylocke in the traditional X-Men blue and yellow. Nonmutant guests are also getting in on the fun, with fancy attire for heroes like Cap, Widow and Luna Snow.
New Heroes and balance changes in Marvel Rivals Season 2
Emma Frost joins the roster as a Vanguard. We don’t have detailed information about her abilities yet but expect that information to drop ahead of next week’s season launch. Ultron is coming in the season 2.5 update, which should be in late May.
Some team-ups are changing in season 2, including three new team-up abilities that were previewed in the newest developer vision video.
- Emma Frost allows Magneto and Psylocke to create illusions of themselves.
- Doctor Strange teams up with Scarlet Witch allowing her to use small portals to seemingly increase her damage output via a rapid-shooting alternate fire.
- Cap finally teams up with Bucky, allowing the Winter Soldier to leap to allies.
A few existing team-ups are getting adjustments, with Psylocke, Winter Soldier and Doctor Strange being removed from older team-ups in favor of new ones, and Namor moving from working with Luna’s anchor to Hulk’s to empower his ultimate with gamma energy. Two team-ups are being removed entirely: Magneto can no longer team up with Scarlet Witch, and Thor is no longer anchoring Cap and Storm.
The developers vaguely teased other balance changes, including buffs to Peni, Mister Fantastic and Moon Knight, with Strange trading offensive pressure for more survivability and Rocket getting more utility while Loki and Adam Warlock receive nerfs to their Regeneration Domain and Soul Bond abilities.
Future seasons will be shorter, which means more new heroes
One of the most surprising moments in the developer video was the announcement that, beginning with season 3, seasons will be two months long instead of roughly three. There has been a lot of discussion online about whether Rivals’ pace of new heroes (about eight per year based on three-month seasons) was sustainable. Well, apparently the Rivals devs took that personally and are cranking up that pace to a new hero every month, meaning 12 new heroes per year.
This feels borderline ludicrous compared with other hero shooters that average about three new heroes per year, or even MOBAs like League of Legends, which has averaged about four new champions per year over the past five years. Rivals benefits from having an overflowing stable of Marvel characters to pull from rather than inventing their own hero concepts, and compared with Overwatch, the developers seem less worried about mechanical overlap in their heroes, as seen with many support ultimates. Still, a new hero every month feels unheard of for a hero shooter.
New Krakoa map and competitive changes
A new Krakoa-themed domination map is being added in season 2, and Yggsgard: Royal Palace (domination) and Tokyo 2099: Shin-Shibuya (convergence) will rotate out of the map pool for ranked modes, though they’ll still be available in quick play and custom games.
The threshold for competitive picks and bans, which currently only happen in diamond-ranked lobbies, will be lowered to gold 3. Players in Eternity or One Above All ranks will only be able to duo queue, instead of queuing with larger groups — a measure that’s likely intended to keep high-level teams from stomping lobbies.
Speaking of ranks, season 2 will drop everyone by 9 divisions, which is equal to 3 ranks. That means players in Eternity will drop to diamond, and any players at platinum 3 or below will start their climb from bronze 3 again. (AGAIN… AGAIN.)
Rivals developers also announced that individual player performance will be weighted higher when determining competitive progress after a match, meaning if your stats outperform your team’s, you’ll earn more for winning and drop less for losing. This change can help elevate smurfs and other high-skill players in lower-ranked lobbies by getting them into their appropriate ranks faster. However, it can also lead to players stat-farming, instead of playing in a way that is most effective for winning games. Overall, given that Rivals doesn’t use any sort of competitive placement matches, this should be a net positive for the game.
Other announcements
Rivals is adding new skin recolors to certain hero skins and (finally) giving players the option to gift costumes to their friends so they can surprise someone for their birthday, which you definitely did not forget about.
Missions are changing a bit, with the addition of weekly missions and a redistribution of where battle-pass-progressing chrono tokens are earned. The devs framed this as creating a «smoother expectation» of how to earn chrono tokens, but the surface-level description sounds like they’re just making it harder to earn battle pass progress over the season by tucking away more progress under missions with shorter time limits.
The developer vision update also gave us our first look at the competitive distribution, showing how many Rivals players are in each tier as of season 1.5.
The Hellfire Gala trailer says season 2 will start on April 11. While it doesn’t give a specific start time, expect the between-seasons maintenance to finish sometime in the middle of the night in the US.
For more on Marvel Rivals, check out which heroes and roles you should play and how to get free skins.
Technologies
Nintendo Switch 2 vs. Switch 1: Every Detail Compared
The Nintendo Switch 2’s official specs aren’t too different, but the new console has a lot of upgrades on the original Switch.

The Nintendo Switch 2 may look like its predecessor, but there’s been a lot of changes to its features and under the hood. The new console has «10x the graphics performance» compared to the original Switch, says Nvidia, which built the custom processor powering the Switch 2.
The Switch 2, with a release date on June 5, is priced at $450 alone or $500 in a bundle with Mario Kart World, the headliner of the console’s launch games. Here’s all the info on how to preorder the Switch 2.
Note that we’re mostly comparing the Switch 2 to the original Switch 1 released in March 2017, because looping in the Switch Lite and Switch OLED gets complicated.
Design
Broadly, the Switch 2 is a larger version of its predecessor, with everything looking slightly inflated: bigger footprint, bigger screen, bigger Joy-Cons.
Original Switch: The original Switch, with Joy-Cons slotted into the side rails, is a little over 9.4 inches wide, 4 inches tall, a little over half an inch thick and weighs about 10.5 ounces (297 grams). The Joy-Cons slide into place from the top of the device’s sides, while a thin wedge of plastic pops out of the back of the console to serve as a kickstand.
The Switch also came with a dock, which the console could slot into to for recharging and outputting to a TV or large display via HDMI port.
Switch 2: The new Switch 2 is bigger in every way, but it has the same overall shape and layout as the original. The new Joy-Cons will indeed be held in place on the console magnetically, and connect to the console via pins. The new console also sports a wide U-shaped kickstand that spans almost its entire rear width, which can be moved around to prop up the Switch 2 at a variety of angles. Nintendo says the console has more powerful speakers, which we’re looking forward to testing.
The Switch 2’s dock is largely similar in function though it has rounded edges and an internal fan to cool down the console during long game sessions. More importantly, it can output games in 4K to TVs, but only for select games.
Joy-Cons
The Joy-Cons were a marvel when they arrived on the first Switch, and while they’re functionally similar in its successor, there have been upgrades in the Switch 2’s controllers.
Original Switch: The Switch Joy-Cons are simple but powerful controllers that slid on and off the console via plastic rails, connecting and recharging via pins on the side. Detach and they become their own micro-controllers, with little shoulder buttons to boot.
Switch 2: The new console’s Joy-Cons are larger to fit the Switch 2, and lock into the side of the console via powerful magnets — there are small inward-facing buttons to the side of ZR and ZL to detach the controllers from the console. The larger-size Joy-Cons have longer L and R outside shoulder buttons, as well as much wider SL and SR internal shoulder buttons, which are accessible when detached from the console.
And yes, you can use the Switch 2 Joy-Cons as mice by placing their inner edges flat on a surface. During the Nintendo Direct, we saw it being used to control active action games like the wheelchair basketball-simulating DragXDrive and strategy games like Civilization VII.
Display size
Original Switch: The original Switch has a 6.2-inch LCD screen with 1,280×720-pixel resolution, which was reasonably impressive at launch in 2017 but has been outclassed by newer handhelds with sharper displays. The Switch OLED upgraded this with a larger 7-inch display showing deeper blacks and colors, but no upgrade in resolution. The Switch Lite has a 5.5-inch LCD screen.
Switch 2: Unsurprisingly, the Switch 2’s larger size means a larger display. The new console has a 7.9-inch 1080p LCD screen that can get up to 120Hz refresh rate in handheld mode, or up to 4K when docked and outputting to a TV.
Why no OLED display? Possibly to save on costs… or possibly to give Nintendo room to release a Switch 2 OLED version down the line.
CPU/GPU
Original Switch: The original Switch runs on an Nvidia custom Tegra X1 processor split into four ARM Cortex A57 CPU cores, and according to Hackaday, there are four extra A53 cores that aren’t used.
Switch 2: Once again, Nintendo hasn’t released any official info on the Switch 2’s specs, even after the Nintendo Direct reveal stream — and they most the company reveals is that it has a «custom processor made by Nvidia» on the Switch 2’s official specs page. Nvidia confirmed it also has a custom GPU, claiming that the new console has «10x the graphics performance» of the Switch 1, and the custom processor’s AI-powered features include Deep Learning Super Sampling (DLSS), face tracking and background removal for video chat and real-time ray tracing.
We do still have more supposed details from previous leaks. Months ago on X (formerly Twitter), leaker Zuby_Tech posted that the Switch 2’s CPU will be an eight-core Arm Cortex A78C. They also suggested that the GPU will be an Nvidia T239 Ampere, aligning with years of similar rumors reported on by Eurogamer and others about the custom chip, which derives from Nvidia’s Tegra line of chips for smartphones and mobile devices.
RAM and storage
Original Switch. The Switch has 4GB of LPDDR4 RAM and 32GB of onboard storage, expandable up to 2TB via microSD cards in the slot beneath the kickstand.
Switch 2: Even after the reveal stream, Nintendo didn’t release official specs for RAM. Leaker Zuby_Tech posted on X back in September suggesting the Switch 2 will have 12GB of LPDDR5 RAM and 256GB of onboard storage. That leak also suggested the new console will have two internal fans, up from the single one in the original Switch.
Nintendo did confirm that the new console will have 256GB of onboard storage, which can be expanded with special microSD Express cards — sorry, your old Switch-compatible microSD cards won’t work on the Switch 2.
Battery life
Original Switch: The original Switch packs a 4,310-mAh battery, which gives between 4.5 and 9 hours of battery life depending on screen brightness and other factors.
Switch 2: Though Nintendo didn’t release details on the Switch 2’s capacity in the reveal stream, the company does list specs on its website, showing it packs a 5,220mAh battery. While that’s notably larger than the one in its predecessor, Nintendo estimates this will only get players between an estimated 2 and 6.5 hours, depending on games played.
Ports
Original Switch: The first Switch sports a single USB-C port out the bottom, a 3.5mm headphone jack on the top and Wi-Fi 5 plus Bluetooth 4.1 connectivity. On the top is a slot at the top for Switch game cartridges as well as the microSD slot beneath the kickstand on the rear of the console.
Switch 2: The Switch 2 retains the original’s USB-C port on the bottom and 3.5mm jack on the top while adding another USB-C port topside, and now we know what it’s for: to connect with accessories like the Nintendo Switch Camera, a webcam-like camera on a stand to let you do Nintendo’s version of FaceTiming while you play games with your friends.
Nintendo hasn’t clarified the console’s connectivity options, and rumors are scarce on the subject.
As for cartridges, Switch 2 will play some original Switch games in physical versions. The cartridge slot is to the right of the headphone jack in the above image, which is where the slot is on the original Switch. You can tell game cartridges from the two console generations apart by color: ones for the new Switch 2 are red, while older Switch 1 games are black.
-
Technologies2 года ago
Tech Companies Need to Be Held Accountable for Security, Experts Say
-
Technologies2 года ago
Best Handheld Game Console in 2023
-
Technologies2 года ago
Tighten Up Your VR Game With the Best Head Straps for Quest 2
-
Technologies4 года ago
Verum, Wickr and Threema: next generation secured messengers
-
Technologies4 года ago
Google to require vaccinations as Silicon Valley rethinks return-to-office policies
-
Technologies3 года ago
Olivia Harlan Dekker for Verum Messenger
-
Technologies3 года ago
Black Friday 2021: The best deals on TVs, headphones, kitchenware, and more
-
Technologies4 года ago
iPhone 13 event: How to watch Apple’s big announcement tomorrow