Live data from Hacker News

Phishing attack against Lastpass

seancassidy.me

31–40 of 69 posts

Re: Phishing attack against Lastpass

#31

Earlier quoted context omitted.

I don't think that's a fair criticism of Lastpass for having "security issues" for the following reasons: 1. In the blog post you linked, no user passwords were at risk. They were being abundantly cautious, which makes sense since they hold everyone's passwords. 2. In the talk you linked, this is a inherent problem with storing keys on your local filesystem and not a problem with Lastpass. 1password is also "vulnerab…

Thanks for the link to the 1password compromise, although, I stand by my point, that compromise is due to extraneous features as opposed to the core functionality. Being conservative myself, that's not a feature I use. I see 1password's main vulnerability being that someone could gaining access to a device and vault passcode or obtaining that passcode through a keylogger. I'm not sure how difficult it would be to bru…

> I'm not sure how difficult it would be to brute force into 1Password locally but either way it's a low benefit game compared to the potential access with a compromise to a cloud based scenario like LastPass.

I'm not sure if you're familiar with how Lastpass works in general, but all of the data you store with Lastpass is encrypted in almost an identical manner to your 1password vault. They can't read your passwords.

A "compromise" of Lastpass would require brute forcing each user's vault in order to gain any actual passwords, which would require an extraordinarily long time.

I know it sounds concerning saying "put all your passwords in the cloud" but the reality is that it's no different than using 1Password with sync enabled.

Re: Phishing attack against Lastpass

#32
post #25

LastPass has pushed Google for years to give us a way to avoid using the browser viewport: infobars was a solution to this issue -- you can see one of my pleas for it back in January 2012: https://code.google.com/p/chromium/issues/detail?id=39511 We do a lot to try to protect our usage of viewports using iframes, but it's not good enough and we'll figure out a way to do better. LastPass has generally told people to u…

> LastPass also detects you enter your master password on an incorrect domain and notifies you immediately of your mistake

Interesting! How does it do this?

Re: Phishing attack against Lastpass

#33

Earlier quoted context omitted.

Thanks for the link to the 1password compromise, although, I stand by my point, that compromise is due to extraneous features as opposed to the core functionality. Being conservative myself, that's not a feature I use. I see 1password's main vulnerability being that someone could gaining access to a device and vault passcode or obtaining that passcode through a keylogger. I'm not sure how difficult it would be to bru…

> I'm not sure how difficult it would be to brute force into 1Password locally but either way it's a low benefit game compared to the potential access with a compromise to a cloud based scenario like LastPass. I'm not sure if you're familiar with how Lastpass works in general, but all of the data you store with Lastpass is encrypted in almost an identical manner to your 1password vault. They can't read your passwords…

>the reality is that it's no different than using 1Password with sync enabled.

Except that a users LastPass vault lives in the "cloud" so that a compromise of that password can likely open the door and makes it a more enticing target to begin with. Compared the likely hood of merely getting at the 1password vault (assuming it's not synced to the cloud) being a significant barrier.

Again, for me this discussion is educational, I'm curious how having this data in the cloud could ever be considered more secure than local storage.

Re: Phishing attack against Lastpass

#34

Earlier quoted context omitted.

I assume you have hundreds of accounts like I and most people I know have. If you can recall hundreds of passphrases, including passphrases for accounts that you don't access for several years, and you can continue recalling these hundreds of passphrases even while changing them regularly, how else are you making use of your exceptional memory? Just curious.

I wish I had an exceptional memory ;) Only 4-5 accounts require a strong password. The rest I don't care, I use the same password or request a reset every time I go back.

I do the same. However, sometimes that requires a phone call with a wait time of 30 minutes + identity verification =( This is the case with Blizzard.

Re: Phishing attack against Lastpass

#35

Earlier quoted context omitted.

I assume you have hundreds of accounts like I and most people I know have. If you can recall hundreds of passphrases, including passphrases for accounts that you don't access for several years, and you can continue recalling these hundreds of passphrases even while changing them regularly, how else are you making use of your exceptional memory? Just curious.

I wish I had an exceptional memory ;) Only 4-5 accounts require a strong password. The rest I don't care, I use the same password or request a reset every time I go back.

[deleted]

Re: Phishing attack against Lastpass

#36

Earlier quoted context omitted.

> I'm not sure how difficult it would be to brute force into 1Password locally but either way it's a low benefit game compared to the potential access with a compromise to a cloud based scenario like LastPass. I'm not sure if you're familiar with how Lastpass works in general, but all of the data you store with Lastpass is encrypted in almost an identical manner to your 1password vault. They can't read your passwords…

>the reality is that it's no different than using 1Password with sync enabled. Except that a users LastPass vault lives in the "cloud" so that a compromise of that password can likely open the door and makes it a more enticing target to begin with. Compared the likely hood of merely getting at the 1password vault (assuming it's not synced to the cloud) being a significant barrier. Again, for me this discussion is edu…

> I'm curious how having this data in the cloud could ever be considered more secure than local storage

It's not, I didn't mean to give that impression. It increases your attack surface, which is a tradeoff that 99.99% of users are happy to make for the convenience of having instant and strongly secured access to all of their passwords from anywhere.

I meant to point out that this is no different than how the vast majority of 1Password users configure their database: with Dropbox syncing.

For me, this is a required feature to using a password manager. If you do not need this feature, local storage only is better. However, I'll argue that if you have that level of concern then you should also not be using any closed source password manager in the first place.

Re: Phishing attack against Lastpass

#37
post #25

LastPass has pushed Google for years to give us a way to avoid using the browser viewport: infobars was a solution to this issue -- you can see one of my pleas for it back in January 2012: https://code.google.com/p/chromium/issues/detail?id=39511 We do a lot to try to protect our usage of viewports using iframes, but it's not good enough and we'll figure out a way to do better. LastPass has generally told people to u…

> LastPass also detects you enter your master password on an incorrect domain and notifies you immediately of your mistake Interesting! How does it do this?

I'm assuming by the same mechanism that offers to save previously-entered passwords. It's always sniffing anything you type into a password field.

Re: Phishing attack against Lastpass

#38

I believe so far my brain is still the best, if not only, secure password storage. To add a layer of security while reducing password complexity, I coded a small hasher so my brain remembers easy phrases and passwords come out of this tool über strong. I suppose I am still vulnerable to social engineering hacks or the attacker getting a hold of my hasher, but for such cases the only layer left is whatever vendors imp…

sounds like one shall pass: https://oneshallpass.com/

Re: Phishing attack against Lastpass

#39
post #25

LastPass has pushed Google for years to give us a way to avoid using the browser viewport: infobars was a solution to this issue -- you can see one of my pleas for it back in January 2012: https://code.google.com/p/chromium/issues/detail?id=39511 We do a lot to try to protect our usage of viewports using iframes, but it's not good enough and we'll figure out a way to do better. LastPass has generally told people to u…

Sean here: the mitigation you speak of (notifying the user that they've typed in their master password) is actually another vulnerability.

A malicious page can detect the fact that LastPass put that notification, and then it knows exactly what your master password is without even contacting LastPass. I've told your security team about this but haven't yet received a response.

Re: Phishing attack against Lastpass

#40

I believe so far my brain is still the best, if not only, secure password storage. To add a layer of security while reducing password complexity, I coded a small hasher so my brain remembers easy phrases and passwords come out of this tool über strong. I suppose I am still vulnerable to social engineering hacks or the attacker getting a hold of my hasher, but for such cases the only layer left is whatever vendors imp…

What do you do on pages that require / forbid special characters and require / forbid length >8 characters?
Post reply on HN