Live data from Hacker News

LastPass RCE vulnerability fixed

bugs.chromium.org

1–10 of 188 posts

Re: LastPass RCE vulnerability fixed

#2
Apparently this was fixed server-side and does not require any update to the client. However the default version on addons.mozilla.org is very old for some reason, so if you are running 3.x it wouldn't hurt to download the latest. You can get it either from LastPass's website directly or from https://addons.mozilla.org/en-US/firefox/addon/lastpass-pass...

Re: LastPass RCE vulnerability fixed

#4
post #3

Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.

Well, this is Project Zero, the security researchers working there are highly competent, but I do agree this guy is amazing. I wonder what kind of methodology do they use to even come up with these attacks.

Re: LastPass RCE vulnerability fixed

#5
post #3

Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.

He also found vulnerabilities in many more security products out there. At some point, years ago, Microsoft became very hostile toward him, but things seem to be better now.

Re: LastPass RCE vulnerability fixed

#7
post #2

Apparently this was fixed server-side and does not require any update to the client. However the default version on addons.mozilla.org is very old for some reason, so if you are running 3.x it wouldn't hurt to download the latest. You can get it either from LastPass's website directly or from https://addons.mozilla.org/en-US/firefox/addon/lastpass-pass...

The 3.x is still updated, but they're replacing it soon. 4.x is a WebExtension, with a different UI.

See https://blog.lastpass.com/2017/03/plans-to-retire-the-lastpa... for details.

Re: LastPass RCE vulnerability fixed

#8
Note that this issue references another (not yet public) issue which is apparently for LastPass on firefox. I expect we'll see a LastPass + Firefox issue in the near future.

> (Please note, issue 1188 which affects LastPass on firefox is not fixed, and still works)

Re: LastPass RCE vulnerability fixed

#9
post #6

I've got to say, this attack looks a little too obvious; that doesn't reflect well on lastpass.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.
Post reply on HN