Live data from Hacker News

LastPass RCE vulnerability fixed

bugs.chromium.org

11–20 of 188 posts

Re: LastPass RCE vulnerability fixed

#11
post #7
post #2

Apparently this was fixed server-side and does not require any update to the client. However the default version on addons.mozilla.org is very old for some reason, so if you are running 3.x it wouldn't hurt to download the latest. You can get it either from LastPass's website directly or from https://addons.mozilla.org/en-US/firefox/addon/lastpass-pass...

The 3.x is still updated, but they're replacing it soon. 4.x is a WebExtension, with a different UI. See https://blog.lastpass.com/2017/03/plans-to-retire-the-lastpa... for details.

Oh you're right. I was confused and there are two bugs, only one of which has been fixed so far. The first one, which is apparently still unfixed, mentioned here https://twitter.com/taviso/status/842205051082821632 only works on 3.x on Firefox.

Re: LastPass RCE vulnerability fixed

#12
post #9
post #6

I've got to say, this attack looks a little too obvious; that doesn't reflect well on lastpass.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

same here. Trialling Dashlane, but not quite convinced yet..

Re: LastPass RCE vulnerability fixed

#13
post #9

Earlier quoted context omitted.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

same here. Trialling Dashlane, but not quite convinced yet..

what is your hesitation with dashlane?

Re: LastPass RCE vulnerability fixed

#14
post #9
post #6

I've got to say, this attack looks a little too obvious; that doesn't reflect well on lastpass.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

Can you please provide some references to the "high number of vulnerabilities"? I've only heard of one or two, but those were promptly fixed.

Re: LastPass RCE vulnerability fixed

#15
post #9

Earlier quoted context omitted.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

same here. Trialling Dashlane, but not quite convinced yet..

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

Re: LastPass RCE vulnerability fixed

#16
post #3

Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.

One of the best vulnerability researchers in the world right now. Tavis Ormandy is a spectre of doom. He is one of the last people you want to see tweeting about your company.

Every member of Google's Project Zero team is individually more capable and productive than entire teams of consultants at the best security firms.

Re: LastPass RCE vulnerability fixed

#18
post #4
post #3

Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.

Well, this is Project Zero, the security researchers working there are highly competent, but I do agree this guy is amazing. I wonder what kind of methodology do they use to even come up with these attacks.

Having briefly interacted with a few of them, and following their work in general:

1. They have a phenomenal intuition for where developers get lazy, tired or simply incompetent in security-sensitive code,

2. They have, in aggregate, a vast knowledge and understanding of past vulnerabilities and how those might be repeated elsewhere or imperfectly patched,

3. They practice a lot and they read a lot (i.e. relevant research, etc). It might be more accurate to say that they have a lot of practice because of their work, not that they actively practice outside of work.

4. They are good at the general process of security research - long hours of mostly dull, complex research interspersed with brief eureka moments and bouts of euphoria.

They're an extraordinary team, for sure.

Re: LastPass RCE vulnerability fixed

#19

Earlier quoted context omitted.

same here. Trialling Dashlane, but not quite convinced yet..

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

I'm not the lead developer (or involved with the project at all) and I also recommend it.

Only issues I have right now are:

- No app-fill on Android.

- No auto-fill (have to manually click the icon and select an account).

- When using Firefox the extension periodically logs out for no apparent reason.

- There's no address/wallet stuff so I actually have to pull out my credit cards.

Other than that it works pretty well.

Re: LastPass RCE vulnerability fixed

#20
post #9

Earlier quoted context omitted.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

Can you please provide some references to the "high number of vulnerabilities"? I've only heard of one or two, but those were promptly fixed.

[deleted]
Post reply on HN