Live data from Hacker News

LastPass RCE vulnerability fixed

bugs.chromium.org

21–30 of 188 posts

Re: LastPass RCE vulnerability fixed

#22
post #19

Earlier quoted context omitted.

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

I'm not the lead developer (or involved with the project at all) and I also recommend it. Only issues I have right now are: - No app-fill on Android. - No auto-fill (have to manually click the icon and select an account). - When using Firefox the extension periodically logs out for no apparent reason. - There's no address/wallet stuff so I actually have to pull out my credit cards. Other than that it works pretty wel…

- We released app-fill (autofill) on android last month. Make sure you are using version 1.3.0 or greater. Read more here: https://blog.bitwarden.com/android-v1-3-0-now-with-auto-fill...

- We also fixed the issue you are referring to on Firefox last week. Make sure you are using 1.10.1

- There are plans for additional "wallet" features in the future.

Re: LastPass RCE vulnerability fixed

#23
post #9
post #6

I've got to say, this attack looks a little too obvious; that doesn't reflect well on lastpass.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

I have the same concern.

Re: LastPass RCE vulnerability fixed

#24

Earlier quoted context omitted.

same here. Trialling Dashlane, but not quite convinced yet..

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

Hi, I'm considering giving bitwarden a try. I'm curious, though - are there any 3rd party security scans for the product? And (only half-joking) can we get Tavis to review it?

Re: LastPass RCE vulnerability fixed

#26

Earlier quoted context omitted.

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

Hi, I'm considering giving bitwarden a try. I'm curious, though - are there any 3rd party security scans for the product? And (only half-joking) can we get Tavis to review it?

There have not been any formal third-party audits done that we can document yet, however, the product is entirely open source (from the database, backend apis, to all client-side applications). https://github.com/bitwarden . Anyone is free to audit (and contribute) as much as they'd like. If you can get Travis (or any security researcher) interested in reviewing our products we would love to work with him.

Re: LastPass RCE vulnerability fixed

#27

Earlier quoted context omitted.

same here. Trialling Dashlane, but not quite convinced yet..

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

How are you making money off of this?

Re: LastPass RCE vulnerability fixed

#28

Earlier quoted context omitted.

what is your hesitation with dashlane?

No Linux support might be a biggie.

No linux support seems like hard deal breaker for a linux user. His comment indicated he was questioning the security practices or some other technical reason

Re: LastPass RCE vulnerability fixed

#29
post #9
post #6

I've got to say, this attack looks a little too obvious; that doesn't reflect well on lastpass.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

Concern about code quality is legitimate, and vulns discovered is one metric for that, but I worry that hopping to the unreviewed (and therefore lacking vuln disclosures) app is even worse. But I don't use lastpass.

Re: LastPass RCE vulnerability fixed

#30

Earlier quoted context omitted.

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

How are you making money off of this?

bitwarden is currently sponsored by the Microsoft BizSpark program which covers many of our operation costs and allows us to offer services for free to our users. We are working to introduce enterprise features for businesses in the future (scheduled for release next month) which will allow us to monetize. In the meantime, everything is free for users.
Post reply on HN