Live data from Hacker News

LastPass RCE vulnerability fixed

bugs.chromium.org

31–40 of 188 posts

Re: LastPass RCE vulnerability fixed

#31
post #9
post #6

I've got to say, this attack looks a little too obvious; that doesn't reflect well on lastpass.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

It's always worth remembering that using something like LastPass should be compared with the status quo that it often fixes (same password for everything, post-it notes, teams emailing passwords around).

Re: LastPass RCE vulnerability fixed

#32
post #29
post #9

Earlier quoted context omitted.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

Concern about code quality is legitimate, and vulns discovered is one metric for that, but I worry that hopping to the unreviewed (and therefore lacking vuln disclosures) app is even worse. But I don't use lastpass.

Other managers have been reviewed, and found better success than LastPass. I (finally) signed up for a password manager a little while ago, and after some evaluation chose 1Password.

A big part of that decision was that they have been reviewed/audited and there were a couple vulnerabilities found, but they were all minor, which indicates to me the system is pretty secure. The nature of the bugs was also comforting in that they seemed like small oversights, compared to a lot of the LastPass bugs which seem like "holy shit how did you let this happen".

Re: LastPass RCE vulnerability fixed

#34

Earlier quoted context omitted.

same here. Trialling Dashlane, but not quite convinced yet..

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

Looks cool. My personal "I can't use it because it lacks X" list:

- Firefox extension

- Password generator

But I'll keep an eye on it. LastPass is far from perfect.

Re: LastPass RCE vulnerability fixed

#35
Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features:

1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.

Re: LastPass RCE vulnerability fixed

#36
post #34

Earlier quoted context omitted.

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

Looks cool. My personal "I can't use it because it lacks X" list: - Firefox extension - Password generator But I'll keep an eye on it. LastPass is far from perfect.

We have both of these things:

- Firefox: https://addons.mozilla.org/en-US/firefox/addon/bitwarden-pas...

- Generator: http://imgur.com/3q4w9Mn.png

Re: LastPass RCE vulnerability fixed

#37
post #34

Earlier quoted context omitted.

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

Looks cool. My personal "I can't use it because it lacks X" list: - Firefox extension - Password generator But I'll keep an eye on it. LastPass is far from perfect.

bitwarden has a Firefox extension [1], and it has a password generator.

[1] https://addons.mozilla.org/firefox/addon/bitwarden-password-...

Re: LastPass RCE vulnerability fixed

#38

Earlier quoted context omitted.

Hi, I'm considering giving bitwarden a try. I'm curious, though - are there any 3rd party security scans for the product? And (only half-joking) can we get Tavis to review it?

There have not been any formal third-party audits done that we can document yet, however, the product is entirely open source (from the database, backend apis, to all client-side applications). https://github.com/bitwarden . Anyone is free to audit (and contribute) as much as they'd like. If you can get Travis (or any security researcher) interested in reviewing our products we would love to work with him.

Thanks. Are there any plans to have routine security audits done?

Re: LastPass RCE vulnerability fixed

#40

Earlier quoted context omitted.

same here. Trialling Dashlane, but not quite convinced yet..

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

Perhaps you missed it at the time but I'm wondering if you can answer this https://news.ycombinator.com/item?id=13438225
Post reply on HN