I've got to say, this attack looks a little too obvious; that doesn't reflect well on lastpass.
The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.
LastPass RCE vulnerability fixed
31–40 of 188 posts
Re: LastPass RCE vulnerability fixed
#32Earlier quoted context omitted.
The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.
Concern about code quality is legitimate, and vulns discovered is one metric for that, but I worry that hopping to the unreviewed (and therefore lacking vuln disclosures) app is even worse. But I don't use lastpass.
A big part of that decision was that they have been reviewed/audited and there were a couple vulnerabilities found, but they were all minor, which indicates to me the system is pretty secure. The nature of the bugs was also comforting in that they seemed like small oversights, compared to a lot of the LastPass bugs which seem like "holy shit how did you let this happen".
Re: LastPass RCE vulnerability fixed
#33Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.
Re: LastPass RCE vulnerability fixed
#34Earlier quoted context omitted.
same here. Trialling Dashlane, but not quite convinced yet..
If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).
- Firefox extension
- Password generator
But I'll keep an eye on it. LastPass is far from perfect.
Re: LastPass RCE vulnerability fixed
#351. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.
Re: LastPass RCE vulnerability fixed
#36Earlier quoted context omitted.
If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).
Looks cool. My personal "I can't use it because it lacks X" list: - Firefox extension - Password generator But I'll keep an eye on it. LastPass is far from perfect.
- Firefox: https://addons.mozilla.org/en-US/firefox/addon/bitwarden-pas...
- Generator: http://imgur.com/3q4w9Mn.png
Re: LastPass RCE vulnerability fixed
#37Earlier quoted context omitted.
If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).
Looks cool. My personal "I can't use it because it lacks X" list: - Firefox extension - Password generator But I'll keep an eye on it. LastPass is far from perfect.
[1] https://addons.mozilla.org/firefox/addon/bitwarden-password-...
Re: LastPass RCE vulnerability fixed
#38Earlier quoted context omitted.
Hi, I'm considering giving bitwarden a try. I'm curious, though - are there any 3rd party security scans for the product? And (only half-joking) can we get Tavis to review it?
There have not been any formal third-party audits done that we can document yet, however, the product is entirely open source (from the database, backend apis, to all client-side applications). https://github.com/bitwarden . Anyone is free to audit (and contribute) as much as they'd like. If you can get Travis (or any security researcher) interested in reviewing our products we would love to work with him.
Re: LastPass RCE vulnerability fixed
#39Re: LastPass RCE vulnerability fixed
#40Earlier quoted context omitted.
same here. Trialling Dashlane, but not quite convinced yet..
If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).