Live data from Hacker News

LastPass RCE vulnerability fixed

bugs.chromium.org

111–120 of 188 posts

Re: LastPass RCE vulnerability fixed

#111

Earlier quoted context omitted.

same here. Trialling Dashlane, but not quite convinced yet..

If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).

cool, thanks - I'll have a look!

Re: LastPass RCE vulnerability fixed

#112
post #25

Earlier quoted context omitted.

That is honestly embarrassing. I'm glad I don't use LastPass.

I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?

Have you tried Dashlane? I've been using it for over a year and it's been great. Their mobile app is really handy as well.

Re: LastPass RCE vulnerability fixed

#113

Earlier quoted context omitted.

same here. Trialling Dashlane, but not quite convinced yet..

what is your hesitation with dashlane?

cost, and clunky yubikey support. I can enable a yubikey with some hoop-jumping but this will impact ease of use on my mobile clients. I still need to look into the team functionality. I have used Lastpass for many years privately and for my business, and it is pretty deeply stuck in everything we do, so evaluation takes time.

Re: LastPass RCE vulnerability fixed

#115
post #81

Earlier quoted context omitted.

Isn't sharing passwords a bad thing to do in general? Each user should have a separate account/identity and manage his own secrets.

There are endless online services which only allow one user per logical account. In fact I would say the majority of them do it.

So why not create multiple accounts? ToS usually advises against sharing credentials.

Re: LastPass RCE vulnerability fixed

#116

Earlier quoted context omitted.

I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?

I would suggest not using the auto fill feature of password managers. I use 1Password and the mini UI that sits in the tray is super easy to copy a password from and paste in the browser.

Why not use auto fill? I consider that a decent defense against phishing attempts. Now I always think twice before entering my name and password.

Re: LastPass RCE vulnerability fixed

#117
post #108

Earlier quoted context omitted.

bitwarden is currently sponsored by the Microsoft BizSpark program which covers many of our operation costs and allows us to offer services for free to our users. We are working to introduce enterprise features for businesses in the future (scheduled for release next month) which will allow us to monetize. In the meantime, everything is free for users.

Which of the current free-for-everyone features, if any, are you considering making available to paid accounts only? (i.e., what will your current free users lose unless they move to a paid account once you monetize?)

Everything you see today will remain free for personal users.

Re: LastPass RCE vulnerability fixed

#118
post #63

Earlier quoted context omitted.

Woo! I just got app-fill working. To be clear though, app-fill and auto-fill were referring to different things. What I meant by lack of "auto-fill" was that when I visit a website on desktop, my details aren't instantly filled when the page loads. I have to manually click the extension icon in my browser and select the account I want.

This is not always a bad thing. Sometimes you don't want software to automatically plunk your login credentials into appropriately named fields on a JavaScript driven web page

This is why we don't offer this feature. This feature is one of the major offenders for lastpass in the past. It's very easy to get wrong and expose vulnerabilities.

Re: LastPass RCE vulnerability fixed

#119
post #50

Update: another vulnerability found, not patched yet. https://mobile.twitter.com/taviso/status/844312124541186048

I'm really surprised, and disappointed, that Travis announced this publicly like this. From my understanding the Google team has a policy of giving people time to patch the bug before announcing it. I know that the technical details weren't released by by confirming there is a zero day exploit he's making it more likely to be discovered and exploited. The responsible thing would have been to notify the vendor and apply the standard policy they have in place for disclosure.

Re: LastPass RCE vulnerability fixed

#120
post #25

Earlier quoted context omitted.

That is honestly embarrassing. I'm glad I don't use LastPass.

I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?

Seconding 1Password. It also works on Firefox and can be used from Mobile Safari and apps that implement support specifically for it, if you have an iPhone.
Post reply on HN