Live data from Hacker News

LastPass RCE vulnerability fixed

bugs.chromium.org

141–150 of 188 posts

Re: LastPass RCE vulnerability fixed

#141
post #119
post #50

Update: another vulnerability found, not patched yet. https://mobile.twitter.com/taviso/status/844312124541186048

I'm really surprised, and disappointed, that Travis announced this publicly like this. From my understanding the Google team has a policy of giving people time to patch the bug before announcing it. I know that the technical details weren't released by by confirming there is a zero day exploit he's making it more likely to be discovered and exploited. The responsible thing would have been to notify the vendor and app…

He announced it exists, though not what it is. Who knows, it might even spur some people to move away from LP.

Re: LastPass RCE vulnerability fixed

#142
post #25

Earlier quoted context omitted.

That is honestly embarrassing. I'm glad I don't use LastPass.

I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?

Keepass, although to be fair I don't think all the plugins on this page have been properly reviewed: http://keepass.info/plugins.html

Re: LastPass RCE vulnerability fixed

#144
post #34

Earlier quoted context omitted.

Looks cool. My personal "I can't use it because it lacks X" list: - Firefox extension - Password generator But I'll keep an eye on it. LastPass is far from perfect.

We have both of these things: - Firefox: https://addons.mozilla.org/en-US/firefox/addon/bitwarden-pas... - Generator: http://imgur.com/3q4w9Mn.png

You need to update your user home screen then, both features have empty links saying "coming soon".

Re: LastPass RCE vulnerability fixed

#145
post #25

Earlier quoted context omitted.

That is honestly embarrassing. I'm glad I don't use LastPass.

I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?

Has anyone used hardware-based password manager like Trezor Password Manager? [1] [2] Initially Trezor was created as a bitcoin wallet but is much more these days.

The issue with 1Password is that it's not accessible in Linux and no U2F (yubikey etc) support AFAIK...

[1] https://trezor.io/passwords/ [2] https://blog.trezor.io/satoshilabs-launches-trezor-password-...

Re: LastPass RCE vulnerability fixed

#146

Earlier quoted context omitted.

You're right, I misremembered the number of rolls for diceware. I guess your passwords have an extra bit over mine. How many 12+ character passwords are you able to memorize? How long does it take you to learn a new/changed one?

> How many 12+ character passwords are you able to memorize? As I need to enter on a regular basis. In practice, no more than half a dozen. Usually I have 3 or 4 in use. Might be work, personal, and a couple for crypto. > How long does it take you to learn a new/changed one? Depending on the length, 5-10 minutes of continuous training to be confident if it's one I'm going to put into immediate use. The point is to go…

I doubt most people type their passwords multiple times on a daily basis, so dismissing mnemonics with "just use muscle memory" doesn't look practical to me. And they're not incompatible, actually: you can eventually commit to muscle memory a diceware-like password, but in the meantime (or if it slips out of muscle memory) you got mnemonics ie. clues.

As far as I'm concerned, I've tested some diceware passwords for some months, and I would say they served me all right. I "name" my passwords by their initials (first letter of each word), so there's no risk of missing a word or swapping some.

Re: LastPass RCE vulnerability fixed

#147
post #31
post #9

Earlier quoted context omitted.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

It's always worth remembering that using something like LastPass should be compared with the status quo that it often fixes (same password for everything, post-it notes, teams emailing passwords around).

Why is that a relevant comparison for anyone interested in their own security? It seems to me that the comparison that matters is with my own status quo and with other options that I might consider, not with some average status quo.

Re: LastPass RCE vulnerability fixed

#149

Earlier quoted context omitted.

This is not always a bad thing. Sometimes you don't want software to automatically plunk your login credentials into appropriately named fields on a JavaScript driven web page

This is why we don't offer this feature. This feature is one of the major offenders for lastpass in the past. It's very easy to get wrong and expose vulnerabilities.

It _is_ a vulnerability!

Re: LastPass RCE vulnerability fixed

#150

Earlier quoted context omitted.

> How many 12+ character passwords are you able to memorize? As I need to enter on a regular basis. In practice, no more than half a dozen. Usually I have 3 or 4 in use. Might be work, personal, and a couple for crypto. > How long does it take you to learn a new/changed one? Depending on the length, 5-10 minutes of continuous training to be confident if it's one I'm going to put into immediate use. The point is to go…

I doubt most people type their passwords multiple times on a daily basis, so dismissing mnemonics with "just use muscle memory" doesn't look practical to me. And they're not incompatible, actually: you can eventually commit to muscle memory a diceware-like password, but in the meantime (or if it slips out of muscle memory) you got mnemonics ie. clues. As far as I'm concerned, I've tested some diceware passwords for s…

If it works for you, great. Maybe I was being deliberately controversial calling xkcd/diceware bullshit. Kudos for raising bad password awareness and improving practices, I suppose.

But, I still contend it basically knocks down a straw man with bullshit. Yes, they correctly point out that if you're using a mnemonic method, a long passphrase is better than a short password. I'm pretty sure the PGP folks pointed that out at least a decade or two ago.

At the end of the day, if you're not using, recalling, and exercising a strong secret, you will forget it. That's how memory works. With Diceware you have three things to learn; your silly mnemonic, what it translates to, and how to type it quickly. True, you might (just might) forget the muscle memory of exactly how to type it before you forget the entire mnemonic, and then be able to recover the password from your memory of the mnemonic cues. That seems intuitive, at least, but misleadingly so.

But my years of experience has taught me that muscle memory is the most durable memory. There's nothing inherent in "correct horse battery" that's going to give you "staple" once you've forgotten it; it's gone. It was random, after all. If you're not exercising and remembering your secret, then you have to have a backup to fall upon--written down or stored somewhere? If your goal is muscle memory with minimum pain, fewer, maximally-random higher-entropy keystrokes is better.

I don't think most people sit down at their desk all day uninterrupted without leaving. I lock my terminal when I leave my keyboard and type a password to unlock when I return. I enter a password whenever I unlock an encrypted volume (e.g., to get other passwords).

You can use biometrics or tokens, but purely memorized passwords can have unique utility. In America, for instance, you generally can't be rubber-hosed to give up a memorized passphrase, and it's not generally a crime to do so. You can be compelled in a variety of settings to provide a physical token, including biometrics, or disclose their existence. There can be civil coercive techniques to pursuade you to give up a password, but at a bare minimum, in a criminal situation or where the 5th amendment applies under my current understanding you cannot be forced to give a password from memory.

Of course if you're the surveillance target of a nation-state then potentially they can do what they need to do to covertly intercept your passphrase through physical access, evil maid etc., but that's a different ballgame.

Post reply on HN