Live data from Hacker News

LastPass RCE vulnerability fixed

bugs.chromium.org

171–180 of 188 posts

Re: LastPass RCE vulnerability fixed

#171

Earlier quoted context omitted.

I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?

1Password, and it's been awesome. If you use the non-hosted version you control the whole thing. LAN only sync, or Dropbox, Rsync, however you want to sync it if it matters. Otherwise they've got a hosted version which can also give you web access in a pinch and handle all the syncing for you. I have been with them for long enough that my only option was a non-hosted version and I keep in sync with Dropbox and it wor…

But no linux support.

Re: LastPass RCE vulnerability fixed

#172

Earlier quoted context omitted.

Which mobile app do you use with KeePass? I use MiniKeePass and am pretty happy with it.

It's a good app but as far as I remember the integration with Dropbox wasn't working properly. I think that's the main issue with KeePass right now - getting your passwords synchronized with your phone.

SyncThing solves this quite nicely on Android at least. For iOS, I'm not sure, Apple's restrictions make proper sync near impossible in the name of battery life - even while charging or on WiFi.

Re: LastPass RCE vulnerability fixed

#173
post #25

Earlier quoted context omitted.

That is honestly embarrassing. I'm glad I don't use LastPass.

I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?

I use password safe: https://pwsafe.org/ with a strong central password and store the safe it in my Dropbox. Even if my cloud was compromised, the safe is highly encrypted.

PasswordSafe's safe is an open source file structure and thus there are many different ways to access it with different features for each. I have PasswordSafe on both my Windows PC and android phone and I'm using PasswordSafe professionally for my organization's passwords and found that there are reliable Mac options so those with Macs can access the safe.

Re: LastPass RCE vulnerability fixed

#174
post #98
post #67

Brilliant find by taviso. So simple yet thousands of others passed over it. It takes a relentless mind to comb through all this code and actually find such an issue.

> So simple yet thousands of others passed over it. is that true? how do you know?

LastPas has been in the spotlight for quite some time now, and repeatedly critized by the security community. I've also read various articles about alleged security flaws with LastPass (which were quickly resolved by the team).

Re: LastPass RCE vulnerability fixed

#175

>>Its a pretty bad trait we should do something about that and just continue striving for peer reviewable code and implementations. COMMENT OF THE DECADE. If you think that lastpass should be embarrassed based on what Tavis has written, maybe consider taking a lit criticism class. There is a concept called an "unreliable narrator." Tavis has a documented track record of poor interpersonal behavior. It's time that peo…

Personal attacks are not allowed on HN. We ban accounts that do this, so please don't do it again.

Unfortunately, your comment history has plenty of uncivil and unsubstantive comments. It also has some really good ones, so we aren't banning you, but if you keep doing this, we'll have to, so please fix it.

We detached this subthread from https://news.ycombinator.com/item?id=13927087 and marked it off-topic.

Re: LastPass RCE vulnerability fixed

#176
post #119

Earlier quoted context omitted.

I'm really surprised, and disappointed, that Travis announced this publicly like this. From my understanding the Google team has a policy of giving people time to patch the bug before announcing it. I know that the technical details weren't released by by confirming there is a zero day exploit he's making it more likely to be discovered and exploited. The responsible thing would have been to notify the vendor and app…

He announced it exists, though not what it is. Who knows, it might even spur some people to move away from LP.

They fixed all 3 bugs already. https://mobile.twitter.com/taviso/status/844573211278794753 I'm not moving.

Re: LastPass RCE vulnerability fixed

#177
post #145

Earlier quoted context omitted.

Has anyone used hardware-based password manager like Trezor Password Manager? [1] [2] Initially Trezor was created as a bitcoin wallet but is much more these days. The issue with 1Password is that it's not accessible in Linux and no U2F (yubikey etc) support AFAIK... [1] https://trezor.io/passwords/ [2] https://blog.trezor.io/satoshilabs-launches-trezor-password-...

I've wanted to use such a thing, but the requirement to use a specific browser is always a massive bother same with things like yubikey It seems like it would be better to just fake a keyboard output instead? then you could have something that could work on all platforms in all situations

KeePass does this. Autofill activates the last window, finds the "input control" on the window, then tries to type in the username, tab key, password. It breaks in all the expected ways, and sometimes new and exciting ways.

Re: LastPass RCE vulnerability fixed

#178
Most of the reported issues I've seen have been caused by browser extensions. It seems like uninstalling the extensions and just using the web app directly in a separate browser might go a long way towards avoiding these kinds of issues.

Re: LastPass RCE vulnerability fixed

#179

Earlier quoted context omitted.

1Password, and it's been awesome. If you use the non-hosted version you control the whole thing. LAN only sync, or Dropbox, Rsync, however you want to sync it if it matters. Otherwise they've got a hosted version which can also give you web access in a pinch and handle all the syncing for you. I have been with them for long enough that my only option was a non-hosted version and I keep in sync with Dropbox and it wor…

But no linux support.

No direct Linux support but you can absolutely run the windows version 4 in Wine. It's not without a few crashy glitches but for just using stored passwords it works fine.

It would be very nice if they did support Linux and people have been asking for it, but there is a passable workaround- and frankly one I'm willing to work with because it works so great everywhere else.

Re: LastPass RCE vulnerability fixed

#180

Earlier quoted context omitted.

But no linux support.

No direct Linux support but you can absolutely run the windows version 4 in Wine. It's not without a few crashy glitches but for just using stored passwords it works fine. It would be very nice if they did support Linux and people have been asking for it, but there is a passable workaround- and frankly one I'm willing to work with because it works so great everywhere else.

That only works if you store your vault yourself.

When I tried it out I wanted 1password family so I could share some accounts with my partner. 1password 4 doesn't support their cloud datastore; the version that does will not run on Wine.

However, I could use the webapp on linux. It was a bit annoying but I could have dealt with it. The other complaint I had was the UX for Android. Having to switch my keyboard every time I wanted to enter a password was very annoying. Hopefully that gets better with the recently announced Autofill API for Android O.

Post reply on HN