Live data from Hacker News

LastPass bug leaks credentials from previous site

zdnet.com

171–180 of 196 posts

Re: LastPass bug leaks credentials from previous site

#171

Earlier quoted context omitted.

Yes, but that's the essence of the whole problem: there are ways to spoof what the current website is, causing your context-aware password manager to spit out data it shouldn't. Diabling autofill pretty much eliminates the whole vector though, without breaking UX that hard.

> there are ways to spoof what the current website is, causing your context-aware password manager to spit out data it shouldn't. Can you give an example?

There was this example from 2017. https://freedom-to-tinker.com/2017/12/27/no-boundaries-for-u...

I seem to remember reading about similar stuff done elsewhere, but don't remember the details (or apparently a useful search term :P).

Re: LastPass bug leaks credentials from previous site

#172
Password manager recommendations from Tavis Ormandy, who found the bug:

"KeePass and KeePassX are both good choices. If you really must use an online one, at least LastPass are responsive to researchers and have a competent security team, I would use them."

He adds about Lastpass:

"I consider them competent, I've reported some pretty complex issues and found they handle them well. Attack surface is definitely massive, I always recommend KeePass or just use a book if that's too complicated"

(source: https://twitter.com/taviso/status/1167311357957435392)

Re: LastPass bug leaks credentials from previous site

#173
post #10

Was prepared to change all my darn credentials when clicking on that. For those clicking the comments first, the byline is: "LastPass has released a fix last week. Vulnerability details are now public. Users advised to update."

For something that has such a long trail of vulnerabilities, I don't recommend LastPass to family friends and business associates. Use 1Password instead, or pass. Just one example (this one from 2017) of many: https://bugs.chromium.org/p/project-zero/issues/detail?id=12... . Fundamental architectural flaws. For more HN references, see https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...

Tavis Ormandy, who discovered the latest and several other Lastpass bugs, has these password manager recommendations:

"KeePass and KeePassX are both good choices. If you really must use an online one, at least LastPass are responsive to researchers and have a competent security team, I would use them."

Asked about the experience he had reporting a 1Password vulnerability, he says:

"Astonishingly bad"

(source: https://twitter.com/taviso/status/1167311357957435392)

Re: LastPass bug leaks credentials from previous site

#174

Earlier quoted context omitted.

I've been using something very similar, though I only have a local keyfile that I independently put on my synced machines rather than the yubikey thing. How do you like the yubikey process? Not too much of a pain?

Not much of an issue at all, it does mean that when i need to unlock my manager or save the database, i have to have my [physical] keys around but it's otherwise not an issue. I've got two duplicated yubikeys for it, a neo with nfc and a 5 with usb-c. I generally use the neo for everything but needed the usb-c one for laptops with no USB-A ports and my tablet which also has no USB-A or NFC. Just the march of progress…

Forgot to mention, the syncing is all done via Nextcloud (open source dropbox like system, but also does a lot more).

Re: LastPass bug leaks credentials from previous site

#175

Earlier quoted context omitted.

lastpass' privacy policy is very privacy hostile. They're now aggressively offering a free product with the ability to monitor (and sell) all browsing behavior tied to you as an individual (thanks to LogMeIn). >How We Use the Information We Collect and Receive >LogMeIn may access (which may include, with your consent, limited viewing or listening) and use the data we collect as necessary (a) to provide and maintain t…

LastPass only collects data on how you use the product and how well the product works. It doesn't collect info about your sites or browsing activity.

Says who? It's governed by this privacy policy and will not work until it has browsing and tab data

Re: LastPass bug leaks credentials from previous site

#176
post #42

Classic LastPass. Shoddiest pw manager out there with history of editing wiki pages to hide their sad track record.

Interested in this. Got a link?

I've described it here: https://news.ycombinator.com/item?id=15756044

Re: LastPass bug leaks credentials from previous site

#177
post #9

Earlier quoted context omitted.

That makes no sense as the point of attack here is exactly the extension. So wrt this type of bug you gain nothing.

You have the option of not using the extension with this method, and the same vulnerability likely doesn't exist with Browserpass due to the communication method.

But you have the same option with lastpass.

Re: LastPass bug leaks credentials from previous site

#178

Earlier quoted context omitted.

Yes, but that's the essence of the whole problem: there are ways to spoof what the current website is, causing your context-aware password manager to spit out data it shouldn't. Diabling autofill pretty much eliminates the whole vector though, without breaking UX that hard.

> there are ways to spoof what the current website is, causing your context-aware password manager to spit out data it shouldn't. Can you give an example?

Isn't the XSS example highlighted here a good example?

Re: LastPass bug leaks credentials from previous site

#179

Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.

Is that the “new” ui you’re speaking of? The old, pre 2019 UI, on MacOS was actually pretty nice and clean but the new webview one is a sad turn in the wrong direction.

Re: LastPass bug leaks credentials from previous site

#180

Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.

Long time last pass user...what do you recommend? Team of 15-30 people, need shared username/password credentials for web, FTP, and DB systems. Also other arbitrary secure "notes", e.g. SSH key. Needs 2FA as well.

https://padloc.app (currently in beta. shoot me an email if you want to try it: martin@padloc.app)
Post reply on HN