Live data from Hacker News

Phishing attack against Lastpass

seancassidy.me

1–10 of 69 posts

Re: Phishing attack against Lastpass

#2
This is of the devil. It needs to be burned with fire and the ashes should be sunk in the Mariana trench and the trench should be filled with dirt that has been cursed by a witch that was formerly dead but was reanimated by Cthulhu and then rekilled, burned with fire, and buried on the opposite side of the earth.

Everything here is usual phishing stuff, but that Chrome-Extension.pw url is disturbing combined with the lastpass API stuff.

Re: Phishing attack against Lastpass

#3
post #2

This is of the devil. It needs to be burned with fire and the ashes should be sunk in the Mariana trench and the trench should be filled with dirt that has been cursed by a witch that was formerly dead but was reanimated by Cthulhu and then rekilled, burned with fire, and buried on the opposite side of the earth. Everything here is usual phishing stuff, but that Chrome-Extension.pw url is disturbing combined with the…

Where's that quote coming from? It's awesome.

Re: Phishing attack against Lastpass

#5
Woah, this is scary. I'll need to look closely at LastPass alternatives (perhaps something that runs separately from the browser, even if it's a little more clunky to use than LastPass's integration).

Re: Phishing attack against Lastpass

#6
post #5

Woah, this is scary. I'll need to look closely at LastPass alternatives (perhaps something that runs separately from the browser, even if it's a little more clunky to use than LastPass's integration).

I'll keep using Lastpass and I'm not sure that this is really their fault, but I have to say this is the first phishing scheme that I've thought "Wow, I would definitely fall for that".

The chrome-extension.pw domain looked almost exactly the same as the Lastpass URL at first glance. I wonder if it would help if Chrome added a special URL-bar designation for extensions.

EDIT: It looks like Chromium has an issue for adding this sort of URL-bar designation: https://code.google.com/p/chromium/issues/detail?id=453093

Re: Phishing attack against Lastpass

#7
I believe so far my brain is still the best, if not only, secure password storage. To add a layer of security while reducing password complexity, I coded a small hasher so my brain remembers easy phrases and passwords come out of this tool über strong. I suppose I am still vulnerable to social engineering hacks or the attacker getting a hold of my hasher, but for such cases the only layer left is whatever vendors implement to defend its users, like SSL, 2FA or external devices.

Re: Phishing attack against Lastpass

#8

I believe so far my brain is still the best, if not only, secure password storage. To add a layer of security while reducing password complexity, I coded a small hasher so my brain remembers easy phrases and passwords come out of this tool über strong. I suppose I am still vulnerable to social engineering hacks or the attacker getting a hold of my hasher, but for such cases the only layer left is whatever vendors imp…

Still, that's just one password. Do you use this one password for all your accounts, or as input to a password manager?

Or are you just manually copying and pasting this one super good hash into all your accounts? :/

Re: Phishing attack against Lastpass

#10

I believe so far my brain is still the best, if not only, secure password storage. To add a layer of security while reducing password complexity, I coded a small hasher so my brain remembers easy phrases and passwords come out of this tool über strong. I suppose I am still vulnerable to social engineering hacks or the attacker getting a hold of my hasher, but for such cases the only layer left is whatever vendors imp…

Still, that's just one password. Do you use this one password for all your accounts, or as input to a password manager? Or are you just manually copying and pasting this one super good hash into all your accounts? :/

Different phrases->hashes for each vendor. The brain can easily remember what short phrase corresponds to what vendor.
Post reply on HN