Live data from Hacker News

LastPass: design flaw in communication to privileged components

bugs.chromium.org

1–10 of 45 posts

Re: LastPass: design flaw in communication to privileged components

#2
Agree with the comment that the blogger doesn't understand what phishing is. This could be done against a huge number of people through various approaches with ad network code or targeted attacks controlling path to internet. That's all setting aside how trivial it would be for nation states.

Re: LastPass: design flaw in communication to privileged components

#3
post #2

Agree with the comment that the blogger doesn't understand what phishing is. This could be done against a huge number of people through various approaches with ad network code or targeted attacks controlling path to internet. That's all setting aside how trivial it would be for nation states.

They have a history of trying to explain away their security problems as not really their fault. That alone should give any LastPass user pause.

Re: LastPass: design flaw in communication to privileged components

#4
post #2

Agree with the comment that the blogger doesn't understand what phishing is. This could be done against a huge number of people through various approaches with ad network code or targeted attacks controlling path to internet. That's all setting aside how trivial it would be for nation states.

I don't.

The phrasing was "both exploits do require tricking a user via a phishing attack into going to a malicious website".

This suggests that the blogger believes that the only attack vector involves tricking the user to go to a malicious website; I can reasonably see calling such attacks phishing attacks.

The problem (which is, in my opinion, more serious) is that, as you identify, the blogger seems to horribly misunderstand the potential attack vectors.

Re: LastPass: design flaw in communication to privileged components

#5
Password managers exchange a strong secret, something you know, for a weak one, something you have. Once an attacker gets to your database you're completely owned. When they compromise a normal password the damage is more contained if you maintain reasonable security practices.

Re: LastPass: design flaw in communication to privileged components

#6

Password managers exchange a strong secret, something you know, for a weak one, something you have. Once an attacker gets to your database you're completely owned. When they compromise a normal password the damage is more contained if you maintain reasonable security practices.

I thought the point of a password manager is to allow you to have separate passwords for numerous services which are protected by centralizing those passwords somewhere (preferably somewhere you control, such as your own phone) and protecting the result with one password. Your model of them seems to involve them replacing a password locally, which I don't think anyone would recommend.

Re: LastPass: design flaw in communication to privileged components

#7

Password managers exchange a strong secret, something you know, for a weak one, something you have. Once an attacker gets to your database you're completely owned. When they compromise a normal password the damage is more contained if you maintain reasonable security practices.

Just about any scenario I can think of where the attacker could get to "what you have", by which I assume you mean the unencrypted password database (i.e. what you have after you entered something you know, since the whole point of a password manager is to have one strong password that you need to remember, instead of tens or hundreds probably-not-so-strong individual passwords), would also be a game-over scenario if you keep all your passwords in your head, since the attacker could just run a keylogger and take the passwords as you type them during regular use instead of getting your unencrypted password database after you unlock it.
Post reply on HN