Security Issues with LastPass on Android
abhyudaya.dev
Security Issues with LastPass on Android
1–10 of 64 posts
Re: Security Issues with LastPass on Android
#2Re: Security Issues with LastPass on Android
#3Re: Security Issues with LastPass on Android
#4Re: Security Issues with LastPass on Android
#5These aren't really novel security vulnerabilities or anything, just some common sense things to be aware of so you don't shoot yourself in the foot: generated pronounceable passwords might not strictly follow the length that you set, don't paste your passwords into the address bar of a web view, and don't set a weak master password.
Password managers are increasingly mandated by organisations, and Lastpass is a very common recommendation. Even in the minority of technical users that use this kind of tool I expect small mistakes - like accidentally pasting a password in a URL. A good tool doesn't let you shoot yourself in the foot by escalting that to a non-obvious leak. The password length being wrong is 100% on the tool. Th weak master password and the duplicates are again, things the tool shouldn't do - it claims to give good quality security reports.
With respect to Lastpass specifically, I dislike the tool immensely. Ive had to use it a number of times and have always found its UX significantly buggy - included blatant failures like not saving passwords with no indication; coupled with the acquisition by LogMeIn and I'm incredibly distrustful.
Re: Security Issues with LastPass on Android
#6These aren't really novel security vulnerabilities or anything, just some common sense things to be aware of so you don't shoot yourself in the foot: generated pronounceable passwords might not strictly follow the length that you set, don't paste your passwords into the address bar of a web view, and don't set a weak master password.
Re: Security Issues with LastPass on Android
#7Companies that use password managers are infinitely better off with one then without. My co-workers would repeat their passwords and make them incredibly simple and easy for anyone to break the it with basic social hacking. My old company had the lowest level of tech skills and the company contracted their IT work and had the stupidest password policy. You just had to change one digit. So the joke was people would just +1 their passwords and they would know how long they worked there.
Repeated passwords is something people do because we all have hundreds of passwords if they don't have a password manager. Even me and my paranoid ways had several because I had to use a system that was based on the url of what I using.
Re: Security Issues with LastPass on Android
#8These aren't really novel security vulnerabilities or anything, just some common sense things to be aware of so you don't shoot yourself in the foot: generated pronounceable passwords might not strictly follow the length that you set, don't paste your passwords into the address bar of a web view, and don't set a weak master password.
Too short passwords being generated sounds like an issue that IMO violates user expectations, the other two do not.
Re: Security Issues with LastPass on Android
#9These aren't really novel security vulnerabilities or anything, just some common sense things to be aware of so you don't shoot yourself in the foot: generated pronounceable passwords might not strictly follow the length that you set, don't paste your passwords into the address bar of a web view, and don't set a weak master password.
Thats right, we should blame the victim for trusting the tool. Password managers are increasingly mandated by organisations, and Lastpass is a very common recommendation. Even in the minority of technical users that use this kind of tool I expect small mistakes - like accidentally pasting a password in a URL. A good tool doesn't let you shoot yourself in the foot by escalting that to a non-obvious leak. The password…
Re: Security Issues with LastPass on Android
#10That's very interesting. I would love to read this student's paper once it comes out.