Live data from Hacker News

LastPass autofill exploit

labs.detectify.com

11–20 of 443 posts

Re: LastPass autofill exploit

#12
Please correct me if I am mistaken, but couldn't this have been implemented into an iframe that when ran could send the passwords to another remote server?

If so, I am a little taken back by LastPass only offering $1,000 to the researcher that found and reported it for fixing. He or she could have taken a different path and resulted in this being used in some complex targeted attack against tech corporations via short-url redirect interstitial pages, or an ad network's javascript, etc. Given the potential damage, I'd say there is a missing zero or two on that reward amount, in my opinion.

Re: LastPass autofill exploit

#13
I've been using LastPass for about 3 years, and now I'm seriously thinking about all the times people told me about how storing passwords in someone else's cloud is bad.

I've been defending LastPass and recommending it to everyone till today. Now I'm thinking about how I might have to 'pay' for a software vulnerability in some private (read:unauditable by me) code. All the comments about offline, local backups make sense to me.

But the points I usually make are still valid, like:

1. I can go to any computer with chrome and get access to all my passwords, so don't have to carry my passwords with me everywhere.

2. Don't have to worry about storing passwords properly since lastpass is a good company and they know their stuff about protecting the customers' data.

3. Password capture. It might seem like a tiny feature, but I'm too lazy to remember opening an app and entering my credentials whenever I create an account or login into an old account.

4. Mobile login, although a paid feature, this really changes my life. If I don't trust a computer enough to login via chrome or something else, or want my secret notes, I just open up my phone.

But all the above features meaning nothing when it comes to the chance of compromising all my passwords (except bank info, of course)

I'd like to hear the thoughts of anyone else who uses lastpass and what they think.

Re: LastPass autofill exploit

#14

Was this an issue with the browser extension? How (and how often) are updates pushed to the client?

Yes, at least the Chrome one.

They're pushed via Chrome's extension store. Definitely at browser startup, but otherwise periodically every 5 hours (by default)

Re: LastPass autofill exploit

#16
post #15
post #11

People trusting a third party for their passwords boggles my mind.

Where do you write yours down?

I'd recommend Pass [1].

It stores your data locally, is suprisingly easy to use and relies on battle tested GPG.

From the website: "The community has even produced a cross-platform GUI client, an Android app, an iOS app, a Firefox plugin, a Windows client, a pretty Python QML app, a nice Go GUI app, an interactive console UI, Alfred integration (1) (2) (3), a dmenu script, OS X integration, git credential integration, and even an emacs package."

[1] https://www.passwordstore.org/

Re: LastPass autofill exploit

#17
post #11

People trusting a third party for their passwords boggles my mind.

Well, there's always a balance with usability.

password reuse There's another dimension for cross-platform support somewhere in there. At the moment if you want your passwords saved and shared between desktops and mobiles, the best solution I'm aware of is 1password with separate sync (dropbox/icloud) - and you're still trusting the 1password app. You can go further, but you're starting to destroy usability on the way. Lastpass / 1password is still a valid choice that's better than many alternatives.

Re: LastPass autofill exploit

#18
post #12

Please correct me if I am mistaken, but couldn't this have been implemented into an iframe that when ran could send the passwords to another remote server? If so, I am a little taken back by LastPass only offering $1,000 to the researcher that found and reported it for fixing. He or she could have taken a different path and resulted in this being used in some complex targeted attack against tech corporations via shor…

I was surprised by them giving such a tiny amount too. The potential damage to their users here is staggering. If this was used to grab someone's twitter,facebook,email,linkedin an attacker could take full control of their online presence :S

Re: LastPass autofill exploit

#19
post #13

I've been using LastPass for about 3 years, and now I'm seriously thinking about all the times people told me about how storing passwords in someone else's cloud is bad. I've been defending LastPass and recommending it to everyone till today. Now I'm thinking about how I might have to 'pay' for a software vulnerability in some private (read:unauditable by me) code. All the comments about offline, local backups make s…

I think you could do a lot worse than lastpass. You could also do better, by sacrificing some usability. On the extreme side, you could use a separate, offline device, just for password storage.

But I don't think it's worth getting excited about a single lastpass bug. Everything is vulnerable. There will be more of them. Chrome itself had 105 security issues, just this year (https://www.cvedetails.com/product/15031/Google-Chrome.html?...) - a few of them potentially leading to your passwords being exposed without any extensions.

Upgrade often, don't do stupid stuff, keep backups, and you'll be more secure than 99% of people. Evaluate your choices from there.

Re: LastPass autofill exploit

#20
post #13

I've been using LastPass for about 3 years, and now I'm seriously thinking about all the times people told me about how storing passwords in someone else's cloud is bad. I've been defending LastPass and recommending it to everyone till today. Now I'm thinking about how I might have to 'pay' for a software vulnerability in some private (read:unauditable by me) code. All the comments about offline, local backups make s…

I do not use LastPass exactly because of what you describe. I use a KeePass Password safe without autofill. I use other software to sync the file. It used to be Dropbox, later I was using BitTorrent Sync, but what tool sync shouldn't really matter. As I see it: the tool only gets to see and sync an encrypted file. You could even use a USB stick and not sync at all. Or only sync on LANs.

I love it how I get to decide who or what gets to see the encrypted file.

Now hopefully the Keepass audit will not reveal any issues in the encryption.

Post reply on HN