Earlier quoted context omitted.
I would say password reuse can be pretty good! Simply have your own rule such as "letters 2 and 5 of the domain name" and combine those with your reusable password. In fact, I'd go further and say that you can do this with your login name. So for example: myemail+by@gmail.com for eBaY This also helps mitigate those attacks where the attacker actually contacts support and socially engineers them into giving all your i…
This "clever" security measure would be annihilated in case of a well planned attack targeted against a single individual.
LastPass: design flaw in communication to privileged components
31–40 of 45 posts
Re: LastPass: design flaw in communication to privileged components
#32Earlier quoted context omitted.
Password managers exchange too many strong secrets to remember, for one strong secret you can remember. You just have to turn off any automatic / integration features. I do. Unlock with master password for every use. Really, how often is that, since most sites keep you logged in? Just a couple times a day for me.
Ugh, seriously? I think the vast majority of people wouldn't use a password manager if it were that difficult to use, especially on mobile where typing a truly secure password with different casing and special chars is a PITA. Getting a phone with a fingerprint scanner to unlock my password manager has been the mobile feature that has had the most valuable impact on me in the past couple years.
(Though I don't use much more than those, on my phone. I do have a laptop ...)
Re: LastPass: design flaw in communication to privileged components
#33Earlier quoted context omitted.
No, the two disclosures just happened to come at the same time.
Wow, a bad day for them. Two different awful bugs on the front page.
Might work out better for them than having one issue appear a week later.
Re: LastPass: design flaw in communication to privileged components
#34Agree with the comment that the blogger doesn't understand what phishing is. This could be done against a huge number of people through various approaches with ad network code or targeted attacks controlling path to internet. That's all setting aside how trivial it would be for nation states.
Re: LastPass: design flaw in communication to privileged components
#35Agree with the comment that the blogger doesn't understand what phishing is. This could be done against a huge number of people through various approaches with ad network code or targeted attacks controlling path to internet. That's all setting aside how trivial it would be for nation states.
I have not used LP in a long time but does not not prompt for the master password before filling?
Re: LastPass: design flaw in communication to privileged components
#36I use a Yubikey that's required when I log into a new PC (my home pc is set to only ask every 30 days for my 2FA key), I use an email that is only connected to Lastpass and I have a strong passphrase. Any other device I use Lastpass on is set to require a password and 2FA key at each start.
Is that enough to make me reasonably secure?
Re: LastPass: design flaw in communication to privileged components
#37So, I've been using Lastpass for a few years now and I probably rely on it too much. Every single login has a unique and strong password so it would be a pain to have to move away. I use a Yubikey that's required when I log into a new PC (my home pc is set to only ask every 30 days for my 2FA key), I use an email that is only connected to Lastpass and I have a strong passphrase. Any other device I use Lastpass on is…
This guy says that if the webpage "asks" for another's page credentials, lastpass plugin will give it. Every character/keystroke in specific fields could be catched/logged , here you have an example from ... eBay : https://news.ycombinator.com/item?id=12000820
Anyway, this was already fixed and pushed to the users, as the guy mentions in his post.
Re: LastPass: design flaw in communication to privileged components
#38So this post says > We have verified that intercepting messages via the method you suggested is possible and is a problem. We have also verified it only affects firefox (chrome, ie, safari, opera, etc do not use the window for message passing in the same manner) and doesn't affect our primary addons.mozilla.org firefox download (which is still 3.0 version). It seems latest version for windows is 4.1.20a? As I'm both…
> If you are running LastPass 3.0, you are not impacted and do not need to update.
As far as I know, 3.0 refers to their old interface. You can download the new version directly from their website, but not through the Firefox add-on site. The version history is available here [1].
Re: LastPass: design flaw in communication to privileged components
#39Agree with the comment that the blogger doesn't understand what phishing is. This could be done against a huge number of people through various approaches with ad network code or targeted attacks controlling path to internet. That's all setting aside how trivial it would be for nation states.
They have a history of trying to explain away their security problems as not really their fault. That alone should give any LastPass user pause.
Re: LastPass: design flaw in communication to privileged components
#40So, I've been using Lastpass for a few years now and I probably rely on it too much. Every single login has a unique and strong password so it would be a pain to have to move away. I use a Yubikey that's required when I log into a new PC (my home pc is set to only ask every 30 days for my 2FA key), I use an email that is only connected to Lastpass and I have a strong passphrase. Any other device I use Lastpass on is…
The LastPass exploits presented exist after you have unlocked your vault, so 2fa on the LastPass vault won't stop them.
Personally, I'm not moving away from LastPass over these.