Live data from Hacker News

LastPass autofill exploit

labs.detectify.com

341–350 of 443 posts

Re: LastPass autofill exploit

#341
post #206
post #201

Earlier quoted context omitted.

How easy is it to migrate from Laspass to 1Password? I've had the worst experience with their tech support (reported 2 bugs that have both been scrapped as WONT FIX) and really don't want to support them as a premium subscriber anymore.

Disclosure: I also work for AgileBits :) We have a dedicated LastPass import option. See here: https://support.1password.com/import-lastpass/ If you encounter any trouble please write into support at agilebits dot com and mention "Kyle" somewhere in the body of the email and I'll get notified. You should be fine though, but every once in awhile we have someone encounter trouble with the import from LastPass.

Thanks!

I checked out the pricing model and didn't see anything that made sense to me as an individual user. Is there any plan for an affordable individual plan (in the range of 10-20$/ year)?

As a Mac/IOS user, I don't see myself shelling out 60$ for a desktop license and then another 10$ for an IOS license on top of it. I'm sure your profit margin is great, don't get me wrong, but as a buyer that is just overkill.

Re: LastPass autofill exploit

#342

Earlier quoted context omitted.

Here's some context: I am a former LastPass user for many years and current (concerned) 1Password user wondering if I should be changing all of my passwords again. My goal was to settle concern for myself and other 1Password users. That's why I wrote whether a similar vulnerability "does not affect 1Password" instead of "does". My apologies if this was unclear.

Why did you switch from LastPass to 1Password? I recently started using LastPass after years of reusing the same uncrackable password: !p@ssword123

I've been using LastPass for years now, but I'm starting to explore other options.

For me, the biggest pain point is the interface. The automatic form filling rarely works as it should; I click the LastPass icon in the username field, select the site, and it only populates the username (even though there is an input with type="password" right below it).

I then have to: 1) Press ALT+W to bring up the LastPass site search 2) Type in the domain name 3) Find the correct entry, and then click "Show Password" 4) Use my mouse to highlight the password and copy it (there is no quick way to copy the password) 5) Close the tab, go back to the original site, put my cursor in the password field and paste it

And then I have to worry about what password I may or may not have lingering in my clipboard.

If anyone has a better workflow please let me know. I'm envious when I watch coworkers use 1Password to populate a form in two steps using hotkeys.

Re: LastPass autofill exploit

#343

>They are still much better than the alternative (password reuse). I'm not sure if it is, bugs like that are a serious threat. Personally I use the same (long) password for every website, except one of the characters which I replace by the website's first letter. One could think of similar, more sophisticated schemes of password reuse that yield a slightly different password for each website. It would be even better…

Your "algorithm" is far less secure than using unique secure passwords through a PW manager. If someone got access to 2 (maybe 1) of your passwords, they would have all your passwords.

I can see that if the same attacker managed to get access to two of my passwords and was particularly interested in me, but how likely is that compared to an exploit on a password manager? Besides, I change all my passwords twice a year.

Re: LastPass autofill exploit

#344
post #264
post #202

Earlier quoted context omitted.

When you are here, is 1password for team is the future and the classic 1password will become obsolete soon?

Disclaimer: I also work for AgileBits We really try not to call it "Classic" or anything like that. It's standalone, you're in charge of upgrades, syncing and backups and stuff like that. It's also not designed for sharing (at least to the degree of the Family and Team solutions). That said, we don't have any immediate plans to remove the standalone products. However, if a vast majority of our users switch to 1Passwo…

Please do consider keeping the standalone apps. Not having my passwords stored on someone else's server (encrypted or not) is why I'm a 1Password user (and likely buying an upgrade license this month to load it on my other windows box). Similarly why I've bought and upgraded Arq to store backups on storage I control.

Re: LastPass autofill exploit

#345

Earlier quoted context omitted.

If you're using a *nix system: https://www.passwordstore.org/ I switched over from LastPass a few months ago. It uses gpg for encryption and supports git for password syncing between systems. Pretty simple to set up and use. There are quite a few third party apps for it already (both desktop and mobile)

I've been amazed by Pass, but couldn't find a thorough review between Pass and KeePass(x). Is one safer than the other?

One big difference: pass only encrypts the password. All metadata is plaintext, so anyone can see a full listing of what online accounts you have.

Re: LastPass autofill exploit

#346
post #318

$1000 for the bug bounty? This is incredibly stupid! How can you make a living off that? You could make hundreds of thousands of US$ from exploiting this. You could sell it on the black market. I am surprised that most of the corporations, even respectable ones, are awarding peanuts for something that is so important to their business process. This makes my blood boil. I operate a small business website and I awarded…

> You could make hundreds of thousands of US$ from exploiting this Oh no, not this type of comment again. Infosec people always make fun of HN for this exact type of comment. The total lack of understanding of the economics of bug hunting doesn't stop people from commenting here. Noone is paying $100k in some imaginary black market for web exploits. I mean have you even considered who buys exploits and what type of a…

>Noone is paying $100k in some imaginary black market for web exploits.

You're right, it's usually in low-mid $10ks for this sort of thing.

>low-grade consumer password manager that no enterprise or governments uses

Can't speak to government, but multiple large companies I have worked for have mandated LastPass as the password manager.

> But even then your grey market for this is tiny and most likely not going to be some criminal overlord paying out $100k in bitcoin to kids on a darknet forum.

In fact that's almost exactly what it is, except you've underestimated the price. A really juicy iOS RCE or Privesc can fetch almost half a million.

These transactions aren't usually done on forums, though. Not enough trust. There are middlemen who buy exploits from researchers and sell to the big customers.

Re: LastPass autofill exploit

#347
post #341
post #206

Earlier quoted context omitted.

Disclosure: I also work for AgileBits :) We have a dedicated LastPass import option. See here: https://support.1password.com/import-lastpass/ If you encounter any trouble please write into support at agilebits dot com and mention "Kyle" somewhere in the body of the email and I'll get notified. You should be fine though, but every once in awhile we have someone encounter trouble with the import from LastPass.

Thanks! I checked out the pricing model and didn't see anything that made sense to me as an individual user. Is there any plan for an affordable individual plan (in the range of 10-20$/ year)? As a Mac/IOS user, I don't see myself shelling out 60$ for a desktop license and then another 10$ for an IOS license on top of it. I'm sure your profit margin is great, don't get me wrong, but as a buyer that is just overkill.

The individual plan is the lowest cost subscription option, and standalone is an option if you would like to try to spread the cost out between releases, but you would have to pay for any major upgrades as those are not included.

I'd say many people don't need the Pro features in the iOS version, it's possible that maybe you won't either? Depends on how you use it I guess. Probably the biggest reason to get the Pro features is multiple vault support (you can add additional vaults that were created from the desktop versions). With the free version you only get the one vault.

If you use the app like most people, you'll be using it dozens of times a day. Even if it's in small interactions those do add up. I've been trying to convince the team to add some sort of individual statistics that were stored locally for users to see, but I suspect this would probably help you decide that regardless of price it would be worth while :)

In the end, the choice is yours though. We certainly want to hit the price point for all users that we can, but we do have to keep the lights on or the product disappears. We aren't priced at a point where we're trying to acquire users in bulk so we can sell to another company. AgileBits is privately owned and has never taken outside funding. Something to be aware of when you're talking pricing I suppose. At least one factor.

Kyle

AgileBits

Re: LastPass autofill exploit

#348
post #331

Earlier quoted context omitted.

Long time 1Password user here. I use it on bunch of Machines and I wish you guys supported Linux. :( Heck 1Password mostly works under Wine, except perhaps there is no unlock on Secure desktop and bunch of other usability things.

Coincidentally, a bunch of Dropboxers are working on a version of 1Password for Linux written in Rust (it's Dropbox's "Hack Week" right now). Hopefully we can open source it soon. Looking good so far!

Hi there!

If you have any questions that we might be able to answer, please shoot me an email. kyle at agilebits.com, or support at agilebits.com. I work on our Mac/iOS teams and security teams. I can probably answer most of your questions and at least get them in front of people who can answer them.

I really hope you're not making this work with AgileKeychain, we've put that one out to pasture. :)

Kyle

AgileBits

Re: LastPass autofill exploit

#349
post #15

Earlier quoted context omitted.

Where do you write yours down?

I memorised a very simple algorithm to construct passwords from the domain name of a site. Then I concatenate that with one of three fixed portions depending on how important I view the site (e.g. banks get the most secure one, then gmail, then everything else). It works pretty well. Different password for each site, I only have to remember a few things, and it would take several compromises (and a weirdly dedicated…

> it would take several compromises (and a weirdly dedicated attacker) to work out my algorithm.

Use that algorithm widely enough and several compromises are guaranteed. The only thing protecting your password is that url manipulation.

Post reply on HN