Live data from Hacker News

LastPass autofill exploit

labs.detectify.com

381–390 of 443 posts

Re: LastPass autofill exploit

#381
post #300
post #283

Earlier quoted context omitted.

While content scripts (in the extension world, meaning scripts running in the context of a content page) shares the DOM with the untrusted page, it does not share the JavaScript wrapper layer around that DOM. This is extra confusing because the global object is a (JavaScript wrapper around a) DOM object. The untrusted script can override its own view of createElement, but not the extension's view.

Very interesting if true. I'm tempted to build an extension just to check that. I wonder if a DOM mutation event would be triggered if a content script adds a new link element and changes it's href. Would I be able to catch that and quickly change the href, before the content script continues to fecth the processed properties?

I don't know about this specific point, but you might want to take a look at the greasemonkey security pitfalls page [0]. There's been a lot of effort put into how all of these parts work together to make sure that malicious Javascript on the page can't interfere with what the plugin or userscript is trying to do.

[0] http://archive.oreilly.com/pub/a/network/2005/11/01/avoid-co...

Re: LastPass autofill exploit

#382

Earlier quoted context omitted.

I've been using Pass for several months and I love it. https://www.passwordstore.org/

Within Pass is there a best practice for sharing passwords with another person or team?

I don't know about best practise but it integrates closely with Git. I store the encrypted passwords in a remote git repository. That means if someone else had the same GPG key and the password for that key, they could simply clone the repo and obtain the passwords. Equally they could add passwords and push them to the repo.

So that seems like a reasonable way for people to share them. However, I only use it for myself so I may not have thought of all the gotchas.

Re: LastPass autofill exploit

#383
post #374
post #353

Earlier quoted context omitted.

We don't generally do feature comparisons. So many products operate under different sets of requirements that comparison charts can be very easily rigged to make one thing look significantly better than the other. I can tell you one thing that is indisputably better about 1Password though. Support. Quite literally. We have a team of over 30 customer support personnel (in addition to myself and other developers who pi…

Out of the year I have been using Keepass I have never had a time where something was wrong that I would need support for. I am actually not sure what I would need support for either, it seems pretty basic. I am simply storing passwords. It doesn't seem too complicated. And maybe this is because I am a tech person, so maybe I am looking for the more technical reasons why the software may be better rather than how the…

An example I like to give for why 1Password Families has helped me is this:

I work remotely for my job. I do travel several times a year as a result and when I'm gone I have other family members watch my house. Before 1Password Families I had to find a way to easily get my wifi password, my garage door code, and various other instructions and information to whoever was watching my house.

With 1Password Families I simply create a vault in my Family, add my items to it and invite the person who will be watching my house as a guest (or in my most recent case, granted my brother access to the vault).

In the first case, the person simply signed up, installed 1Password and they had access to the data. In the second case, my brother simply unlocked 1Password and the vault was there.

When I get back home, I simply remove access and those things disappear from their devices. None of these are so important that I have to change them, but, that's another step as well if necessary.

But that is how easy it is to share and use vaults in 1Password Families (and Teams).

I also love that using this I can add family members, like my parents, and it handles all the syncing for them so I don't have to micro manage it with backups and other stuff. It's a far more seamless experience. And since I hold the keys to the family kingdom, I can also reset their master password for them if they forget it.

Now, you might think you have no use for this, and that's fine, but it's an example of how someone who doesn't have an immediate family (I'm single, and childless) was able to use 1Password Families in a way that wasn't obvious when I first set out to use it for myself.

In terms of features that differentiate us from Keepass, I have never used Keepass so I am not able to speak to what we do differently. I'm sure there are things each of us do better though.

There is a trial version of 1Password, so, you could use it and see how it stacks up for yourself. I'd be very curious what you find better or worse so I can pass that feedback along to our team. Completely optional of course.

Kyle

AgileBits

Re: LastPass autofill exploit

#384
post #324

Earlier quoted context omitted.

Someone always makes a comment like this. Honestly, the black market value (if any) has nothing to do with the whitehat bounty amount. Why should it? The person who's going to do legitimate whitehat work isn't the same person who's going to sell on the black market. I think of it like drugs. $50k street value of cocaine is not going to do me a lot of good because 1) I'd have no idea where to sell it, 2) if I did know…

I think the point is 1) it encourages more people to go the black hat way and 2) $1000 just isn't worth all the time people spend not finding bugs before finding one. So no one is encouraged to look in the first place except maybe the few who find it fun to do in their free time. Side-note: isn't there a grey market that buys exploits (for sums of ~$100k depending on the exploit) and sells them to government agencies…

"I think the point is 1) it encourages more people to go the black hat way".

How many times have people had to pay you not to commit felonies that are a) immoral, and b) could land you in jail?

I think most people don't need monetary encouragement not to turn black hat.

Re: LastPass autofill exploit

#386
post #72
post #69

Earlier quoted context omitted.

Normally I like bike shedding about bug bounty payouts just about as much as complaints about paywalls. If you are going to go poking around someone's code for fun or profit, the terms of the bounty program are readily available [1] so you can't complain after the fact for earning the maximum payout. LastPass isn't Facebook, and they never claimed they would pay more than $1,000 even for a full compromise or RCE. On…

The concern with the low payout is that it's supposed to be a way to compensate white hat hackers and dissuaded them from going to the black market with security problems like this. Given the business that LastPass is in wouldn't you agree that it's extremely crucial they make sure white hat hackers are aptly compensated for serious problems they find? In fact I'd think it'd be reasonable for them to pay more than Fa…

I mostly agree, but I would say that if the amount of a bounty affects your decision on whether to responsibly disclose it or sell to the highest black-market bidder, then you are at the very least a grey hat.

Re: LastPass autofill exploit

#387
post #347
post #341

Earlier quoted context omitted.

Thanks! I checked out the pricing model and didn't see anything that made sense to me as an individual user. Is there any plan for an affordable individual plan (in the range of 10-20$/ year)? As a Mac/IOS user, I don't see myself shelling out 60$ for a desktop license and then another 10$ for an IOS license on top of it. I'm sure your profit margin is great, don't get me wrong, but as a buyer that is just overkill.

The individual plan is the lowest cost subscription option, and standalone is an option if you would like to try to spread the cost out between releases, but you would have to pay for any major upgrades as those are not included. I'd say many people don't need the Pro features in the iOS version, it's possible that maybe you won't either? Depends on how you use it I guess. Probably the biggest reason to get the Pro f…

I appreciate the honest response. I couldn't find an easy link on mobile to explain what those Pro features were and it sounds like I don't need them after all. I just need to be able to share a database of passwords between my few devices for personal use.

Purchasing 1Password for 65$ gets the current major release with no updates?

Subscribing to 1Password Families for 5$/month: Lets me sync passwords between all of my desktops and phones? Can I sync an encrypted password database or is this done as a hosted cloud solution by 1Password?

Re: LastPass autofill exploit

#388
post #12

Please correct me if I am mistaken, but couldn't this have been implemented into an iframe that when ran could send the passwords to another remote server? If so, I am a little taken back by LastPass only offering $1,000 to the researcher that found and reported it for fixing. He or she could have taken a different path and resulted in this being used in some complex targeted attack against tech corporations via shor…

Let's do a little calculation to see if the payout is worthwhile. Using something illegally means you run the risk of going to prison. Let's say there's a 1% chance you get caught, the prison sentence is 10 years, and the evil hackers will pay you $20,000 for your bug. Let's also say that you're a mid-career software engineer in the US, and over the next 10 years you expect to make $2M (after taxes). This means your…

You are approaching from the wrong angle. How much was the exploit "worth" to the company?

Some people want to watch the burn. An attacker could make it known anonymously and LastPass will never recover from that onslaught.

Re: LastPass autofill exploit

#390

Earlier quoted context omitted.

Are you saying that you remember a unique and sufficiently random password for every website/app/etc you use? If so, you've got a far better memory that me.

Not the GP, but yes, and it doesn't require a good memory. The main things I do: 1. "Salt" my email usernames with the name of the service (johndoe+reddit@example.com) 2. Use multiple (long) password bases depending on the type of service (eg website vs app) 3. Combine the password bases with a cipher/salt based on the service name and my username I'm guilty of not rotating passwords on a regular basis, however.

So do you use encryption on that combined version? If yes, how do you deal with different requirements (one website says symbols required and more than 8 characters, another says symbols forbidden and less than 8 characters). If no, what stops someone who finds one password from changing the service name part and trying it somewhere else?
Post reply on HN