Live data from Hacker News

LastPass autofill exploit

labs.detectify.com

421–430 of 443 posts

Re: LastPass autofill exploit

#421

Earlier quoted context omitted.

I did speak rather harshly in my prior comment, and for that I apologize. Worse, I did a very poor job of expressing the concern that motivated me to respond. But I think it's still fair to ask whether your initial comment has value. I understand that, as a user of 1Password's browser extension(s), you may well feel some concern that a similar vulnerability exists, and I don't think it's unreasonable to want reassura…

I understand a concern with my phrasing -- to be honest, I didn't put much thought into it as far as considering multiple interpretations. I have sent a message to 1Password through the official customer support channel to ask the same question posed here. I'll update once they reply.

Update: Here's the response from earlier this morning:

> Thank you for taking the time to write to us here at AgileBits. The current version of the 1Password extension does not use regex to parse URLs for this exact reason. We don't autofill either, which also helps avoid issues like the one you mentioned.

Re: LastPass autofill exploit

#422
post #249

Earlier quoted context omitted.

No, that is not at all what a bug bounty is meant to do. We are not expected to pay people to avoid them launching criminal conspiracies against us. The purpose of a bug bounty is to incentivize researchers to target specific pieces of software so that vendors can benefit from that attention.

Let's assume that there is a spectrum of honesty (say, from 1-10) and the pool of people capable of discovering vulnerabilities in your product includes people from the entire range. If you're a 10 you will disclose responsibly regardless of a bounty, and if you're a 1 you will disclose to the highest bidder. The rest will weight profit, ethics, and risk in some ratio depending on where they fall on the scale and dec…

The point is to get more tens to even look at the code, not encourage people that have already found vulnerabilities to share them. I also think you vastly overestimate the percentage of criminals.

Re: LastPass autofill exploit

#423
post #420
post #387

Earlier quoted context omitted.

I appreciate the honest response. I couldn't find an easy link on mobile to explain what those Pro features were and it sounds like I don't need them after all. I just need to be able to share a database of passwords between my few devices for personal use. Purchasing 1Password for 65$ gets the current major release with no updates? Subscribing to 1Password Families for 5$/month: Lets me sync passwords between all of…

Sorry for the delay in response here. I eventually had to go do some of my regular duties and that meant closing the web browser at some point yesterday :) $65 gets you a single license for Mac and Windows. This can be installed on multiple Macs or PCs you own, but is generally for 1 single person. You get all updates to 1Password 6 for Mac for free, and any updates to 1Password 4 for Windows for free. On the Mac sid…

Thanks for the informative response! I may try out the subscription.

Re: LastPass autofill exploit

#424
post #418
post #264

Earlier quoted context omitted.

Disclaimer: I also work for AgileBits We really try not to call it "Classic" or anything like that. It's standalone, you're in charge of upgrades, syncing and backups and stuff like that. It's also not designed for sharing (at least to the degree of the Family and Team solutions). That said, we don't have any immediate plans to remove the standalone products. However, if a vast majority of our users switch to 1Passwo…

I'm probably being daft but I can't find the Individual Plan on 1Passwords homepage, any idea where I can find out more about it?

Sorry about that, we haven't officially announced it but it is available when you start the sign up process.

https://start.1password.com

It is $2.99/mo when billed annual ($3.99/mo month to month), includes all of the applications as part of the subscription price.

It is otherwise based on the same technology as Family and Teams options. It's basically Families with only 1 user.

Re: LastPass autofill exploit

#425

Earlier quoted context omitted.

Here's some context: I am a former LastPass user for many years and current (concerned) 1Password user wondering if I should be changing all of my passwords again. My goal was to settle concern for myself and other 1Password users. That's why I wrote whether a similar vulnerability "does not affect 1Password" instead of "does". My apologies if this was unclear.

Why did you switch from LastPass to 1Password? I recently started using LastPass after years of reusing the same uncrackable password: !p@ssword123

Two things - 1Password has a smoother experience on iOS, and I prefer the one time purchase model vs LastPass is only available as a subscription.

(Without a paid subscription, bookmarklets on mobile still work for free of course. But I found that login flow so cumbersome.)

Re: LastPass autofill exploit

#426
post #4

It looks like there's more interesting stuff coming in soon: https://twitter.com/taviso/status/758074702589853696 (to save a click: Tavis Ormandy: "Are people really using this lastpass thing? I took a quick look and can see a bunch of obvious critical problems. I'll send a report asap.")

https://bugs.chromium.org/p/project-zero/issues/detail?id=88...

Re: LastPass autofill exploit

#427
post #368

Earlier quoted context omitted.

Why did you switch from LastPass to 1Password? I recently started using LastPass after years of reusing the same uncrackable password: !p@ssword123

You didn't ask me, but, several things: - This is the second serious security incident with them. Nobody's immune to bugs, but I haven't seen a similar history with AgileBits. - LastPass has, IMHO, terrible UI/UX. Things don't work consistently, there are weird, unexpected pauses that look like malfunctions until something visible happens; it took me a comparatively long time to figure out how to map common actions t…

> - Lastpass is more trouble than it is worth in Safari/Mac.

Can't agree with this more. I've had so many issues with LastPass staying logged in one browser across sessions, even though the preferences are set to logout after short inactivity windows and on browser quit. LastPass seemed to lose its preferences like this multiple times, and it made me uncomfortable from a security perspective to not know for sure when my sessions would actually end.

Besides that it's mostly UX issues for me, similar to what you've described.

I also prefer 1Password's pronounceable random password generator vs LastPass's generator (obligatory xkcd https://xkcd.com/936/).

Re: LastPass autofill exploit

#428

Earlier quoted context omitted.

Why did you switch from LastPass to 1Password? I recently started using LastPass after years of reusing the same uncrackable password: !p@ssword123

I've been using LastPass for years now, but I'm starting to explore other options. For me, the biggest pain point is the interface. The automatic form filling rarely works as it should; I click the LastPass icon in the username field, select the site, and it only populates the username (even though there is an input with type="password" right below it). I then have to: 1) Press ALT+W to bring up the LastPass site sea…

> And then I have to worry about what password I may or may not have lingering in my clipboard.

I'm not sure how LastPass does it, but 1Password does clear the clipboard after a short period of time (configurable, I think 90 seconds by default). I use clipboard logging via Alfred, and can confirm that however they clear the clipboard works to keep them out of its log.

Re: LastPass autofill exploit

#429
post #367

Earlier quoted context omitted.

What you are really "asking" is logically equivalent to this blaming statement: "I see you are posting about LastPass' vulnerability, but you work for 1Password. Please confirm there exists a regex vulnerability in 1Password which is similar in nature to the one that occurred with LastPass." Put this way, the insanity of the statement is obvious. In questions, it becomes less obvious to the majority of the population…

> You downvoters can go fuck yourselves. Please don't do this on Hacker News.

I save downvotes for truly awful comments made in a blaming way. If a comment I've made is non-blaming, yet addresses the more uncomfortable bits of reality, I fully expect to be downvoted. In this case, within several minutes I was at -2, even when there was no "fuck yourselves" in the post. Interestingly enough, when I added it, there appeared to be more commenting occurring.

While I would agree that this place would be better off without judgment, and harsh judgment as I've shown here, the reality is that we all share this place equally with others who do not stop and consider their actions as affecting others thought processes in a negative way. I put this on here to illustrate that point in a non-obvious way, and in a way people CAN understand: anger. It's not the only way of course, but it does get the bug into people's brains quite well.

I appreciate your comment and intent behind it.

Re: LastPass autofill exploit

#430
post #368

Earlier quoted context omitted.

You didn't ask me, but, several things: - This is the second serious security incident with them. Nobody's immune to bugs, but I haven't seen a similar history with AgileBits. - LastPass has, IMHO, terrible UI/UX. Things don't work consistently, there are weird, unexpected pauses that look like malfunctions until something visible happens; it took me a comparatively long time to figure out how to map common actions t…

> - Lastpass is more trouble than it is worth in Safari/Mac. Can't agree with this more. I've had so many issues with LastPass staying logged in one browser across sessions, even though the preferences are set to logout after short inactivity windows and on browser quit. LastPass seemed to lose its preferences like this multiple times, and it made me uncomfortable from a security perspective to not know for sure when…

Another really cool trick it plays is that it enables Secure Input, as it should, but then never disables it. So it breaks 3rd party tools that expand shortcuts, automate UI actions, etc. like TextExpander, which I use a lot.
Post reply on HN