Earlier quoted context omitted.
>You could make hundreds of thousands of US$ from exploiting this. And all you have to do is risk your freedom.
No, you can sell to the appropriate folks who will effectively launder the legal risk for you. Someone like Hacking Team.
LastPass autofill exploit
431–440 of 443 posts
Re: LastPass autofill exploit
#432Earlier quoted context omitted.
They sold their future. The next bug will be sold to the highest bidder.
People find and disclose bugs regularly even where there isn't a bounty. Most (at least 99.99%) developers don't want to see a useful, successful product fail even if they can personally gain from it. The likelihood that an exploit for Lastpass will be discovered by an attacker and sold to a nefarious actor is very small. Further to that though, we now know that this problem is fixed in LastPass. We don't know about…
Um...it was a really stupid mistake. Writing your own bug-prone regex here instead of using an existing, trustworthy function is just really bad. Especially when the consequences of a bug mean a hacker can steal someone's passwords.
You should really hope that any company that prides itself (and bases itself) on security would never release this bug. It absolutely lowers the reputation of lastpass.
Re: LastPass autofill exploit
#433Earlier quoted context omitted.
People find and disclose bugs regularly even where there isn't a bounty. Most (at least 99.99%) developers don't want to see a useful, successful product fail even if they can personally gain from it. The likelihood that an exploit for Lastpass will be discovered by an attacker and sold to a nefarious actor is very small. Further to that though, we now know that this problem is fixed in LastPass. We don't know about…
To that end, LastPass is now a better option than it's rivals. Only when you believe that all password managers are equally secure from the start. There are many reasons to believe that this is not the case. Storing passwords in a cloud service is quite a red flag. Then there is a former employee stating on Twitter that part of the codebase is very neglected: https://twitter.com/ejcx_/status/758081553712820225
Re: LastPass autofill exploit
#434Earlier quoted context omitted.
> - Lastpass is more trouble than it is worth in Safari/Mac. Can't agree with this more. I've had so many issues with LastPass staying logged in one browser across sessions, even though the preferences are set to logout after short inactivity windows and on browser quit. LastPass seemed to lose its preferences like this multiple times, and it made me uncomfortable from a security perspective to not know for sure when…
Another really cool trick it plays is that it enables Secure Input, as it should, but then never disables it. So it breaks 3rd party tools that expand shortcuts, automate UI actions, etc. like TextExpander, which I use a lot.
Re: LastPass autofill exploit
#435Earlier quoted context omitted.
No, you can sell to the appropriate folks who will effectively launder the legal risk for you. Someone like Hacking Team.
That's disingenuous. It's still illegal for a citizen to do this.
Re: LastPass autofill exploit
#436Earlier quoted context omitted.
> You downvoters can go fuck yourselves. Please don't do this on Hacker News.
I save downvotes for truly awful comments made in a blaming way. If a comment I've made is non-blaming, yet addresses the more uncomfortable bits of reality, I fully expect to be downvoted. In this case, within several minutes I was at -2, even when there was no "fuck yourselves" in the post. Interestingly enough, when I added it, there appeared to be more commenting occurring. While I would agree that this place wou…
I very much agree that downvoting without comment (indeed except for the truly awful ones that would just draw needless noise because of it) is an anti-pattern. But I am occasionally guilty of it myself as well, partly because writing a reply to a not-quite-awful comment costs me a lot of time (even if it's a short cmt).
The greying-out of downvoted comments doesn't help with the perception of receiving a downvote without comment either (makes it feel more harsh, IMO). I'd prefer showing the counts again, actually.
Re: LastPass autofill exploit
#437Earlier quoted context omitted.
Another really cool trick it plays is that it enables Secure Input, as it should, but then never disables it. So it breaks 3rd party tools that expand shortcuts, automate UI actions, etc. like TextExpander, which I use a lot.
I've had this trouble in Chrome quite a bit too. For example, system level text expansions break in the Chrome omnibox. I think that's independent of LastPass, but I could be wrong.
But after the first use of the LastPass Safari extension, TextExpander (or KeyboardMaestro, or a bunch of other tools) won't work anywhere until a after reboot or some other method of disabling SI.
Re: LastPass autofill exploit
#438$1000 for the bug bounty? This is incredibly stupid! How can you make a living off that? You could make hundreds of thousands of US$ from exploiting this. You could sell it on the black market. I am surprised that most of the corporations, even respectable ones, are awarding peanuts for something that is so important to their business process. This makes my blood boil. I operate a small business website and I awarded…
> You could make hundreds of thousands of US$ from exploiting this Oh no, not this type of comment again. Infosec people always make fun of HN for this exact type of comment. The total lack of understanding of the economics of bug hunting doesn't stop people from commenting here. Noone is paying $100k in some imaginary black market for web exploits. I mean have you even considered who buys exploits and what type of a…
However, I still stand behind that this corporation should have paid $100,000. There are so many opportunities to exploit this vulnerability. LastPass is seen as something "advanced" users use, so it's highly probable that you could PM link to this page to some computer celebrity, and you would have access to his inbox in no-time, because most people don't use annoying second-factor authorization. This could result in a huge amount of new leaks, etc, etc. $1000 basically screams - "fuck you, we don't care about our security, and we are not going to encourage future white hat future bug reporting".
Re: LastPass autofill exploit
#439Earlier quoted context omitted.
I save downvotes for truly awful comments made in a blaming way. If a comment I've made is non-blaming, yet addresses the more uncomfortable bits of reality, I fully expect to be downvoted. In this case, within several minutes I was at -2, even when there was no "fuck yourselves" in the post. Interestingly enough, when I added it, there appeared to be more commenting occurring. While I would agree that this place wou…
Interesting view on the matter, even if I don't quite agree with your prev comment (too tired now to argue why, sorry). I very much agree that downvoting without comment (indeed except for the truly awful ones that would just draw needless noise because of it) is an anti-pattern. But I am occasionally guilty of it myself as well, partly because writing a reply to a not-quite-awful comment costs me a lot of time (even…