Live data from Hacker News

LastPass autofill exploit

labs.detectify.com

431–440 of 443 posts

Re: LastPass autofill exploit

#431
post #321

Earlier quoted context omitted.

>You could make hundreds of thousands of US$ from exploiting this. And all you have to do is risk your freedom.

No, you can sell to the appropriate folks who will effectively launder the legal risk for you. Someone like Hacking Team.

That's disingenuous. It's still illegal for a citizen to do this.

Re: LastPass autofill exploit

#432
post #84
post #62

Earlier quoted context omitted.

They sold their future. The next bug will be sold to the highest bidder.

People find and disclose bugs regularly even where there isn't a bounty. Most (at least 99.99%) developers don't want to see a useful, successful product fail even if they can personally gain from it. The likelihood that an exploit for Lastpass will be discovered by an attacker and sold to a nefarious actor is very small. Further to that though, we now know that this problem is fixed in LastPass. We don't know about…

> Further to that though, we now know that this problem is fixed in LastPass. We don't know about other password managers.

Um...it was a really stupid mistake. Writing your own bug-prone regex here instead of using an existing, trustworthy function is just really bad. Especially when the consequences of a bug mean a hacker can steal someone's passwords.

You should really hope that any company that prides itself (and bases itself) on security would never release this bug. It absolutely lowers the reputation of lastpass.

Re: LastPass autofill exploit

#433
post #84

Earlier quoted context omitted.

People find and disclose bugs regularly even where there isn't a bounty. Most (at least 99.99%) developers don't want to see a useful, successful product fail even if they can personally gain from it. The likelihood that an exploit for Lastpass will be discovered by an attacker and sold to a nefarious actor is very small. Further to that though, we now know that this problem is fixed in LastPass. We don't know about…

To that end, LastPass is now a better option than it's rivals. Only when you believe that all password managers are equally secure from the start. There are many reasons to believe that this is not the case. Storing passwords in a cloud service is quite a red flag. Then there is a former employee stating on Twitter that part of the codebase is very neglected: https://twitter.com/ejcx_/status/758081553712820225

I never understood why security-conscious people would choose to use a service (e.g. Lastpass) that stores all of your passwords in the cloud. Why not just use KeePass instead? Yes, it's a little bit more hassle, but all of the other password managers have been subject to serious exploits like the OPs that put people's data at serious risk of compromise.

Re: LastPass autofill exploit

#434
post #430

Earlier quoted context omitted.

> - Lastpass is more trouble than it is worth in Safari/Mac. Can't agree with this more. I've had so many issues with LastPass staying logged in one browser across sessions, even though the preferences are set to logout after short inactivity windows and on browser quit. LastPass seemed to lose its preferences like this multiple times, and it made me uncomfortable from a security perspective to not know for sure when…

Another really cool trick it plays is that it enables Secure Input, as it should, but then never disables it. So it breaks 3rd party tools that expand shortcuts, automate UI actions, etc. like TextExpander, which I use a lot.

I've had this trouble in Chrome quite a bit too. For example, system level text expansions break in the Chrome omnibox. I think that's independent of LastPass, but I could be wrong.

Re: LastPass autofill exploit

#435
post #321

Earlier quoted context omitted.

No, you can sell to the appropriate folks who will effectively launder the legal risk for you. Someone like Hacking Team.

That's disingenuous. It's still illegal for a citizen to do this.

Selling it to sketchy vendors and doing "see no evil" appears to be perfectly legal. Unless you have some data otherwise?

Re: LastPass autofill exploit

#436
post #367

Earlier quoted context omitted.

> You downvoters can go fuck yourselves. Please don't do this on Hacker News.

I save downvotes for truly awful comments made in a blaming way. If a comment I've made is non-blaming, yet addresses the more uncomfortable bits of reality, I fully expect to be downvoted. In this case, within several minutes I was at -2, even when there was no "fuck yourselves" in the post. Interestingly enough, when I added it, there appeared to be more commenting occurring. While I would agree that this place wou…

Interesting view on the matter, even if I don't quite agree with your prev comment (too tired now to argue why, sorry).

I very much agree that downvoting without comment (indeed except for the truly awful ones that would just draw needless noise because of it) is an anti-pattern. But I am occasionally guilty of it myself as well, partly because writing a reply to a not-quite-awful comment costs me a lot of time (even if it's a short cmt).

The greying-out of downvoted comments doesn't help with the perception of receiving a downvote without comment either (makes it feel more harsh, IMO). I'd prefer showing the counts again, actually.

Re: LastPass autofill exploit

#437
post #430

Earlier quoted context omitted.

Another really cool trick it plays is that it enables Secure Input, as it should, but then never disables it. So it breaks 3rd party tools that expand shortcuts, automate UI actions, etc. like TextExpander, which I use a lot.

I've had this trouble in Chrome quite a bit too. For example, system level text expansions break in the Chrome omnibox. I think that's independent of LastPass, but I could be wrong.

I'm actually talking about sort of the reverse. Secure Input is a system-level thing; it disables input capture via the accessibility API (which things like TextExpander use), which effects everything on the machine. That is what you want; when typing a password, there is no good reason for other code to be reading what you (or LastPass) is typing. You just also want it to be turned back off when you're done.

But after the first use of the LastPass Safari extension, TextExpander (or KeyboardMaestro, or a bunch of other tools) won't work anywhere until a after reboot or some other method of disabling SI.

Re: LastPass autofill exploit

#438
post #318

$1000 for the bug bounty? This is incredibly stupid! How can you make a living off that? You could make hundreds of thousands of US$ from exploiting this. You could sell it on the black market. I am surprised that most of the corporations, even respectable ones, are awarding peanuts for something that is so important to their business process. This makes my blood boil. I operate a small business website and I awarded…

> You could make hundreds of thousands of US$ from exploiting this Oh no, not this type of comment again. Infosec people always make fun of HN for this exact type of comment. The total lack of understanding of the economics of bug hunting doesn't stop people from commenting here. Noone is paying $100k in some imaginary black market for web exploits. I mean have you even considered who buys exploits and what type of a…

Ok, you are right, it was naive for me to pull out this "black market" number from the ass, especially because I should know better, coming from Russia where there are many of these forums.

However, I still stand behind that this corporation should have paid $100,000. There are so many opportunities to exploit this vulnerability. LastPass is seen as something "advanced" users use, so it's highly probable that you could PM link to this page to some computer celebrity, and you would have access to his inbox in no-time, because most people don't use annoying second-factor authorization. This could result in a huge amount of new leaks, etc, etc. $1000 basically screams - "fuck you, we don't care about our security, and we are not going to encourage future white hat future bug reporting".

Re: LastPass autofill exploit

#439

Earlier quoted context omitted.

I save downvotes for truly awful comments made in a blaming way. If a comment I've made is non-blaming, yet addresses the more uncomfortable bits of reality, I fully expect to be downvoted. In this case, within several minutes I was at -2, even when there was no "fuck yourselves" in the post. Interestingly enough, when I added it, there appeared to be more commenting occurring. While I would agree that this place wou…

Interesting view on the matter, even if I don't quite agree with your prev comment (too tired now to argue why, sorry). I very much agree that downvoting without comment (indeed except for the truly awful ones that would just draw needless noise because of it) is an anti-pattern. But I am occasionally guilty of it myself as well, partly because writing a reply to a not-quite-awful comment costs me a lot of time (even…

It happens often enough that a comment gets downvoted initially, and then gets sympathy upvotes from people who don't find it bad enough to be voted down. It may help to wait a few more minutes.

Re: LastPass autofill exploit

#440
Given LastPass has pretty much one job to do, protect your passwords, I feel they should refund subscribers' money (a month or several months) everytime it's shown they haven't done their job. It's gotten to the point of being ridiculous how often I've come to HN and seen some new LastPass exploit. Once your password is compromised you could lose everything up till that point in time which was protected by that password. All your money in your bank account. All your photos in the cloud. The confidentiality of your IP. The secrecy of something in your personal life. In other words, it is accumulative. So really, if due to poor engineering on LastPass's behalf, if you loose it all at any point, you've really only been investing in a time bomb. You're making monthly investments in something growning more valuable each day until the day arrrives at which the value could drop to zero. Or worse, drop to zero and cost you. But LastPass seems to treat security issues as non-accumulative costs. Because for them, it isn't accumulative. They keep collecting subscription fees, adding new features, advertising to reach new customers, and maintaining a fundamentally broken product.
Post reply on HN