Live data from Hacker News

LastPass’ Authenticator app is not secure

medium.com

71–80 of 118 posts

Re: LastPass’ Authenticator app is not secure

#71
As it happens, I switched from Google Authenticator to LastPass Authenticator a few days ago. The app has a feature that allows you to require a PIN or fingerprint in order to use it. That feature is disabled by default. (Note that Google Authenticator has no such feature.) As I understand it, this attack allows someone with access to my unlocked phone to install a activity launcher app and then generate 2FA codes without supplying a PIN or fingerprint. Actually, for my phone they wouldn't need to bother with the launcher app, because I didn't enable the additional fingerprint/PIN feature--it seems to reduce convenience while adding little security.

Still, it's definitely a bug. They should either fix it or remove the feature so people aren't misled into thinking their two-factor codes are secure when they're not.

Re: LastPass’ Authenticator app is not secure

#72

LastPass produces two apps, the Password Manager and this Authenticator App, which looks like a 2FA competitor to Google Authenticator. The bug the article is detailing is in the Authenticator application, not the Password Manager application, which wasn't very clear to me on my first read.

Now I'm confused. It says it in the title? Where might the confusion stem from?

Most people will only use the password manager app. I didn't realise they make a different authenticator app and assumed that this was about the password manager.

Re: LastPass’ Authenticator app is not secure

#73

LastPass produces two apps, the Password Manager and this Authenticator App, which looks like a 2FA competitor to Google Authenticator. The bug the article is detailing is in the Authenticator application, not the Password Manager application, which wasn't very clear to me on my first read.

Now I'm confused. It says it in the title? Where might the confusion stem from?

If people don't know that LastPass has a 2FA app, they might think LastPass Authenticator is the password manager app, and is affected by this bug. As a matter of fact, a number of commenters seem to think exactly that.

Re: LastPass’ Authenticator app is not secure

#74

LastPass produces two apps, the Password Manager and this Authenticator App, which looks like a 2FA competitor to Google Authenticator. The bug the article is detailing is in the Authenticator application, not the Password Manager application, which wasn't very clear to me on my first read.

Now I'm confused. It says it in the title? Where might the confusion stem from?

It only says it in the title if you're already familiar with Lastpass's apps offerings.

I happen to be familiar so I can read "LastPass Authenticator app" and know it is referring to their 2F/Google Authenticator competitor. But in the general sense Lastpass "Authenticator" could be the name of their password manager for all people know.

It could be titled e.g. "Lastpass's two factor authenticator app is insecure." Still accurate but also less vague for people unfamiliar with Lastpass's different apps.

Re: LastPass’ Authenticator app is not secure

#75

Earlier quoted context omitted.

>Is having a bunch of passwords that you don't actually know all in one place more secure than having a smaller bunch of passwords that you do actually know that, still, can at most be leaked one at a time? It’s been repeatedly demonstrated that yes, it is.

>It's been repeatedly demonstrated Meaning you have consulted a sea of research that has compared the risk posed by password managers to keeping a mental catalogue of long, not-random-but-pretty-good character strings, using 2fa, and exercising proper security habits? I don't think you could ever come to an objective conclusion, since the 99%-user doesn't have a near-autistic obsession with security like most of us.

I don’t have an obsession with security, it’s just so easy and cheap that I don’t get why you wouldn’t do it (the people with an obsession with security probably don’t even trust 1Password to sync that encrypted file anyways)

My mom, who is as far removed from tech as you can get, understands why not sharing passwords might be a good idea when one can get hacked and set of a domino effect.

And your comparison is a straw man, the real comparison is trying to remember 50 random passwords to using a password manager because there is a sea of research showing that good passwords should be truly high entropy and random.

Using a password manager doesn’t stop you from using 2fa like your comparison is worded to imply.

Re: LastPass’ Authenticator app is not secure

#76
post #47
post #36

Earlier quoted context omitted.

Why? 1.) LastPass login page hashes MasterPassword on the login page to produce a hash 2.) Hash is sent to the forums, and is checked against the same hash as the vault system 3.) Hash is confirmed, and you're logged in. 1.) Later hash is grabbed by an attacker. 2.) Attacker sends the hash to get the encrypted vault 3.) Attacker gets the encrypted vault 4.) Attacker is sad, because they don't have the MasterPassword,…

1.) Find exploit in forum software/server. 2.) Modify login.php to send form username/password to attackers server.

Except there is no forum login page, just a SAML redirect to their SSO login.

Re: LastPass’ Authenticator app is not secure

#77

Earlier quoted context omitted.

The article whose "exploit" requires handing your unlocked phone to someone?

You'd be surprised how many people (not on HN) use extremely weak (or no) unlocking mechanisms for their devices. It overlaps with the set of folks who would want to use LastPass because of how easy it is.

Do you know what is easier than using last pass for people who use weak unlocking mechanisms? Using the same password everywhere.

I'd be surprised if there was any overlap at all where you claim.

Re: LastPass’ Authenticator app is not secure

#78
post #8

Earlier quoted context omitted.

I think it is mostly inertia and cross-platform support. Before they were acquired, they seemed to care a lot more about security, instead of just security theater. They also have some nice crypto features: For instance, I forgot my master password, and they have a one time password reset protocol that lets them send you an unlock code that only works on previously logged in devices. Also, it has rock-solid offsite b…

I certainly have worried about LastPass after their aquisitions, but have no concrete grievances, save the extension seems slower than it was previously. I like a number of features in LastPass. The auto fill, the auto password change feature, password sharing, etc.

I have a concrete grievance since acquisition...

They've started to dump crap into the Lastpass Vault. First it was adverts and then they modified the search bar to search the web rather than only your saved passwords/notes. Both attempts at gaining advertising/referral revenue and in my opinion at the cost of security.

I've disabled the idiotic search and was paying for Lastpass Premium before so don't see the ads but it is the principle that the company now places minor revenue over what I consider security which I cannot stand.

Plus I had issues with LogMeIn's business practices previously and moved to a competitor. Only to now have them follow me by buying Lastpass. I am in the early stages of looking at moving away from Lastpass (after four years).

Re: LastPass’ Authenticator app is not secure

#79

Earlier quoted context omitted.

That is a whole lot of opinion, but not much substance. What makes LastPass inferior to these other options?

> What makes LastPass inferior to these other options? Well, for one, the very first sentence of the article here.

The article that is literally not about Lastpass's password manager?

Lastpass Authenticator is not their password manager. It is a Google Authenticator competitor...

Re: LastPass’ Authenticator app is not secure

#80

Earlier quoted context omitted.

My biggest gripe/concern with LastPass Enterprise (we use it) is that sharing/access control _never_ works properly. Every time we bring someone on and try to share folders or credentials with them, we end up needing a multi-hour support ticket to get everything resolved correctly. This shouldn't happen. It raises big alarms for me.

Do they ask you to confirm your master password over the phone so they can check on their end and see if they can reproduce the issue?

[deleted]
Post reply on HN