Live data from Hacker News

LastPass Now Checks If Your Sites Are Affected by Heartbleed

blog.lastpass.com

91–94 of 94 posts

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#91

Earlier quoted context omitted.

[Citation needed]

Computer Misuse Act 1990, section 1.1. The test for the vulnerability requires running the exploit, whose only function is to secure unauthorised access to data held on the remote machine. Seems fairly clear-cut to me.

http://www.legislation.gov.uk/ukpga/1990/18

I think you're wrong:

Unauthorised access to computer material.

(1)A person is guilty of an offence if— (a)he causes a computer to perform any function with intent to secure access to any program or data held in any computer [F1, or to enable any such access to be secured]F1 ; (b)the access he intends to secure [F2, or to enable to be secured,]F2 is unauthorised; and

Lastpass is not trying to secure the web wervers with the check

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#93
post #83

Earlier quoted context omitted.

Why was this downvoted? Seems like sound advice not to drop the keys to your kingdom into a black box run by a business...

Because it's typical free-software-uber-alles posturing lacking logic. Besides, it lacks applicability in this case. LP encrypts all your stuff client side before sending it along for storage, and the browser plugins that handle this are open source by way of being browser plugins. Whatever happens server side after that is mostly irrelevant.

Thanks for clarifying. I wasn't aware that LastPass encrypts your stuff client-side with auditable code, that does change things.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#94
post #54

Earlier quoted context omitted.

I believe if you use a new private key but sign the same CSR the dates will not change. Ideally the old certs should be revoked which should provide some info on this. I saw this explanation on the discussion of the herokuapp.com's cert's dates not changing.

This is entirely up to the issuing CA's process. Thawte, for example, happily revokes-and-reissues certificates for free (perhaps only for "enterprise" customers?), and the newly issued certificate has the same end-validity date as the revoked certificate but the start-validity date is set to the time of issue. I notice herokuapp.com's CA is DigiCert, so perhaps they have the opposite policy, of giving the reissued c…

I think this explains what we've seen best.
Post reply on HN