LastPass: design flaw in communication to privileged components
bugs.chromium.org
LastPass: design flaw in communication to privileged components
1–10 of 45 posts
Re: LastPass: design flaw in communication to privileged components
#2Re: LastPass: design flaw in communication to privileged components
#3Agree with the comment that the blogger doesn't understand what phishing is. This could be done against a huge number of people through various approaches with ad network code or targeted attacks controlling path to internet. That's all setting aside how trivial it would be for nation states.
Re: LastPass: design flaw in communication to privileged components
#4Agree with the comment that the blogger doesn't understand what phishing is. This could be done against a huge number of people through various approaches with ad network code or targeted attacks controlling path to internet. That's all setting aside how trivial it would be for nation states.
The phrasing was "both exploits do require tricking a user via a phishing attack into going to a malicious website".
This suggests that the blogger believes that the only attack vector involves tricking the user to go to a malicious website; I can reasonably see calling such attacks phishing attacks.
The problem (which is, in my opinion, more serious) is that, as you identify, the blogger seems to horribly misunderstand the potential attack vectors.
Re: LastPass: design flaw in communication to privileged components
#5Re: LastPass: design flaw in communication to privileged components
#6Password managers exchange a strong secret, something you know, for a weak one, something you have. Once an attacker gets to your database you're completely owned. When they compromise a normal password the damage is more contained if you maintain reasonable security practices.
Re: LastPass: design flaw in communication to privileged components
#7Password managers exchange a strong secret, something you know, for a weak one, something you have. Once an attacker gets to your database you're completely owned. When they compromise a normal password the damage is more contained if you maintain reasonable security practices.
Re: LastPass: design flaw in communication to privileged components
#8Re: LastPass: design flaw in communication to privileged components
#9This is not the same as https://labs.detectify.com/2016/07/27/how-i-made-lastpass-gi... is it?