Live data from Hacker News

Security Issues with LastPass on Android

abhyudaya.dev

1–10 of 64 posts

Re: Security Issues with LastPass on Android

#4
These aren't really novel security vulnerabilities or anything, just some common sense things to be aware of so you don't shoot yourself in the foot: generated pronounceable passwords might not strictly follow the length that you set, don't paste your passwords into the address bar of a web view, and don't set a weak master password.

Re: Security Issues with LastPass on Android

#5
post #4

These aren't really novel security vulnerabilities or anything, just some common sense things to be aware of so you don't shoot yourself in the foot: generated pronounceable passwords might not strictly follow the length that you set, don't paste your passwords into the address bar of a web view, and don't set a weak master password.

Thats right, we should blame the victim for trusting the tool.

Password managers are increasingly mandated by organisations, and Lastpass is a very common recommendation. Even in the minority of technical users that use this kind of tool I expect small mistakes - like accidentally pasting a password in a URL. A good tool doesn't let you shoot yourself in the foot by escalting that to a non-obvious leak. The password length being wrong is 100% on the tool. Th weak master password and the duplicates are again, things the tool shouldn't do - it claims to give good quality security reports.

With respect to Lastpass specifically, I dislike the tool immensely. Ive had to use it a number of times and have always found its UX significantly buggy - included blatant failures like not saving passwords with no indication; coupled with the acquisition by LogMeIn and I'm incredibly distrustful.

Re: Security Issues with LastPass on Android

#6
post #4

These aren't really novel security vulnerabilities or anything, just some common sense things to be aware of so you don't shoot yourself in the foot: generated pronounceable passwords might not strictly follow the length that you set, don't paste your passwords into the address bar of a web view, and don't set a weak master password.

Too short passwords being generated sounds like an issue that IMO violates user expectations, the other two do not.

Re: Security Issues with LastPass on Android

#7
I personally have been using LastPass since it came out. I am much more secure than if I didn't use LastPass. A friend loved trying to break into my accounts for fun so I feel like I was a much more secure person just for stupid reasons. (It really was a game and nothing he did was nefarious)

Companies that use password managers are infinitely better off with one then without. My co-workers would repeat their passwords and make them incredibly simple and easy for anyone to break the it with basic social hacking. My old company had the lowest level of tech skills and the company contracted their IT work and had the stupidest password policy. You just had to change one digit. So the joke was people would just +1 their passwords and they would know how long they worked there.

Repeated passwords is something people do because we all have hundreds of passwords if they don't have a password manager. Even me and my paranoid ways had several because I had to use a system that was based on the url of what I using.

Re: Security Issues with LastPass on Android

#8
post #4

These aren't really novel security vulnerabilities or anything, just some common sense things to be aware of so you don't shoot yourself in the foot: generated pronounceable passwords might not strictly follow the length that you set, don't paste your passwords into the address bar of a web view, and don't set a weak master password.

Too short passwords being generated sounds like an issue that IMO violates user expectations, the other two do not.

Hi! I am the author of this post. I think that taking the user to `www.foobar.com` when he/she typed `foobar` does violate the expectations for most users. All browsers which I've used take the user to their selected search engine. Most people outside of HN do not know that what they type in that search bar would be visible to anyone listening on the wire.

Re: Security Issues with LastPass on Android

#9
post #4

These aren't really novel security vulnerabilities or anything, just some common sense things to be aware of so you don't shoot yourself in the foot: generated pronounceable passwords might not strictly follow the length that you set, don't paste your passwords into the address bar of a web view, and don't set a weak master password.

Thats right, we should blame the victim for trusting the tool. Password managers are increasingly mandated by organisations, and Lastpass is a very common recommendation. Even in the minority of technical users that use this kind of tool I expect small mistakes - like accidentally pasting a password in a URL. A good tool doesn't let you shoot yourself in the foot by escalting that to a non-obvious leak. The password…

Most people realize they can hurt themselves if they use a hammer wrong. If someone can be expected to put four years of their life into a degree or prepatory trade training they can be held accountable for not caring enough to spend 10 minutes reading about effective use of their password manager.
Post reply on HN