LastPass: design flaw in communication to privileged components
bugs.chromium.org
bugs.chromium.org
And there's nothing in their response that tries shifting the blame: https://blog.lastpass.com/2016/07/lastpass-security-updates....
This was not necessary for this attack to be successful on the default configuration of the tool. That's what I take issue with.
I feel like I'm reading some person's pet Wikipedia page. If they do then at least give some examples. You can't just say damning things and expect everyone to take it at face value.
The phrasing was "both exploits do require tricking a user via a phishing attack into going to a malicious website".
This suggests that the blogger believes that the only attack vector involves tricking the user to go to a malicious website; I can reasonably see calling such attacks phishing attacks.
The problem (which is, in my opinion, more serious) is that, as you identify, the blogger seems to horribly misunderstand the potential attack vectors.
> We have verified that intercepting messages via the method you suggested is possible and is a problem. We have also verified it only affects firefox (chrome, ie, safari, opera, etc do not use the window for message passing in the same manner) and doesn't affect our primary addons.mozilla.org firefox download (which is still 3.0 version).
It seems latest version for windows is 4.1.20a? As I'm both linux and firefox user and there have been 2 password stealing exploits revealed I would very much like to know if this affects me (my version seems to be 3.3.1). Is there any version history that I could check or does anyone know what versions are affected by these 2 exploits?
> If you are running LastPass 3.0, you are not impacted and do not need to update.
As far as I know, 3.0 refers to their old interface. You can download the new version directly from their website, but not through the Firefox add-on site. The version history is available here [1].
I use a Yubikey that's required when I log into a new PC (my home pc is set to only ask every 30 days for my 2FA key), I use an email that is only connected to Lastpass and I have a strong passphrase. Any other device I use Lastpass on is set to require a password and 2FA key at each start.
Is that enough to make me reasonably secure?
This guy says that if the webpage "asks" for another's page credentials, lastpass plugin will give it. Every character/keystroke in specific fields could be catched/logged , here you have an example from ... eBay : https://news.ycombinator.com/item?id=12000820
Anyway, this was already fixed and pushed to the users, as the guy mentions in his post.
The LastPass exploits presented exist after you have unlocked your vault, so 2fa on the LastPass vault won't stop them.
Personally, I'm not moving away from LastPass over these.
Might work out better for them than having one issue appear a week later.
In fact, I'd go further and say that you can do this with your login name. So for example:
myemail+by@gmail.com for eBaY
This also helps mitigate those attacks where the attacker actually contacts support and socially engineers them into giving all your info and even stealing your account:
https://medium.com/@espringe/amazon-s-customer-service-backd...
If you are hosting with AWS you should really consider doing that http://www.techinsider.io/hacker-social-engineer-2016-2
Plus, from a practical standpoint, what do you do when a site forces you to change your password because they fear their password db has been compromised (or has asinine rules about your password being too long, or make you rotate your password every 90 days, or they change their domain name 5 times in 3 years)?
1) If your password is cracked, a hacker seeing it might deduce your algorithm and then deduce that your Amazon password would be 'myemail+mo', etc. Now your scheme is out the window.
2) Even assuming your password is salted and hashed securely such that it can't be decrypted, Ebay would probably reset it as a precaution. So now you've got to change this password. Maybe you decide to do the 3rd and 5th letters of the domain name instead. So now your scheme is 2nd-and-5th for all but Ebay, and you've got to remember that the Ebay one is unique. For now. As more leaks or resets occur down the line, however, you'll have more exceptions, to the point that you'll be forced to maintain a list of what KIND of passwords each site uses. In which case, why not just use a password manager?
To be fair, there are a lot of script kiddies in the world.
Simply using the browsers built-in password saving capability with random passwords is still better than nothing (Chrome can even generate random passwords for you). Changing the password for one compromised site is better than having to change it for every site because of password reuse.
You just have to turn off any automatic / integration features. I do. Unlock with master password for every use. Really, how often is that, since most sites keep you logged in? Just a couple times a day for me.
(Though I don't use much more than those, on my phone. I do have a laptop ...)