PSA: LastPass Does Not Encrypt Everything in Your Vault
hackernoon.com
hackernoon.com
You are looking at intermediate data of what's stored in your decrypted blob. Yes, some things are encrypted twice in the Lastpass vault.
The contents considered "unencrypted" by the blog post are actually only accessible after your private key has been provided.
"How can Lastpass show me the Google logo?" It's shown by your Lastpass Extension, after your vault has been decrypted with your password. It's the same reason that Lastpass can show you the password saved for Google!
Notice that request has an unencrypted folder name, "Email." Those folder names are only accessible after the decryption of the entire vault.
URLs are encrypted. LastPass does not know your URLs.
I noticed the article does not include the destination URL for this request, only the parameters. So I can't make a determination as to why this request was made and who the destination server is.
I just tried adding a new site to the "Email" folder, and no requests to remote servers showed up in my Network tab.
IF the LastPass extension really does make a call to lastpass.com with this information, then, yes, there is a possibility that Lastpass can track these hashes in some separate store. But that doesn't mean that the encrypted vault blob has the unencrypted data as claimed.
This will return an XML document with your vault data. Most of it is encrypted, however an URL parameter is encoded as hex, in plaintext. I am able to look at all URL. They could be storing the blog fully encrypted in a server datastore, but at some point, the LastPass servers are handing the client non-encrypted URLs.
And if the extension is pulling the logo from the web then there is also a leak to each site whenever it pulls (rather than to lastpass itself).
Best case scenario: the extension comes with a list of the most common logos baked into it. But if that's the case, why would it save a logo url. Hmm ...
I'm pretty sure we'll be hearing back from Lastpass on this one.
That's not really a leak unless you're keeping a password to some site without actually using the site and don't want the site to know you've done this. But that probably doesn't come up often in practice.
Those aren't great examples, but any out-of-band information leak is a bad thing to have. Even if there are no known exploits now there might be future exploits that haven't been anticipated. A common issue when it comes to security.
And again in this scenario (which we don't know if it's accurate, yet) it's pulling the image for every site with a logo whenever you browse the vault. So your IP address could be leaked to a site that you don't want to know your whereabouts at that moment.
Forensic information is forensic information. A security-conscious tool should not be increasing one's forensic footprint.
I've been able to confirm when you update a site through the web interface it makes a POST request to https://lastpass.com/show_website.php with the `url` parameter which contains the hex-encoded URL of the website. I think the author is correct about this.
Well, I don't even have lastpass so I can't check, but it obviously has to be sending something when you save the new site or it isn't saving it in the cloud at all.
NSA: LastPass, we suspect that John Smith uses your service. Give us access to John Smith's password database.
LastPass: We cannot, all of John's usernames and passwords are encrypted and we ourselves don't have the key.
NSA: Alright, then, give us the websites for which John Smith's database has credentials for, and we'll subpoena each website of interest individually.
If John Smith has known email address JohnSmith@gmail.com, it is probably safe to assume that the email is the login for at least some of the websites of interest, and can then ask each website for info on that particular user.
Now if there was a non state-level threat, that'd be different.
1.
The NSA already has that data they have your home address (this is public) and can see you connect to gmail servers at times you are normally home for. We've already seen evidence this is well within the NSA's capabilities based on the Dread Pirate Robert's trial. 2.
LastPass's RNG is closed source so if your threat model includes the NSA you've already lost as it is very reasonable the NSA knows every password LastPass could ever generate for you. 3.
LastPass's encryption/decryption is ALSO closed source so there is no reason the NSA can't just subpoena them to update your client with a faulty crypto. 4.
LastPass Apps/Browser phone home once unlocked. If subpoena by the NSA they can steal your password there.Seriously if you have a threat model that includes the NSA you've already lost.
You are completely correct that any threat model that includes direct attention from the NSA is insurmountable. Even highly skilled targets like OBL are eventually defeated.
I agree with the general point about direct attention, but OBL seems closer to the exception than norm.
I normally don't assume astroturfing without concrete evidence, but there is no information in the post that explains why the author is anonymous and the creator of BitWarden has previously made comments without disclosing their affiliation (https://news.ycombinator.com/item?id=12754396).
Yes, as this seems to be an initial marketing attempt by Kyle Spearrin (the creator of Bitwarden) to unveil his own LastPass alternative while simultaneous making LastPass seem untrustworthy. Regardless of whether the issue detailed in this article is true, the following timeline cannot be ignored:
1. Bitwarden.com was registered on Nov. 16, 2015
2. The initial commit to bitwarden/core was on Dec. 8, 2015
3. Release v1.3.0 of Bitwarden is issued on Jan 16, 2017
4. A quick fix release v1.3.1 is issued on Jan 17, 2017
5. Bitwarden.com gains an SSL certificate on Jan. 17, 2017
6. This article arrives touting an unknown LastPass alternative on Jan. 18, 2017
Suspicious? I am. Especially since Kyle is the only contributor to the project, as well.
The only thing unencrypted is the site's domain name. Who cares? Site domains are public anyways.
Definitely two opinions on this matter, I suppose. But for me, I really don't care that they don't encrypt the domain names for the sites.
For a really simple example, I guess there are quite a few people with a pornhub account in their vault. I'd guess a significant portion of those users don't want that fact to become public.
FTA, which is clearly more than a domain name:
Bitwarden looks interesting, but it doesn't seem to support team features, nor does it seem to have any documentation, or even an "about us" page.
I don't necessarily need LastPass to be there in 5 years, since I can export and recover what I need into another manager if I need to, but I personally don't want to go into something that is set up right now to not be there in 5 years.
This is not a permanent objection forever and ever, amen. If my objections go out of date, I'd consider at least trying it.
I hope you appreciate the joy of customers demanding to give you money, and what it means to your business. :)
Hi there, bitwarden is currently sponsored by the Microsoft BizSpark program which covers many of our operation costs and allows us to offer services for free to our users. We are working to introduce enterprise features for businesses in the future which will allow us to monetize. For now though, everything is free for users.
Let me know if you have any other questions.
- Clicking "Export CSV" does absolutely nothing
- If you have more than one two-factor device, it forces you to use the Yubikey, you can't log in with an alternative second factor
- Asked me to log in, and then when I logged in, it complained that I was already logged in, and forced me to log in again
- You can't have individually shared items within a shared folder
- The UI for permissions is confusing, checkboxes should grant permissions, not take them away
- Moving an item gives this error: "Sorry, this request is taking longer than normal", but the edit dialog stays as it is
- Just because you've added someone to a shared folder doesn't mean they have access to all the items, they may only have access to a whitelist or a blacklist, it's not clear which until you click through
- There's a "(none)" folder, which is confusing, as you can still select the parent folder.
- The free trial of Teams expired, but no visible effect on anything
- On Dec 21, 2016, I get this message: [screenshot]
- When you convert a folder to a shared folder, you get this message, which is not true: [screenshot]
- I get this error after sharing, even though "Shared-Email" does not exist, as I just deleted it! [screenshot]
- LastPass Android doesn't let you edit stuff offline
- LastPass browser extension prompts me for Yubikey more frequently then every 30 days, despite ticking "30 days"
- Keyboard shortcuts just don't seem to work on Firefox on macOS. Also, the help documentation doesn't mention that the defaults seem to be different.
- "Find duplicates" didn't find duplicates, one when one was in a shared folder and the other wasn't.
- This error message when I try to share something: [screenshot]
- When a user in the team forgets their password, they get removed from the team for some reason, without notifying admins.
- When trying to use LastPass on Safari, I get this error: "Something blocked LastPass"
- After creating a shared folder, I get this error. It's very unclear what cancel is meant to do. What is actually does is cause a spinner to appear for ages, then for an error message to appear saying the "request timed out", then a folder called "Shared-Email" to be created which is empty.
- Searching for an email address simply doesn't work
- This is so confusing. My trial has ended... [screenshot]
- I changed a permission, and I got this email. What is "Super Admin Shared Folders"? [screenshot]
- When I tried to add a user to LastPass Teams, I got this error message: "error: undefined" [screenshot]
- The users have a circle next to them with a letter in the middle, representing the first letter of the email address (not the first letter of the first name!)
- It added person X, but then forgot her after she attempted to add a personal account, and none of the passwords showed up
- It forget X's full name
- If you invite someone by accident to a LastPass team, there is no way to uninvite them, until they have accepted the invitation
- If you invite someone to join LastPass Team and they already have an account, the only way to join is by clicking on the link in the email. If the email ends up in Spam (which it did for us), you are not notified in any other way (for instance, when logging in to lastpass.com)
- If one of the admins make another user an admin, none of the existing admins are notified
Super Admin - Shared Folder: https://lastpass.com/support.php?cmd=showfaq&id=8096
Works for me. Guess that draft is really not ready for prime time and your musings are at least partially FUD.
Wine works too.
Edit: When the 1Password app under Wine functions better than the native LastPass app on Linux, I think it's time to rethink some priorities.
Can't even begin to count the # of times it lost a newly generated password, or it failed to swap the password for a website, or didn't immediately show a password I just created until I did a full refresh, or it has opaque rules about what can be shared with teammates. Would be great if they put more focus on getting the fundamentals right before expanding the feature set.
LastPass always thinks I want to replace credentials for subdomain sites. all the time.
When I have a password saved for foo.com And then I try to save a password for bar.foo.com. LastPass, for all that is holy and good in the world, stop assuming I want to replace my password for foo.com damnit.
Lack of linux client (which I suspect are more likely to pay for a password management system)
I get that they say that everything is encrypted, but really it could be a lot worse. I definitely won't be switching password managers just because of this like some people are saying.
Keepass had tons of issues on the synch-side, merging incorrectly or just plain not syncing in addition to the android app being horrible to some extend. Additionally the chrome plugin is less well written, it's not bad but not as easy to access as lastpass.
1password is still not out on linux and I have no intention of using them until they bring out a linux client.
Bitwarden looks fishy to me (audit? pricing? funding? integration?).
If the only problem with Lastpass is that they sent out the URL of the site in cleartext over a HTTPS connection, fine, have it, there is clearly worse and it's something I'm willing to accept in exchange for one of the better password managers.
Thanks for sharing.
Same information that your internet provider already has linked to your ISP and can be retired by a warrant or no warrant.
Really? Were you using KeePassDroid? I remember that being not so great. I think Keepass2Android is excellent.
The LP app has been much more pleasant.
Why? The client functions just fine under Wine and runs better than most of the native clients that already are on Linux.
Secondly, if they treat Linux as second class I'll treat them second class.
Lastpass even has a cli client for Linux in addition to working on all the browsers, I see no reason why 1password is doing it even remotely better.
The problem is that using Wine tells the 1Password devs that they don't need to make a native Linux solution, that it's unnecessary since it already works.
But that is not what I want. I want a native Linux client since that reduces the number of packages on my system drastically.
Wine has also little ways to employ security measures for Linux, so if there is a problem concerning Linux and Security, 1Password cannot fix it.
On the one hand, it feels like they're being sneaky and trying to trick savvier users who might glance at the data to make sure it "looks encrypted". On the other hand, they have to have realized someone would notice eventually. Or maybe that's the point: if they obfuscated it well, someone would break it and they'd have egg on their faces. By just hiding it a little, they have plausible deniability that they weren't trying to obfuscate.
But any way you slice it, it seems weird.
This might be modestly annoyingly resource intensive for mobile, probably not an issue for desktops.
What prevents Lastpass, bitwarden or any other third-party to update their software (and/or compromise the download server) to synchronize all information un-encrypted in a new version which is auto-updated by the user?
I currently use KeePassX, and synchronize this file with a secure server myself since I feel uncomfortable with having software that handles the encryption also controlling the synchronizing service.
This works again random software companies, but not against google.
I see a ton of reviews all over the Internet claiming it's one of the best password managers, and I wonder if these reviewers and websites didn't just get paid some money to write a positive review without ever installing, let alone using the software. With the software being so shoddy, I would not trust my passwords to Lastpass even if they ended up fixing the UX. I ended up deleting my account and switching to Enpass which has worked flawlessly. On top of that, I don't have to trust Lastpass, or any shitty company like that, with my most valuable data and can sync it over WiFi, my NAS, and shared folders in addition to cloud providers (also works in Linux).
Last I checked (over a year ago), 1Password wasn't terribly interested in adding it as a feature, and while there was a KeePass extension which implemented HOTP-based 2nd factor, I never got it to work reliably. Is there ANY service which integrates the YubiKey as well as LP does? I'm more tied to that than I am to LP.
Unrelated to the initial post, but here's a recent LP annoyance: on January 9, LP pushed an update to the Chrome extension which broke the version 3.0 view (which looked like a filesystem), forcing users to move to their 4.0 view if they wanted to use the extension. According to a user commenting on the support tab in the Chrome store, "you deleted the min.js file from your extension but your lastpass version 3 view still needs this file. cant even manually copy it back because chrome then thinks its malware. keep up the good work!"
I can't speak to the veracity of the comment, but LP's forum was pretty active, and admins essentially said "don't use 3.0" as a fix. Support tickets mentioned they were aware of the issue, but not much else. To be fair, LP did say they would eventually deprecate the 3.0 view, but there was little communication about the recent update, making it seem like they don't really give a shit. I don't like their 4.0 view; it's less efficient, and more interested in making things look pretty.
However, if we want to trade off _some_, but not all privacy (in terms of what logins a vault contains), I can think of a naive obfuscation scheme where random domains are added to a login alongside the real one. Here's how that could work:
Preprocessing
* assign an order to the logos and hence numerical IDs
* pick a hash function (URL / site name) => ID
User adds a new login:
* is the URL recognized (e.g. accounts.google.com) i.e. do we have a logo for it?
* if yes, obtain its ID e.g. 1
* get N more random IDs e.g. 14, 124, 144
* save all of them as the login's metadata e.g. "logo_cache:1,14,124,144"
User requests logins (and hence needs logos):
* compute (and cache) the list of IDs of logos needed (M entries x N logo IDs each, deduped)
* pack and send the logos (hopefully a much smaller subset than all logos)If any 3-letter agency want my history, they can just visit anyone in between me and the URL.
My browser have my browsing history. My ISP have my browsing history. DNS resolvers have my browsing history. CDN have my browsing history. Proxy/VPN have my browsing history. (which some they claims they don't log at all)
Basically browsing history is too accessible to anyone. If you are using network that doesn't managed by you, they have your browsing history too. (McD, Starbucks, etc)
And last again like others+Lastpass have commented, your whole pile of encrypted data is encrypted together and sent to Lastpass. Did you try to read your Wireshark?
I haven't found any other services that work as well for teams with features like this. I've tried 1Password and some others and found their team sharing options lacking.
Curious what other teams are using -- not just personal password managers but tools you can use successfully over an entire organization.
For the most part I am happy with Dashlane and pay for it annually. Sometimes when chrome or firefox update it take a while to load the browser plug-in. other than that I have few complaints.
Anyone else use Dashlane or something similar, other than LastPass?
Looks like their Argon2/ChaCha20 based KDBX4 format is now out too, so I've got some upgrading to do.
As for sharing - yeah, you probably lose that. Well, unless you sync a separate DB or something.
Years later KeePassXC[1] was forked and slowly growing.
LastPass needs to comment on this. It looks pretty bad.
Folks, encrypt _everything_. Anything less is profoundly foolish.
The WeChat article recently posted shows one major thing about user behavior and UX architecture. Users actually prefer to have one APP on their phone representing their social identity, have all their notifications, contacts, etc. from all different communities in the app.
So this probably means that the "personal identity server" should have some default protocol to receive notifications (encrypted with user's public key) and an APP for iOS and Android. The server would have rules for processing notifications and may notify the user (eg it may stop after the first 5 or set do not disturb where only the badge updates). Upon opening the app the user would see all the notifications from all the other services (they would be fetched and decrypted). And those notifications may contain deep-links back into flows that generated the notifications, eg a chat.
What is also nice is if you can have these rules be general purpose hooks that run on the client in some isolated JS environment. Then for example you can update the list of ids that a user's contacts have on different services (if you have pairwise anonymity) in the background. And next time you visit a website the auth extension/library/app can offer to connect you with those people on that website.
I think the Personal App should display badges corresponding to the # of websites that have caused notifications, not the # of notifications. The latter should appear only when you open the app and see the list of relying party websites. Then each website can have a # of notifications next to it and the can be sorted eg by most recent or most urgent notifications.
Last thing - by having a personal APP I have a feeling that it would also be tied in with payments in the future. Identity service is becoming tied with payments (to prevent fraud, China now ties the two together more than any other country and cash is disappearing). So the Personal App could in the future have some standard for attaching payment methods and using them without giving the relying party anything except tokens representing payment plans the user agreed to (like Stripe does).
In this way, even though payments are increasingly tied to identity - which may lead to fascism - we can empower local communities to control the identity and maybe in the future even issue their own money on their own credit! This may help finance loans for poor people in India etc. (already shown that having a large group guarantee loans works better for everyone due to social factors etc.) and pull people out of poverty faster. @mediaprophet what do you think of these points about integrating payments inside identity App in the future?
(By the way I say community because you may host your own data AND your own identity on your own server but when it comes to reputation and payments, there has to be some others who give you this value. Maybe it will not be communities. Maybe it will be completely distributed with no centers. But so far in history, wealth and reputation and power has always found a way to concentrate itself at least a little.)
It's been a long-standing dispute... Chrome says "if people have physical access, security is broken anyway." But that's because they refuse to acknowledge the lesser threat model; "A non-tech savvy friend or family member borrowing my computer for 20 min" -or- "my computer gets stolen from my desk while I was logged in... and now they have access to all chrome passwords in plaintext."
It's infuriating. Wish they'd fix that, even if it's a superficial fix.
Actually, I think it does that on Mac OS too.
Don't know about Linux, since I haven't tried it.
When using a non-cloud solution (e.g. KeePass, local 1password installation) - Auditable and specified ecryption: I know how my passwords are encryped. I can check this by actually decrypting and finding my passwords - No automatic updates. You can't force an update to my client that breaks security.
Did they delete it?
Would be my reply to the email, coupled with my demands.