LastPass says no passwords were compromised following breach scare
theverge.com
theverge.com
https://www.theverge.com/2019/9/16/20868111/lastpass-bug-exp...
>In a statement posted on its blog, LastPass downplayed the severity of the bug. The company’s Security Engineering Manager, Ferenc Kun, said that the exploit relied on a user visiting a malicious site and then being tricked into clicking on the page “several times.”
This was what led me to dump them and delete my account.
I thought at the time that A) they're sloppy and B) the next exploit will 100% be sold on the black market for minimum an order of magnitude higher price.
If there were a common exploit among the people on the HN thread like a compromised chrome extension I think they would have discovered it. There were a lot of people on that thread, a bunch of invalidated hypotheses and no clear commonalities.
Edit : i made a mistake - it only exposed the last used password in the vault. Pretty bad but not quite as awful as I first thought.
I remember when KeePass browser plugin had the same issue. The security researchers were not paid.
Or only bad vulnerabilities triggered using JavaScript? Or would you only accept a history with vulnerabilities if security researchers were paid properly for the work they invested into finding the issues?
I have much more confidence in open source password storage that doesnt try to autofill. Theres much less that can go wrong. This is how I store banking passwords.
A serious vulnerability puts me off but not as much as a tepid ass response that tries to downplay the severity of a really bad problem.
That makes me consider the software radioactive.
The fact remains that autofilling passwords in-browser has a gargantuan attack surface and hence the potential to go very wrong. You have to really trust whichever software you use for this.
I expected better from lastpass because I used to give them actual money. I'm not upset that some random keepass extension did this but I also wouldnt use it either.
Several browser plug-ins are available as well as simpler solutions like a browser extension to insert the URL in the title bar and sending keystrokes to the browser to populate it.
The answer is right there in the article: Use the browser's password manager.
I find Firefox's password manager + Sync a good solution, and I don't understand why people don't advocate it more. It's free and open source. Mozilla is a reputable software house with a good security team. Their revenue stream does not depend on you paying for the password manager. It doesn't even depends on monetizing your personal information.
Yesterday I found it even works as a password store for all of iOS.
It works just like another password app.
Thank You. We can now all go back and enjoy our holiday.
Edit: Hold on a min. "likely triggered" means they think it is triggered in error but still not sure?
Side Note: I really dislike these "updated" articles with new reference that are not "clearly labeled at either the top or the bottom of the news. I have no idea when that LastPass statement was added to this piece, was it before the HN headline submission or after? I have no way to know if comments or HN readers here are reading the same as I am.
Best way to keep a secret is don’t share it. Cloud storage is by necessity sharing the secret with the cloud server and everyone with access to it.
As long as you store the encrypted vault on a cloud service, your secrets are not shared.
The problem in this case is that you are running the vendor's code on your local machine to perform the encryption, and that's where the real issue is. You have to trust that that code is completely bug free. This issue is made worse by the fact that things are uploaded to the cloud, but it's not the underlying problem.
I have MFA enabled with the google auth app- has there been any discussion that accounts with two factor auth are pwned as well?
phpBB is notorious for security flaws. It doesn't seem unlikely that someone hacked the forum and modded it to leak user master passwords.
More info:
If passwords from other breaches fit the characteristics of a weak or compromised generator, that could also be used for targeting.
I have a rented VPS whose main two uses are being my IRC host (irssi running in a tmux) and hosting my Git repository containing the pass password store. As long as only I can SSH into the VPS, my encrypted password collection won't leak; as long as there is no keylogger or clipboard logger on the machines I use pass on, my passwords are secure. (I assume that SSH and GPG are unbreakable, which seems good enough of an assumption for the time being. Perhaps I'll switch to passage instead of pass some time in the future.)
I tend to navigate by URL or browser history, so I just don't enter phishing URLs.
An extension could save my ass in the scenario where a legit site (e.g. a shop) has been compromised and the redirect to payment services has been replaced with a malicious site, but I don't believe that's very common?
Any good alternatives?
Apart from that: bitwarden.
1. they found the breach and patched it, lies about it to save face.
2. there was no breach
Even if it’s option two, would you want to gamble on it?
But you have to realistically consider what are actual alternatives. For everybody else in my family, it's not lastpass vs some cryptographycally excellent local solution. It's last pass or 1password as uphill battle vs same password of your cats name over all of your accounts. Shared by your family members. My sister in law doesn't even have to wonder what her mom's utility or bank password is - they all literally use their old dead cat's name. For everything. So moving them to Lastpass or 1password with differentiated passwords has been my life's mission for past several years.
they are the norm. Average HN poster is empathically not :-/
Highly recommended!
And offline¹ or immutable². Some automated ransomware actively goes after common backups³ before touching the base data, more targetted attacks will too.
[1] If part of your threat model is security, not just accidental loss/damage, as it should be for everyone, this stops an attacker jumping from your base system to get at your backups.
[2] Alternatively, this will stop them modifying your backups even if they get access. Cloud providers offer what is claimed to be immutable storage, though your level of trust in them, your sensitivity to cost, and the likelihood you might someday want to properly forget something, will factor in to whether this is suitable.
[3] One reference amongst many: https://www.advintel.io/post/backup-removal-solutions-from-c...
> And don't forget to test them regularly.
A vital step that too many people skip. Or for advanced failure patterns: setting up automated tests that don't fail safe (does no alert mean all is OK, or does it mean the alert system has failed too?) and/or not monitoring to make sure that they are working.
But being a bit paranoid the most important passwords I keep in a KeePass-file on a USB.
I doubt they need more than a few kb's for them, but being 2021, maybe the cheapest onboard memory chip can still hold 16MB or more, and a sufficiently cunning hacker could use it as a storage of last resort.
There is still no better alternative if you want to leave lastpass, but what lastpass really has is a good UI.
1Password. Love the Chrome extension UI coupled with the desktop app. Way better than Bitwarden in my opinion.
Plus, set hosted BW gets you all the premium features, like shared vaults for the wife and family.
Aside from that I probably gave them permission to log in as me in one of the EULAs, why is it OK for them to store my passwords unencrypted. Who guarantees that there are no leaks at Google? Who guarantees that some malicious browser plugin (there have been MANY) has never figured out how to access my passwords - especially as if such a plugin can get the password to identify myself to Chrome, it can login anywhere to get the passwords.
Anyways, whenever I hear of leaked 1Passwords, I figure it is in such a vector - login on the browser. And the fact that they are doubling down on browser login, makes me less secure.
Paranoid, much?
Why do you think that they cannot bring encrypted passwords from browser to browser?
Chrome syncing across browsers does not mean they are being stored in plaintext. Your login is likely given you access to a key to decrypt them.
Chrome does have an ability to encrypt the password store with a different password of your choosing. In this case syncing still happens, but each browser install requires you to enter in the second password to unlock the store.
A malicious browser plugin does not need access to your password store to steal your password. Sooner or later you are going to log into a website and it will just steal it then.
Not necessarily. For example, Google could be encrypting your passwords using your Google account password.
> Who guarantees that there are no leaks at Google?
The same guarantee that all cloud services offer for non-e2e-encrypted content. If you are concerned about this, you must not use any password manager that stores passwords outside of your machine.
> Who guarantees that some malicious browser plugin (there have been MANY) has never figured out how to access my passwords
Even if your passwords are stored locally rather than on a cloud service, a malicious browser plugin can inspect your behavior as you fill in a password. Nothing will protect your credentials from a malicious browser plugin.
> Paranoid, much?
Probably. But self hosted systems exist if you want to use one.