LastPass breach could've been stopped with a 3-year-old Plex update
androidpolice.com
androidpolice.com
For a security focused company, there is no excuse for a threat model to not include insider threats, vulnerable software inside an employees network, and potential phishing of employee credentials.
If it wasn't going to happen through Plex, it would have happened through something else.
Them pivoting like this is such a bad faith attempt at pinning the blame on a company that did everything right with regards to security. They should own up, and not try and throw another company under the bus. Even naming Plex as part of the attack chain seems disingenuous at best.
edit: Or not, or with major qualifications. That quote was mislabeled in the article
> "For reference, the version that addressed this exploit was roughly 75 versions ago," a LastPass spokesperson said.
Irrelevant, what's relevant is how come LastPass employees can access sensitive customer information on their production from a personal laptop
With enough 2FA and a thin-client approach to the user's machine it seems pretty safe. Even if an attacker gets passwords through a keylogger, the 2FA will detect and block attacks.
Sure, Plex had a security flaw, and the system owner didn't update its software in a timely manner, but ultimately the responsibility falls upon LastPass who allowed this system to access their network in the first place.
For a business that focuses and sells a product based upon good security practices, the optics are quite damaging for their reputation.
> "For reference, the version that addressed this exploit was roughly 75 versions ago," a LastPass spokesperson said.
Quite the game of blame deflection going on.
Whether or not the employee was running an outdated version of Plex or every bit of malware known to man on their personal computer has no bearing on the company's security breach. How was the attacker able to cross the corporate security boundary? Did the employee have access to company/customer data from their personal computer? Was this in breach of company policy, or is this generally allowed? If the former, why was this access not monitored and flagged? Answers to all of these are conveniently skipped in favor of "see it was an old version of Plex, case closed".
Does Plex really have that kind of reputation?
Give the man a break. The blame simply is on not practicing proper isolation and keeping work to a secure and controlled environment.
Maybe don't install crap on your dev machine if you're not going to keep it updated.
Blame a normal person? Nah. A senior engineer with keys to the castle? They should really know better.
> The blame simply is on not practicing proper isolation and keeping work to a secure and controlled environment.
Who is responsible for setting this up?
I'm only arguing against not blaiming "the act of missing an update on a personal device". That's nigh impossible to achieve across the board for all software we use.
I'm not arguing he's blameless. I agree that Plex is blameless. I also agree that LastPass needed a better threat model for privellage escalation/insiders attacks.
That's why you chuck Plex on a NAS, an old workstation, at least wrap it up inside a virtual machine.
... at LEAST least run it as it's own user.
Not your dev machine for a security company!
I promise I don't usually buy into a scapegoat. This is a unique situation. Almost any other company and it's a forgivable mistake. Any other role it's a forgivable mistake. Hell, any other seniority and it's a forgivable mistake.
Bro you are responsible for all my passwords, could you give half a fuck about basic security?
If only there was some way lastpass could ensure that crap wasn't installed on corporate network connected dev machines...
Does it not yell at you every time you open it?
What’s the best tool to find out if any of them is hacked?
Even if you are perfect, and you wont ever be, some dumb little thing can come up like Docker bypassing your firewall entirely and baring your database's passwordless arse to the internet[1]. Or like in this case you'll have forgotten to update Plex for 3 years.
[1] https://blog.newsblur.com/2021/06/28/story-of-a-hacking/
Protect the data as well as the machines. Isolate everything that can be the best way it can be. Pull your backups rather than push. Don't leave sensitive data around if it doesn't need to be there. Encrypt data at rest where possible. Don't allow HTTP access to directories named .git if you're in web hosting - of course don't store a repo in the served web directory, but know someone is going to do it anyway. Pre-emptively disarm any footguns you come across. Label them at least.
The best tool is experience, but I'd at least have some monitoring too. I use Zabbix myself because it was the first monitoring tool I used, but you can use whatever you fancy. This is not an install and sorted application, you need to learn how to use and configure it too..
Sorry as I type this I realise I definitely don't know my knowledge well enough as I'm having trouble simplifying it into a HN comment. This is a too-close-to 20 year career and counting in fairness haha.
Learn how to be the bad guy. Guard against your skills. Improve your skills. Repeat.
Stuff like running through hackthissite.org might be a decent place to get started on offence-based defence.