Fake LastPass password manager spotted on Apple's App Store
bleepingcomputer.com
bleepingcomputer.com
It’s not like it’s an edge case either, there are hundreds of apps with obviously and blatantly misleading logos, brands, names etc. Just see ChatGPT / OpenAi for example.
I have taken to sharing direct links to Apps in the app store now when recommending things to non-technical friends/family, because I’ve lost all confidence that they will find the “correct” app anymore just by searching, and not one of hundreds of highly dubious clone apps.
Difficult to argue against the recent actions of the EU when the supposed benefits of the walled garden are crumbling anyway…
A lot of the "security" industry is a big scam designed to take your money. Many of the products they sell don't work because they don't have the ability to filter out bad actors. What's the value of a code signing certificate if someone can spin up a company in a corrupt country and get an EV code signing cert for that businesses? The answer is $0.
We're on the 2nd generation of users that have been trained to trust the app store which is little more than a big search engine due to the volume. I would compare it to searching for an app on Google and installing whatever shows up high in the results.
The average user doesn't have the tools to discover the trustworthiness of individual developers, and haven't for ~15 years, which has led to a situation where no one (normal) could assess things properly even if you gave them the tools they need.
The Domain Name System has its flaws, but it's honestly kind of a miracle that we arrived at a system that's easy for users to remember (compared to numeric phone numbers), while remaining relatively decentralized.
I worked on the App Store and Music at Apple, but I have no idea about the app review process.
1. https://blog.lastpass.com/wp-content/uploads/sites/20/2024/0...
I’m still not sure what you are suggesting a reviewer unfamiliar with LastPass to know.
The reasonable response here from people at Apple should be more like "this individual reviewer was negligent in their duties and has been reprimanded appropriately; additionally, we are attempting to prevent this kind of mistake from happening in the future with better training and more redundancy in the review process", not "what do you expect? how could the reviewer possibly know what LastPass is?".
Like, do I believe an open ecosystem is better? Of course! But that isn't my argument here, today, on this thread. I am saying that, assuming the benefits claimed of the closed ecosystem are legit, Apple is not just doing a half-assed job: you are actively defending that half-assed job by saying it somehow isn't possible to do better, even when that obviously isn't the case... do remember that this was actually my job for a while!
If you had submitted this kind of scam to Cydia, I guarantee I would have put enough effort in to at least learn what LastPass was and verify your involvement in the company before rubber-stamping a product that used its trademark! (Which, incidentally, maybe finally explains why the independent UCSB research done on this actually showed Cydia offered a safer curated core ecosystem than Apple... we actually gave a shit about what we promised to do.)
Also Apple: Lets in thousands of scam apps as a matter of course
The entire software distribution industry could use a mulligan. I think it should start by using domains as identity because it's the only namespace we have with global buy-in and anyone can register / reserve a unique identifier (aka domain) in that system.
If the supply chain for that app went back to 'lastpass.com', and that information was prominently displayed, it solves a lot of problems in terms of educating users to help them avoid scams.
Misspellings indicate fraud?? Good grief.
Check the meaning of fraud in the dictionary, please.
Do note that this article fails to actually identify any threat here.
https://blog.lastpass.com/2024/02/warning-fraudulent-app-imp...
Fake news. Article does not say Apple removed it. On the contrary:
"whether by Apple or the fake app’s developer is yet unclear — Apple has not commented."
From the article:
> ...the app was likely created to act as a phishing app and steal credentials.
> If you have installed the fake LastPass app, you should immediately remove it and change your password at lastpass.com. It is then advised to perform the arduous task of resetting all passwords stored in your LastPass vault to be safe.
Though one could argue that they have not _definitively_ proven that this app is a threat through testing, it really is not much of a stretch of the imagination that a LastPass-lookalike would be used for phishing. This app is very clearly an illegitimate clone.
That a fear, not a threat.
> Though one could argue that they have not _definitively_ proven that this app is a threat
Why bother arguing that? They haven't claimed any evidence, let alone proof.
> it really is not much of a stretch of the imagination that a LastPass-lookalike would be used for phishing.
App Store rightly does not ban apps on stretches of imagination.
Apple has removed the app: https://techcrunch.com/2024/02/08/a-fake-app-masquerading-as...
Fake news. Article does not say Apple removed it. On the contrary:
"whether by Apple or the fake app’s developer is yet unclear — Apple has not commented."
Your view is very strange though, because if the app were not a scam, then why would the developer voluntarily pull the app from the store?
Agreed. And readers can draw the obvious conclusion from your failure to do so.
> if the app were not a scam, why would the developer voluntarily pull the app from the store?
To prevent further bad publicity, obviously.
People all over the internet today in various discussion forums, including on HN in multiple submissions, have already drawn the obvious conclusion, without having read my comments, and their conclusion is almost universally the opposite of yours.
> To prevent further bad publicity, obviously.
It prevents any sales, which is the point of selling in the App Store. But why do you think there's so much bad publicity, if there's nothing wrong with the app?
It's unclear why it even matters who exactly removed the app from the App Store, because Apple's rules do not allow developers to deceive App Store users, and you've already more or less admitted that the app is deceptive. https://news.ycombinator.com/item?id=39308175 Although I don't know how you can justify saying that it's "at most" deception rather than "at least" deception, because "Trusted by over 1+ million users and 10,000+ businesses" is a flat out lie. Thus, even if the developer refused to remove the app, Apple should have anyway.
The LastPass claims.
> if there's nothing wrong with the app?
I didn't say there's nothing wrong with the app.
> It's unclear why it even matters who exactly removed the app from the App Store
Then I wonder why you are insisting it was Apple.
As I already said, "somehow magically every single time a scam app makes the news media, the app disappears from the App Store." Also, self-removal "prevents any sales, which is the point of selling in the App Store."
> I didn't say there's nothing wrong with the app.
Then I wonder why you are insisting it wasn't Apple.
It appears your view is that it's "unsubstantiated" unless Apple comments, but as I already said, Apple never comments about this, so apparently there's never any substantiation according to you, and it's just a giant coincidence that every single time a scam app makes the news media, the app disappears quickly from the store, even when the app's developer may be asleep due to living on the other side of the Earth.
It's a very convenient way of sticking your head in the sand and refusing to make the most logical inference.
Even if true, that doesn't mean removal was by Apple rather than dev.
> self-removal "prevents any sales, which is the point of selling in the App Store."
Ditto. Self-removal reduces further rep damage that cold impact other sales inc. of a future remedied version.
>> I didn't say there's nothing wrong with the app.
>Then I wonder why you are insisting it wasn't Apple.
I am not. I am insisting we don't know.
> It appears your view is that it's "unsubstantiated" unless Apple comments
No. You've shown no substantiation from /any/ source. Just supposition.
> but as I already said, Apple never comments about this, so apparently there's never any substantiation according to you,
Wrong. Often devs announce removal by Apple.
> a very convenient way of sticking your head in the sand and refusing to make the most logical inference.
Inference requires evidence. None has yet been shown.
I agree with the Techdirt article that you misrepped as saying removal was by Apple. "whether by Apple or the fake app’s developer is yet unclear".
I eagerly await the return of the app.
That's the thing: these scam removals never return. New scams arise, but the specific removed apps don't.
You speak of evidence, so show me even one example of a publicized scam app that was removed (by "someone") and then returned triumphantly.
> Wrong. Often devs announce removal by Apple.
Wrong. Legitimate developers announce removal by Apple. Scam developers never announce removal by Apple. In fact, scam developers are almost always anonymous, so where would you even find their announcements? Go ahead and find the announcements of "Parvati Patel". I'll wait here.
> Inference requires evidence. None has yet been shown.
Wrong. We have plenty of evidence. You're requiring a very specific piece of evidence, an official announcement from someone, but that's never going to occur. It's weird to even call it "inference" when your evidence for X is simply someone asserting X. (Moreover, theoretically, either Apple or the developer could be lying, so where's your evidence that they're not?)
This dev is not. His name is on the app.
> We have plenty of evidence.
None shown. The only evidence you presented was the TechDirt article which transpired to be a misrep by you.
> You're requiring a very specific piece of evidence, an official announcement from someone
I am not requiring anything. I"m happy to accept the lack of evidence for your claim Apple removed the app.
> Moreover, theoretically, either Apple or the developer could be lying, so where's your evidence that they're not?
Since no-one has shown either has identified the removal, we need no evidence to show either one lied about it.
“UPDATE 2/9: Apple has removed the "LassPass" app from its App Store and also pulled the app's developer from its developer program, the company confirms to PCMag. Apple says it has also received a trademark dispute against the now-removed app.“
I guess you can stop the logorrhea now… Although the true lesson I hope you take away from this is that you could have stopped the logorrhea at any time if you applied just a little deductive reasoning and common sense.
Because it is unsubstantiated.
No pedantry involved.
Or you can simply read:
https://www.pcmag.com/news/beware-theres-a-fake-lastpass-app...
UPDATE 2/9: Apple has removed the "LassPass" app from its App Store and also pulled the app's developer from its developer program, the company confirms to PCMag. Apple says it has also received a trademark dispute against the now-removed app.
That (belatedly) is evidence. Thanks.
So much for the claim hereabouts that Apple never comments on removals...
Fake news. LastPass's warning does not claim the other app is a fake copy.
> LastPass would like to alert our customers to a fraudulent app attempting to impersonate our LastPass app on the Apple App Store. The app in question is called “LassPass Password Manager” and lists Parvati Patel as the developer.
And the claim of fraud is unsubstantiated.
What would you consider to be such a claim? The part they quote seems to explicitly call out the other app as being a fake copy when they call it "a fraudulent app attempting to impersonate our LastPass app".
> And the claim of fraud is unsubstantiated.
You seem to be asserting that there is no such claim. What are you trying to say?
"The app is a fake copy."
> The part they quote seems to explicitly call out the other app as being a fake copy when they call it "a fraudulent app attempting to impersonate our LastPass app".
Explicit would be "fake copy".
This callout does not even claim successful impersonation.
> You seem to be asserting that there is no such claim.
On the contrary, there is such a claim. What I said was is the claim is unsubstantiated.
How about wait until it happens?