Slashdot Mirror


LastPass Accounts Can Be 'Completely Compromised' When Users Visit Sites (theregister.co.uk)

Reader mask.of.sanity writes: A dangerous zero-day vulnerability has been found in popular cloud password vault LastPass, which can completely compromise user accounts when users visit malicious websites. The flaw is today being reported to LastPass by established Google Project zero hacker Tavis Ormandy who says he has found other "obvious critical problems". Interestingly, Mathias Karlsson, a security researcher has also independently found flaws in LastPass. In a blog post, he wrote that he was able to trick LastPass into believing he was on the real Twiter website and cough up the users' credentials of a bug in the LastPass password manager's autofill functionality. LastPass has fixed the bug, but Karlsson advises users to disable autofill functionality and use multi-factor authentication. At this point, it's not clear whether Ormandy is also talking about the same vulnerability.

2 of 134 comments (clear)

  1. Re:Expected by Sneftel · · Score: 5, Informative

    The exploit doesn't seem to have anything to do with "the cloud". Once you're logged in to LastPass and your vault is downloaded, password decryption and form filling happen locally.

    --
    The opinions stated herein do not necessarily represent those of anybody at all. Deal with it.
  2. Re:Expected by Sneftel · · Score: 5, Informative

    The problem again is LastPass. Nobody knows if their security practices are any good, and the attack surface is huge.

    Well, their online security practices are relatively unknown, but they're also kind of beside the point. Yes, LastPass won't hand out someone's vault without some sort of authentication, but that's just fences around brick walls. The real means of security is in the client, which is the only part capable of decrypting the vault (decryption keys never being uploaded). The client source code is available and has been audited, so you can feel pretty good about that, short of the Ken Thompson hack or the possibility of the local computer itself being hacked (which, of course, would affect any password manager).

    --
    The opinions stated herein do not necessarily represent those of anybody at all. Deal with it.