4 ms·
Blog post about the sploit here from the authors: https://news.ycombinator.com/item?id=10217551 https://news.ycombinator.com/item?id=10217551
by jonmarkgo 11y ago
Blog post about the sploit here from the authors: https://news.ycombinator.com/item?id=10217551 https://news.ycombinator.com/item?id=10217551
- fuzzywalrus 11y agoFrom above link: "Our attack only covers users that click the “Store my password” option though so, don’t store your master password!" That seems a rather important detail. Thanks for the link.
- mhurron 11y ago> "Our attack only covers users that click the “Store my password” option though so, don’t store your master password!" > That seems a rather important detail. It's also against LastPass's best practices. When you click that button (Remember my password) you get this: "Are you sure you want to have LastPass remember your password? This will significantly decrease the security of your LastPass account!"
- misterbwong 11y agoThis has me breathing a sigh of relief. That said, why is this even an option??
- silverlake 11y agoBecause if people are required to type in a complex password every time they use LP, then people will choose short simple passwords. It's a tradeoff between security and ease-of-use.
- teach 11y agoI save my LastPass master password on my home computer, which I never log out of. (It's not a laptop, so it never leaves my office.) If an attacker is already physically in my office then I've got bigger problems.
- r3bl 11y agoSame thing. I'm using Linux and my /home directory is encrypted. My laptop automatically logs out after a pretty short inactivity (2 minutes, unless I'm using certain apps like VLC in which case, it logs out after half an hour) essentially locking the access to my /home directory. With that being said, having to type in my master password over and over again seems like a bit of an overkill.
- fr0styMatt2 11y agoCan this be a problem on mobile? I have a long master passphrase - too long to type on a touchscreen keyboard in any convenient amount of time and where there's a non-trivial risk that somebody peering over my shoulder (think - using it on the bus) could spy it. So in that case I resort to using the fingerprint-unlock feature (which I assume is the security equivalent of 'save master passphrase' or at least token). I am aware that this might open me up to other attacks - an adversary dusting my fingerprints off my tablet, etc. Curious though as to whether this is an attack vector for the same or a similar type of process to what the authors are describing (haven't read their blog post, just the Black Hat description).
- mahyarm 11y agoFingerprint unlock on iOS puts something equivalent to the master password in the iOS keychain for 1password. Only when your fingerprint is verified does the 1password app get it. So at the very least you still have your passwords kept in a relatively secure keychain manager and not inside the app stored in plain text of some sort.
- pstoll 11y agoAbout iOS fingerprint- while a judge can not compel you to type in a password, I have heard that they can compel you to swipe your fingerprint. Something to consider when deciding whether to enable fingerprint access to your smart phone login or other sensitive credentials (e.g. Password manager keychain credentials). http://jolt.law.harvard.edu/digest/telecommunications/court-rules-police-may-compel-suspects-to-unlock-fingerprint-protected-smartphones http://jolt.law.harvard.edu/digest/telecommunications/court-... (Fwiw - I use LP, no master password saved, no iOS finger print access)
- pmontra 11y agoYour fingerprints are already on the phone, they don't need to ask. After getting access to the phone owner accounts and data they can use other investigation methods to get proofs that can be used in a trial. Tl;dr, fingerprints are a password replacement only against people that can't read them.
- Karunamon 11y agoPossibly flippant response: because if the user doesn't want to keep rekeying their password, they should not be forced to.
- 27182818284 11y agoThat's from 2014, though. I would imagine what they are going to present is more current research?
- tempestn 11y agoReading that, it looks like the master password retrieval relies on you using the 'store password' feature, which means anyone with access to the local machine would have access to your vault anyway. Obviously such a feature will reduce security, although you wouldn't necessarily expect it to make the password itself retrievable. This was also somewhat reassuring: "As always, we made a responsible disclosure to LastPass. I want to stress how easy it was to work with the security team. The where very responsive and worked on fixing the issues we reported immediately. They also followed up with us from time to time and asked for our thoughts on every fix. It was a real pleasure to work with team!"
- why-el 11y agoA google search did not return meaningful results, so pardon the dumb question: What does the store password feature does exactly? Is that a way to remember the password like usual browsers do? I use 1Password and I don't think it has this feature?
- tempestn 11y agoThis is the feature to store the master password, so you don't have to type it in each time; you can just log into Lastpass automatically on that device. (Not a great feature for security!)
- why-el 11y agoYeah I got that reading the full post by the researchers. I am surprised it's even offered.