5 ms·
It seems dubious that there is a real vulnerability here. The authors talk a lot about how you can get everything if you compromise the client machine, but of
by devit 11y ago
It seems dubious that there is a real vulnerability here.
The authors talk a lot about how you can get everything if you compromise the client machine, but of course if you compromise the client you can compromise everything.
Just install a keylogger to get all typed passwords, send the decrypted hard drive image over the network and run it in a VM proxying network traffic via the compromised machine, no need for any targeted attack.
The fact that they focus on that rather than on an actual interesting attack makes me believe that there is no real vulnerability whatsoever.
"We also found how it is possible to abuse account recovery to ultimately obtain the encryption key for the vault" is really scary, but if it were accurate they would be talking solely about that, so maybe it's just a phishing attack.
- superuser2 11y agoThere is an account recovery mechanism available to those with a LastPass extension that is or was logged in to the account in question. Dropbox is the same way - if you forget your Dropbox password you can use your logged-in copy to get an authenticated session and change your password. It will be news if there's an account recovery mechanism that can be exploited by a total stranger without access to your copy of Chrome/FF. You would expect that 2FA could be bypassed for the locally cached password database, since AFAIK there is no such thing as requiring an OTP to decrypt the ciphertext that you have, only to prove to a server that you know the TOTP secret. Lastpass discloses that you can turn off 2FA for new logins by proving ownership of an email address. You can set a separate email address for this purpose, and I believe also turn it off.
- polemic 11y agoYes, of course if your live machine is owned you lose. However, this means you can potentially recover vaults from unattended / stolen / lost / unwiped hard drives, phones etc.
- Meekro 11y agoOnly if they told the browser plugin to "store my master password." That shouldn't surprise anyone -- if the master password is stored somewhere that the plugin can read it without any additional decryption keys, so can an attacker.
- chrisfosterelli 11y agoI agree. It doesn't sound so much like an actual vulnerability in Lastpass as much as it is a reminder of how crypto works.
- outworlder 11y agoSounds like one of those "It rather involved being on the other side of this airtight hatchway" http://blogs.msdn.com/b/oldnewthing/archive/2014/12/17/10581257.aspx http://blogs.msdn.com/b/oldnewthing/archive/2014/12/17/10581...
- TrevorJ 11y agoThe fact that it is still a central point of failure that contains the keys to the kingdom is worth noting. It occurs to me as I write this that for most people compromising an email account would be just as disastrous, given how many services rely on a simple email for password recovery/resets.
- rkuykendall-com 11y ago> The fact that it is still a central point of failure that contains the keys to the kingdom is worth noting. I think the difference between someone who uses a password-manager user, and the vast majority of people who don't, is that those who don't have HUNDREDS of points of failure that contain the keys to the kingdom, some completely insecure.
- deleted 11y ago[deleted]
- morsch 11y agoHardly. "Keys to the kingdom" seems to imply that access to the key opens up a large number of other doors. That's the case for email (via password recovery) and password manager (via its function), but not for much else. E.g. while access to online banking is a catastrophe in its own right, it doesn't unlock many other accounts.
- normloman 11y agoNo, the point is, people without a password manager tend to use the same password for every account. So you steal the bank password, and it opens your email, facebook, and everything else. Hundreds of failure points. With a password manager, there is just one.
- rphlx 11y agoHuman nature being what it is, a large fraction of password-manager users probably also reuse passwords, or nearly reuse them, which is nearly as bad. With the password manager being there for cases where some BOFH admin required two relatively-prime numbers, plus three non-adjacent capital letters, plus at least one special character that's not a star, plus a final character that's not a lower case letter, plus uniqueness with respect to your previous 100 passwords, plus a length of at least 12 characters, plus a change every 14 days.
- akshatpradhan 11y agoWhat do you mean by >run it in a VM proxying network traffic via the compromised machine?
- aqwwe 11y agoI guess you could setup two factor auth. locally without a third party...
- rebootthesystem 11y agoI think you are right. I am sorry to say I have fallen prey to this flawed argument. I need to migrate to LastPass something I am not happy with and have been stopped a few times because of articles like this one. I'll ascribe it to a lazy approach to evaluating what is being said.
- knieveltech 11y agoLastPass is pretty sweet. It even has a CLI widget that deploy scripts like Fabric can use to check out credentials and log into remote servers.
- abalone 11y agoAnd yet it may be interesting to compare it to competing password managers such as iCloud Keychain. Is it less vulnerable to "master password decryption" part of this attack due to its deeper OS integration? Not that it doesn't have its own vulnerabilities.[1] But perhaps those are more bugs (e.g. not enforcing sandboxes properly) than architectural weaknesses. [1] http://arstechnica.com/security/2015/06/serious-os-x-and-ios-flaws-let-hackers-steal-keychain-1password-contents/ http://arstechnica.com/security/2015/06/serious-os-x-and-ios...
- legulere 11y agoSo it's the old story that desktop operating systems lack process/application separation aka sandboxing.
- lisivka 11y agoI prefer hardware separation: just use old smartphone, without connection to internet, as password vault. No connection — no risk of stealing (except physical stealing, of course, so use _old_ ugly smartphone, e.g. with broken screen). Keep your important passwords encrypted with GPG on flash card, with backup on an another flash card. Regular GPG works flawlessly in terminal. Small shell script, which will ask for password and site name to display site password(s), will do the job on any Linux-compatible smartphone.
- smt88 11y agoThis would be really painful. Many of my passwords are more than 20 characters all over the keyboard, and I probably fill in passwords 20 times per day. Instead, I just use KeePass, which I protect with an offline SSH key as well as a strong password. In order to compromise my passwords, you'd need my KeePass database, access to one of my devices (laptop, desktop, but not phone), and my password.
- dwild 11y agoNot everything, my 2FA wouldn't be compromised and if I'm lucky, I would find the keylogger before using the passwords I use less often (bank accounts, servers key passwords, etc...). Personally I would like some sort of hardware password manager, it could even take care of my private keys. Hackaday tried to build something similar but it was too expensive and too bulky.