3 ms·
With the recent security issues surrounding LastPass, it makes me wonder, is the bar set too low even for professional products? Does LastPass not do this testi
by oneJob 11y ago
With the recent security issues surrounding LastPass, it makes me wonder, is the bar set too low even for professional products? Does LastPass not do this testing on their own? Does LastPass not reach out to the security community and contract to have this testing done, proactively? I mean, these folks pulled this off in their 10% time...
- tajen 11y agoI don't know, how much is the security bug bounty on LastPass? $1000 according to Bugcrowd [1]. But what would be the right value? That's the only way we ensure it's economically more viable for hackers to resell their security leaks to LastPass than to pirates. An economic approach would claim that the total available bug bounty scheme must be worth the same as the potential stolen value of the contents, otherwise it's still valuable to exploit the leak rather than publish them. The only savings that LastPass can make is over the gap between insured value and their ability to not have leaks. [1] https://bugcrowd.com/lastpass https://bugcrowd.com/lastpass
- josefresco 11y agoI doubt most small businesses could afford a bug bounty that would exceed potential illegal profits from selling an exploit to bad actors. I don't think the economics work at any scale. Could Google, Apple or Microsoft even outbid a nation state seeking to purchase an exploit?
- nhstanley 11y agoNo, but I think as long as the bug bounties pay enough to keep someone comfortable (along with added notoriety/resume padding with it), you'll have enough moral people choosing to reveal them to the companies rather than bad actors. Maybe that's naive. $1k bucks though probably isn't that number. More like $50k or $100k for 0-day level stuff.
- emodendroket 11y agoWell, maybe, but states don't just have more resources to buy exploits; they also have more resources to devote to finding them in the first place.
- cookiecaper 11y agoStates are not really the buyers to be concerned about. In many cases, the state already has tools that give them enhanced access to target data, all the way up to the authority to obtain and execute warrants. The people that are really worrisome are private malicious actors.
- Someone1234 11y ago> With the recent security issues surrounding LastPass What security issues? This blog post isn't really new information (or surprising), and I cannot think of anything else. The biggest problem LastPass has had is that LogMeIn purchase them who a lot of people hate/distrust (myself included). The rest of your post is predicated on LastPass being of "low quality" because of supposed "security issues" so I invite you to point them out.
- MikeKusold 11y agoThey've been hacked multiple times now. https://blog.lastpass.com/2015/06/lastpass-security-notice.html/ https://blog.lastpass.com/2015/06/lastpass-security-notice.h... https://blog.lastpass.com/2014/07/a-note-from-lastpass.html/ https://blog.lastpass.com/2014/07/a-note-from-lastpass.html/ https://blog.lastpass.com/2011/05/lastpass-security-notification.html/ https://blog.lastpass.com/2011/05/lastpass-security-notifica...