10 ms·
Please correct me if I am mistaken, but couldn't this have been implemented into an iframe that when ran could send the passwords to another remote server? If
by mcs 10y ago
Please correct me if I am mistaken, but couldn't this have been implemented into an iframe that when ran could send the passwords to another remote server?
If so, I am a little taken back by LastPass only offering $1,000 to the researcher that found and reported it for fixing. He or she could have taken a different path and resulted in this being used in some complex targeted attack against tech corporations via short-url redirect interstitial pages, or an ad network's javascript, etc. Given the potential damage, I'd say there is a missing zero or two on that reward amount, in my opinion.
- thrwawayask 10y agoHi, newbie sec researcher here. Just wanna ask, how do we actually ask for a bounty considering that sometimes the severity of the breach is BIG (this, Shell Access, etc). I really don't wanna ask the companies for money but it just seem so... underwhelming for me. (3 out of 3 rather big companies just gave some thanks)
- rando444 10y agoNo matter what it is, you don't just give someone something they didn't ask for, and then expect money in return. It would be like someone walking up to you on the street, handing you something they think is valuable, and then hoping that you'll want it and pay them for it. The first thing you should do is check and see if they have an official bug bounty, if they don't then contact them and ask them if they had one.. say something like "because you saw some things on their site that concerned you, but wanted to know if it was worth the time exploring further" .. this is assuming you already found something. The goal of this is to get them to try and offer a bounty. If they don't offer a bounty, then if you want to be responsible, you can just disclose their vulnerabilities to them, and accept whatever thanks you get. If you're explicitly doing what you're doing to try and get some money out of it, then your time would be better spent focusing on companies that have well published bug bounties.
- pmx 10y agoI was surprised by them giving such a tiny amount too. The potential damage to their users here is staggering. If this was used to grab someone's twitter,facebook,email,linkedin an attacker could take full control of their online presence :S
- maze-le 10y agoYes, my thoughts exactly. He could had made 100x that money on the black market, so no wonder we still have problems with 0days traded there. How long would you work for $1,000? Some days, a week, two? If you spend more than a week on this problem it seems not worth to report it... On the other hand, if you set the incentive for bug bounty too high I imagine all sorts of cranks pop up, that want to show off bugs that are not there, and resources will be bound to this task -- they have to be verified, and analyzed even if its a bogus report (and in the worst case it will not accomplish anything). Where is the middle ground?
- bluedino 10y ago> How long would you work for $1,000? Some days, a week, two? You might not work for long on a $1,000 problem, but other people sure will. College or high school students, people in a country with low salaries such as Ukraine...
- RangerScience 10y ago"You agree not to disclose the full amount awarded you as part of this bug bounty award contract."
- estefan 10y agoIf the full amount is <=1000 it's irrelevant what you're actually awarded for a bug as serious as this.
- RangerScience 10y agoOh, no - I mean, if you want to reward people fairly, but not get a stampede to your door, tell them to report a smaller bounty than was received. They can spread private word to their network (presumably, other people who are going to actually be correct) but still provide hooks to the public. Probably doesn't work out, but it's what came to mind as a way to deal with the balancing act.
- deleted 10y ago[deleted]
- hrrsn 10y agoSeems like LastPass' bounty program is a joke. Their max reward is $1,000. https://bugcrowd.com/lastpass https://bugcrowd.com/lastpass
- avlidienbrunn2 10y agoAt the time I submitted this, they didn't even have a bug bounty. Considering that, I think $1,000 is great :)
- k__ 10y agoThey sold their future. The next bug will be sold to the highest bidder.
- onion2k 10y agoPeople find and disclose bugs regularly even where there isn't a bounty. Most (at least 99.99%) developers don't want to see a useful, successful product fail even if they can personally gain from it. The likelihood that an exploit for Lastpass will be discovered by an attacker and sold to a nefarious actor is very small. Further to that though, we now know that this problem is fixed in LastPass. We don't know about other password managers. To that end, LastPass is now a better option than it's rivals.
- danieldk 10y agoTo that end, LastPass is now a better option than it's rivals. Only when you believe that all password managers are equally secure from the start. There are many reasons to believe that this is not the case. Storing passwords in a cloud service is quite a red flag. Then there is a former employee stating on Twitter that part of the codebase is very neglected: https://twitter.com/ejcx_/status/758081553712820225 https://twitter.com/ejcx_/status/758081553712820225
- v0x 10y agoI never understood why security-conscious people would choose to use a service (e.g. Lastpass) that stores all of your passwords in the cloud. Why not just use KeePass instead? Yes, it's a little bit more hassle, but all of the other password managers have been subject to serious exploits like the OPs that put people's data at serious risk of compromise.
- 10y ago
- y04nn 10y agoThe fact that LastPass consider that a flaw in their system that could have put them on their knees is only worth 1K is quite frightening if you are relying on them for your security.
- crdoconnor 10y agoExactly this. I'm abandoning them now.
- SaturateDK 10y agoI want an alternative, got a good one?
- ajdlinux 10y agoAny good alternatives for LastPass Enterprise-style multi-user sharing? (Apart from "don't use services that require you to share passwords for a single account". Alas.)
- winsome 10y agoMy team and I have been using 1Password Teams (https://1password.com/teams/ https://1password.com/teams/) for this. They also have a Families service if for some reason you want to do the same thing with family and friends.
- greenshackle 10y agoDoes it need to have Windows client? I'm guessing yes. If not there is [SFLVault](http://sflvault.org/ http://sflvault.org/)
- scandox 10y agoI've been using Pass for several months and I love it. https://www.passwordstore.org/ https://www.passwordstore.org/
- deleted 10y ago
- OneNoteIsFree 10y agoSpeaking as an end user- seeing that they provide no incentive to 'hackers' to help them instead of using this information otherwise, I'd say I'm inclined to not trust them.
- zaroth 10y agoNormally I like bike shedding about bug bounty payouts just about as much as complaints about paywalls. If you are going to go poking around someone's code for fun or profit, the terms of the bounty program are readily available [1] so you can't complain after the fact for earning the maximum payout. LastPass isn't Facebook, and they never claimed they would pay more than $1,000 even for a full compromise or RCE. On the other hand, using regexp to parse the URL when it's such an obviously security critical code path... just, why?! [1] - https://bugcrowd.com/lastpass https://bugcrowd.com/lastpass
- icebraining 10y agoyou can't complain after the fact for earning the maximum payout Why not? Sure, you can't accuse them of being dishonest, but why would simply announcing an action make it beyond reproach?
- K0nserv 10y agoThe concern with the low payout is that it's supposed to be a way to compensate white hat hackers and dissuaded them from going to the black market with security problems like this. Given the business that LastPass is in wouldn't you agree that it's extremely crucial they make sure white hat hackers are aptly compensated for serious problems they find? In fact I'd think it'd be reasonable for them to pay more than Facebook for certain classes of bugs(like this one). After all all your passwords are more valuable than your Facebook account.
- tptacek 10y agoNo, that is not at all what a bug bounty is meant to do. We are not expected to pay people to avoid them launching criminal conspiracies against us. The purpose of a bug bounty is to incentivize researchers to target specific pieces of software so that vendors can benefit from that attention.
- cloudjacker 10y agoWhat he's saying is "raise the bid" Your rationale would be a valid rebuttal in your world no matter what the amounts in question were. $500? Incentive! $50? Incentive!
- jrockway 10y agoLet's do a little calculation to see if the payout is worthwhile. Using something illegally means you run the risk of going to prison. Let's say there's a 1% chance you get caught, the prison sentence is 10 years, and the evil hackers will pay you $20,000 for your bug. Let's also say that you're a mid-career software engineer in the US, and over the next 10 years you expect to make $2M (after taxes). This means your expected outcome over 10 years is $20,000 + (0.99 * $2M) = $1.98M. With Lastpass's bounty you end up with $2.001M. With these assumptions, you should be paying Lastpass to find bugs in their software! Of course, if you're not in the US, you probably make a more reasonable salary (read: less), taxes are higher, and the risk of getting caught is lower.
- virtualwhys 10y ago> over the next 10 years you expect to make $2M (after taxes) That would be $300K per year pre-tax (assuming current 2016 tax rate of 33% for the 200-400K bracket). Is that really a normal mid-career salary? I need to change jobs if that's the case...
- superuser2 10y agoAt elite big-name tech companies in the Bay Area, if you're selling your stock as it vests, that might be a little high but in the ballpark.
- fulafel 10y agoIn most places doing gray/black-hat things rarely results in going to prison, especially for someone who hasn't been convicted before. https://en.wikipedia.org/wiki/List_of_computer_criminals https://en.wikipedia.org/wiki/List_of_computer_criminals paints a picture that prison time is mostly a US-only thing.
- teekert 10y agoIs it still illegal when Lastpass actually stimulates you financially to pry into their systems?
- 10y ago
- downandout 10y ago>If so, I am a little taken back by LastPass only offering $1,000 to the researcher that found and reported it for fixing. I am a lot taken back by it. This wasn't a minor bug. I don't care if $1,000 was the published maximum payout under their bug bounty program - for something like this, the payout needs to be representative of the damage that would have been done to their reputation had this bug been discovered and exploited by bad actors. Given that reputation is everything in this space, any well-publicized incident using this would have effectively rendered the company dead within days. Here's hoping they reconsider the award amount (though I'm certain they won't).
- Dwolb 10y agoSomething to consider is a mis-alignment of incentives. When LastPass gets breached, they're not directly responsible for what an attacker does with the passwords. When another site/service gets breached, they have to spend a lot of time making it right to the customer again (e.g. rolling back transactions, compensating for lost or stolen funds, etc.)
- pmarreck 10y agoHe could have basically killed LastPass, the company, if he didn't go white-hat. And caused all sorts of other mayhem that would also have been far more profitable for him. It does seem like an extremely low bounty for a security bug that severe. I mean, in a 100% libertarian world, this hole would have been put up for auction to the highest bidder and LastPass would have had to ensure they were the highest bidder in order to close up the hole and basically save their business.
- ghurtado 10y agoI don't think of the bounty as a reward for choosing not to break the law. Staying out of jail is the reward for not breaking the law; the $1000 is just a token of appreciation for someone that could have otherwise not bothered to report the bug.
- ktta 10y ago>Staying out of jail is the reward for not breaking the law I think it works the other way around.