6 ms·
Disclosure: I work for AgileBits, makers of 1Password. For browser extensions, the URL constructor would be even easier: https://developer.mozilla.org/en-US/do
by jxpx777 10y ago
Disclosure: I work for AgileBits, makers of 1Password.
For browser extensions, the URL constructor would be even easier: https://developer.mozilla.org/en-US/docs/Web/API/URL/URL https://developer.mozilla.org/en-US/docs/Web/API/URL/URL (Yes, I know it says that IE doesn't support it, but IE doesn't have a proper extensions framework, so it's irrelevant to this topic.)
- tedmiston 10y agoWhile you are here, can you confirm whether a similar regex vulnerability does not affect 1Password?
- kordless 10y agoWhat you are really "asking" is logically equivalent to this blaming statement: "I see you are posting about LastPass' vulnerability, but you work for 1Password. Please confirm there exists a regex vulnerability in 1Password which is similar in nature to the one that occurred with LastPass." Put this way, the insanity of the statement is obvious. In questions, it becomes less obvious to the majority of the population, which only serves to spread the insanity to others. Don't feed the fear with dissonance. Edit: It is NOT "reasonable" to ask questions with negation in them which assume blame in a piece of software which is, by a rather large assumption, a completely different code base. Reason is based on logic. This question was based on fear and uncertainty, and only serves to spread it further. You downvoters can go fuck yourselves.
- XMPPwocky 10y agoI see no need to read that into it. It's a reasonable question. Sounds like they just want to know if they, as a 1Password customer, could be affected. A little misguided, but a reasonable question.
- matt_wulfeck 10y agoOr maybe he's just curious if this type of url regex fail is more widespread among similar software.
- kordless 10y agoThen say that as a hypothesis and stop asking leading questions (which are blaming in nature) from people who make it their business.
- tedmiston 10y agoWhile this is something I'm generally curious of, especially with regex vulnerabilities being such a hot topic in software right now. See, for example, the regex issue last week that caused Stack Overflow to go down [0]. That aside, my concern stems solely from being a 1Password customer. [0]: Stack Overflow Outage Postmortem https://news.ycombinator.com/item?id=12131909 https://news.ycombinator.com/item?id=12131909
- tedmiston 10y agoHere's some context: I am a former LastPass user for many years and current (concerned) 1Password user wondering if I should be changing all of my passwords again. My goal was to settle concern for myself and other 1Password users. That's why I wrote whether a similar vulnerability "does not affect 1Password" instead of "does". My apologies if this was unclear.
- balls187 10y agoWhy did you switch from LastPass to 1Password? I recently started using LastPass after years of reusing the same uncrackable password: !p@ssword123
- cloakandswagger 10y agoI've been using LastPass for years now, but I'm starting to explore other options. For me, the biggest pain point is the interface. The automatic form filling rarely works as it should; I click the LastPass icon in the username field, select the site, and it only populates the username (even though there is an input with type="password" right below it). I then have to: 1) Press ALT+W to bring up the LastPass site search 2) Type in the domain name 3) Find the correct entry, and then click "Show Password" 4) Use my mouse to highlight the password and copy it (there is no quick way to copy the password) 5) Close the tab, go back to the original site, put my cursor in the password field and paste it And then I have to worry about what password I may or may not have lingering in my clipboard. If anyone has a better workflow please let me know. I'm envious when I watch coworkers use 1Password to populate a form in two steps using hotkeys.
- benologist 10y agoI use 1Password like that. I'm starting to explore other options because I'd much rather pay for open source software. Dropbox and 1Password are the only proprietary software I really depend on... cause it's 2016 and everyone else got the memo, even Microsoft is changing.
- ufmace 10y ago
- webXL 10y agoI was about to downvote after reading your edit, but part of me likes that attitude. That you're so passionate about your objection actually helped me arrive at the same conclusion. That and my own thought: Why would a developer come on here to suggest a fix if they weren't aware of this potential security flaw? There are appropriate channels to ask questions like that and appropriate times to downvote. But, hey, I'm not here to offend the hivemind. Please have mercy ;)
- sctb 10y ago> You downvoters can go fuck yourselves. Please don't do this on Hacker News.
- kordless 10y agoI save downvotes for truly awful comments made in a blaming way. If a comment I've made is non-blaming, yet addresses the more uncomfortable bits of reality, I fully expect to be downvoted. In this case, within several minutes I was at -2, even when there was no "fuck yourselves" in the post. Interestingly enough, when I added it, there appeared to be more commenting occurring. While I would agree that this place would be better off without judgment, and harsh judgment as I've shown here, the reality is that we all share this place equally with others who do not stop and consider their actions as affecting others thought processes in a negative way. I put this on here to illustrate that point in a non-obvious way, and in a way people CAN understand: anger. It's not the only way of course, but it does get the bug into people's brains quite well. I appreciate your comment and intent behind it.
- tripzilch 10y agoInteresting view on the matter, even if I don't quite agree with your prev comment (too tired now to argue why, sorry). I very much agree that downvoting without comment (indeed except for the truly awful ones that would just draw needless noise because of it) is an anti-pattern. But I am occasionally guilty of it myself as well, partly because writing a reply to a not-quite-awful comment costs me a lot of time (even if it's a short cmt). The greying-out of downvoted comments doesn't help with the perception of receiving a downvote without comment either (makes it feel more harsh, IMO). I'd prefer showing the counts again, actually.
- gpvos 10y agoIt happens often enough that a comment gets downvoted initially, and then gets sympathy upvotes from people who don't find it bad enough to be voted down. It may help to wait a few more minutes.
- throwanem 10y agoWhy not take a look at the code injected by 1Password's browser extension and find out for yourself whether it handles URLs safely? That shouldn't be hard to do, and it's a lot healthier for the community than discouraging devs to participate by taking their presence as an opportunity for drive-by pot shots.
- tedmiston 10y agoI'm sorry, but I don't see how asking an employee of the company that makes the product that I use every day is "discouraging devs to participate by taking their presence as an opportunity for drive-by pot shots". I think an official word holds more clout and is more valuable than any one person confirming for themselves in one version of one browser on one version of one OS.
- throwanem 10y agoI did speak rather harshly in my prior comment, and for that I apologize. Worse, I did a very poor job of expressing the concern that motivated me to respond. But I think it's still fair to ask whether your initial comment has value. I understand that, as a user of 1Password's browser extension(s), you may well feel some concern that a similar vulnerability exists, and I don't think it's unreasonable to want reassurance on that score. But I think your phrasing and framing of the question feels a lot more like a "gotcha" than anything else, and it's that feeling which motivated my prior comment - I'm not an AgileBits dev myself, but if I were, I'd feel strongly inclined to shy away from that question rather than trying to frame an answer that doesn't leave me open to a potentially hostile followup.
- jamie_ca 10y agoNot a dev on either product, but I use 1Password for my personal accounts, and a corporate LastPass for my work accounts. I do not believe that 1Password is as immediately vulnerable as LastPass. LastPass (on Chrome) will auto-fill information on a detected site, which a malicious site can read immediately. 1Password (on Chromium nightly) requires me to hit the 1Password Mini button and select a site/account to log in with. If 1Password had a similar vulnerability, a malicious site as described would merely wind up showing me accounts for the wrong site in the dropdown. Clicking one could wind up submitting/leaking my credentials to the attacker, though.
- notJim 10y ago1Password doesn't auto-fill, but you can press [Ctrl|CMD] + \ to fill in the password automatically based on the detected domain.
- unfletch 10y agoIt does have an "open and fill" feature which autofills, but only immediately after opening the site by URL first. (So the attacker's URL would have to be saved in 1Password along side your credentials.) This is actually how I use 1Password most often. Global hotkey of cmd+opt+\, type a site name, hit enter: 1Password opens the site and logs in.
- ruipgil 10y agoIf they're not using regex, they can't be affected by it anyways
- K0nserv 10y agoI had a quick look at the 1Password chrome extension source and it seems to me like they are using window.URL[0]. See this pastebin[1] for the function I believe is determining the url of the active tab and if it has a valid hostname. There's also this one[2] that seems to be extracting the hostname of a given url also using the URL API. Both these pastebins contain minimized code that I've cleaned up. 0: https://developer.mozilla.org/en-US/docs/Web/API/URL https://developer.mozilla.org/en-US/docs/Web/API/URL 1: http://pastebin.com/tWns7XmG http://pastebin.com/tWns7XmG 2: http://pastebin.com/PXS1iqsq http://pastebin.com/PXS1iqsq
- cyberpanther 10y agoURL constructor looks great! Just wish it was stable. I normally don't have to worry about IE very much anymore anyways.