7 ms·
LastPass’ Authenticator app is not secure
- david-cako 9y agoWow, color me surprised. Software developers aren't perfect, and closed source software with less eyes on it tends to be even less perfect. I will never trust my passwords all being in one place other than my brain.
- BoorishBears 9y agoYou can't keep varied, secure passwords in your head unless you barely use any services.
- PakG1 9y agoThere are no good options until someone figures out a good alternative to passwords.
- exabrial 9y ago'U2F + password' is very secure and can't be phished if implemented fully. However, even Google doesn't do U2F correctly :( U2F authentication needs to happen _every_ time a new TLS session is established in order to be 100% phish proof
- david-cako 9y agoSomewhat true. I use abbreviations of several different long sentences with random characters added in random positions. To me this is far more secure than trusting a single authoritative source with 10 different random character strings that I have no real ownership of, and can all easily be stolen (or lost) at once.
- BoorishBears 9y agoI have at least 50 different passwords in my 1Password account And 1Password supports syncing via services other than their own and each device acts as its own backup too, so you’re really only relying on their service to shuttle around an encrypted keystore to your new devices.
- david-cako 9y agoOk, but the core of the argument to me is "Is having a bunch of passwords that you don't actually know all in one place more secure than having a smaller bunch of passwords that you do actually know that, still, can at most be leaked one at a time?" For me the answer is no. I would rather have fewer technically less secure passwords than have technically more secure passwords that all live in one place. My passwords live "nowhere". There is no database breach, or peek over the shoulder that could ever compromise my entire wellbeing. I also use 2fa wherever possible.
- BoorishBears 9y ago>Is having a bunch of passwords that you don't actually know all in one place more secure than having a smaller bunch of passwords that you do actually know that, still, can at most be leaked one at a time? It’s been repeatedly demonstrated that yes, it is.
- david-cako 9y ago>It's been repeatedly demonstrated Meaning you have consulted a sea of research that has compared the risk posed by password managers to keeping a mental catalogue of long, not-random-but-pretty-good character strings, using 2fa, and exercising proper security habits? I don't think you could ever come to an objective conclusion, since the 99%-user doesn't have a near-autistic obsession with security like most of us.
- BoorishBears 9y agoI don’t have an obsession with security, it’s just so easy and cheap that I don’t get why you wouldn’t do it (the people with an obsession with security probably don’t even trust 1Password to sync that encrypted file anyways) My mom, who is as far removed from tech as you can get, understands why not sharing passwords might be a good idea when one can get hacked and set of a domino effect. And your comparison is a straw man, the real comparison is trying to remember 50 random passwords to using a password manager because there is a sea of research showing that good passwords should be truly high entropy and random. Using a password manager doesn’t stop you from using 2fa like your comparison is worded to imply.
- rainieri 9y agoVery powerful and rich people already have the capacity to buy chips to be implanted in the back of their heads or around the neck area that permits them speak other languages. It's a matter of time before we get one to generate and or generate passwords. How they will function beats me.
- mandelbrotwurst 9y agoYou're right, but that doesn't mean he's better off with a password manager. No method of storage is perfectly secure. Password managers have their attack vectors, your brain has others.
- UncleMeat 9y agoThe attack vectors against password managers tend to be more rare and more difficult to exploit.
- alkonaut 9y agoMost people don’t use many services where security is important. It’s not uncommon to have several hundred accounts with passwords, but I have maybe 10 that I really worry about being hacked/lost. For all the crap sites I can just use $singlepassword+$servicename as password. For the few sensitive ones I use strong passwords and 2FA. I do use a manager to keep those strong passwords - but even though I have it, I can’t be bothered to use stronb passwords for all those forums, web shops etc. Is my solution secure? No. Using a bad password for hundreds of sites is definitely not secure - but the quality of a password only needs to be proportional to the sensitivity of what it protects.
- BoorishBears 9y agoWhen I started using a password manager I did something similar, but I told myself every site which used the "insecure" password was linked. So I'd ask myself "If someone hacked the least consequential site I've used this password on, they'd also have hacked this site, do I care?" It was very rare that the extra 30 seconds to add a new entry password manager wasn't justified after asking myself that question. I think it all comes down to ease. Yes, some secure passwords is better than none, but it's just soooo easy I'd just say go with the PM
- UncleMeat 9y agoThis "problem" has precisely nothing to do with open source vs closed source. "Tell me the list of activities that are public" and "tell me the name of each activity as I launch it" are babies-first-app-analysis level and work equally well on open and closed source apps. Are we really concerned about an exploit that requires somebody to have unlocked access to your phone?
- david-cako 9y agoI'm not saying that's the problem, I'm just suggesting that you have to have a lot of faith in a company to trust it with all of your passwords, especially when there's only a handful of eyes on its source code. It's not for me, personally. And yes, because the scariest aspect of password managers is the fact that you have basically shifted the responsibility of "I use the same password everywhere" to a different party.
- cannonedhamster 9y agoProve that open source has more eyes than closed source. You can't because in reality it's most likely not true for the vast majority of software. Most software requires an incentive to look over the code and the skill to do it. The incentive to do it for closed source is money, open source is warm fuzzies or personal interest. I really love open-source software but code review is clearly not a benefit for the vast majority of people.
- ufmace 9y agoGiven the recent number of cripplingly awful security bugs that have been found in open-source infrastructure projects (Shellshock, Heartbleed, etc) which have been in the wild for many years before being discovered, I'm rather less interested in arguments that open-source software is supposedly more secure than closed-source due to the number of eyes that are supposedly on it. When was the last time there were any security flaws of that magnitude in the Windows Server/IIS stack? The reality seems more like that even if anybody can look at the code, auditing security code well is damn hard, very few people can do it well, and those people basically never audit open-source projects in their spare time. How secure something is depends more on how battle-tested it is, how good the people who wrote it are, and how well and often it's been tested for security flaws by experts.
- darrmit 9y agoI can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.
- SubiculumCode 9y agoThat is a whole lot of opinion, but not much substance. What makes LastPass inferior to these other options?
- craftyguy 9y ago> What makes LastPass inferior to these other options? Well, for one, the very first sentence of the article here.
- strictnein 9y agoThe article whose "exploit" requires handing your unlocked phone to someone?
- SubiculumCode 9y agoAnd which just got revealed,and will probably be fixed.
- craftyguy 9y agoYou'd be surprised how many people (not on HN) use extremely weak (or no) unlocking mechanisms for their devices. It overlaps with the set of folks who would want to use LastPass because of how easy it is.
- saosebastiao 9y agoDo you know what is easier than using last pass for people who use weak unlocking mechanisms? Using the same password everywhere. I'd be surprised if there was any overlap at all where you claim.
- exabrial 9y agoProps for the responsible disclosure timeline
- zwerdlds 9y agoWell this is disappointing. In the past, LastPass seemed to have been receptive to patching these kinds of things. But no follow-up via email? Maybe it's time to start looking at other options.
- ComputerGuru 9y agoThe code, tech, and mindset behind LastPass is a joke. They started just after the “dark ages” of security but don’t seem to have upgraded their mental model of security since. I’ll share with you the moment I discovered something that made me cancel my schedule for the day, research alternatives, write a LastPass to 1Password converter [0], and cancel my LastPass account and subscription. Are you ready? You log in to their support forums and online community with the same password you decrypt your vault with. [0]: https://neosmart.net/blog/2017/a-free-lastpass-to-1password-conversion-utility/ https://neosmart.net/blog/2017/a-free-lastpass-to-1password-... EDIT: To answer some of the comments, since understandably not everyone is a security expert: What happens if LastPass’s web forum is compromised and all their additional security counts for nothing? Even if not: you have no problem with people being conditioned to enter the password securing all their passwords repeatedly into random pages for random content not related in any way, shape, or form to their vault in a web browser? Containment is the name of the game. It’s hard enough making one app secure enough to enter your password into. Then extending that with an SSO, relying on The security of none other than notoriously crappy phpBB, vulnerable to upstream code injections, XSS, phishing attacks, and god knows what else, and you still think you can trust them to keep your master password secure? LastPass is such a juicy target and this is such an easy attack vector that I can virtually guarantee at some point phpBB - or, more accurately, their abuse of it - will be a massive liability and the source of a huge catastrophe for them, if it hasn’t secretly already. Of course they know to treat changes to their authentication apps very carefully and code review each and every syllable added or removed (well, I hope so). But do they review upstream patches to the forum software they use? What about the third party template they have installed? Do they hold off on patches after a security bug is discovered in phpBB so they can review the code changes? Do they even upgrade their forums? What about a vulnerability in PHP itself? Do they secure the server hosting their authentication apps in the same manner as the server hosting their forums? Do their web developers undergo the same background checks and scrutiny their core developers undergo? How many sysadmins have access to the website? Do they provide the same access monitoring to people managing an ancillary feature like their forum software? The list just goes on forever. You’re as secure as the weakest link. All anyone that want to break into LastPass has to do is get some code into phpBB or the random phpBB themes and plugins they use and it’s game over for millions of LP users and billions of credentials worldwide. See the problem?
- strictnein 9y agoSo the moral of the story is don't let people install applications on your Android device? And the bigger moral is: don't hand someone your unlocked Android device and let them play with it for an extended period of time?
- willstrafach 9y agoYou are correct. Not sure why you were downvoted.
- zupzupper 9y agoLastPass produces two apps, the Password Manager and this Authenticator App, which looks like a 2FA competitor to Google Authenticator. The bug the article is detailing is in the Authenticator application, not the Password Manager application, which wasn't very clear to me on my first read.
- banachtarski 9y agoNow I'm confused. It says it in the title? Where might the confusion stem from?
- bitdivision 9y agoMost people will only use the password manager app. I didn't realise they make a different authenticator app and assumed that this was about the password manager.
- scarhill 9y agoIf people don't know that LastPass has a 2FA app, they might think LastPass Authenticator is the password manager app, and is affected by this bug. As a matter of fact, a number of commenters seem to think exactly that.
- banachtarski 9y agoRight but I guess to me "password management" and "authentication" are two entirely separate concepts (i.e. authorization vs authentication being separate English words). I can authorize someone to do something. I authenticate that a person is who he or she claims to be.
- Belphemur 9y agoThe combo username password authenticate the person as much as it authorize them to access the service. Different meaning but connected nonetheless.
- 9y ago
- scarhill 9y agoAs it happens, I switched from Google Authenticator to LastPass Authenticator a few days ago. The app has a feature that allows you to require a PIN or fingerprint in order to use it. That feature is disabled by default. (Note that Google Authenticator has no such feature.) As I understand it, this attack allows someone with access to my unlocked phone to install a activity launcher app and then generate 2FA codes without supplying a PIN or fingerprint. Actually, for my phone they wouldn't need to bother with the launcher app, because I didn't enable the additional fingerprint/PIN feature--it seems to reduce convenience while adding little security. Still, it's definitely a bug. They should either fix it or remove the feature so people aren't misled into thinking their two-factor codes are secure when they're not.
- chocolatkey 9y agoLineageOS users can enable Privacy Guard to protect google authenticator, which requires device credentials (pattern, finger etc.) to start app. Also don't put it on your homescreen
- pixelpp 9y agoLastPass is shit!
- ilyagr 9y agoI'm very confused about how bad this is, the article seems unclear. Does it allow malicious apps steal the OTA codes? Does it allow malicious apps to steal the keys used to generate the OTA codes? Does it allow a user to see the keys? Is it none of the above? All I get from the article is that the user might be able to see the OTA codes in a roundabout way. If that's the entire problem, why is it a problem?
- willstrafach 9y agoIt is difficult to understand, but it seems like the app normally has some sort of PIN protection in order to open it. This is apparently a bypass method for that protection. Maybe I am misunderstanding, but it really does not seem like much of a big deal, as someone would need to have your phone in hand as well as your lock screen passcode. The title seems pretty dishonest, if my interpretation of this issue is correct.
- mankash666 9y agoThe worrying bit is LastPass' inaction since July 2017, when they were notified of the issue. For a product whose aim is to secure your credentials, this is a lax attitude to security
- dzhiurgis 9y agoI accidentally cought LastPass doctoring their terrible track record of security in wikipedia: https://news.ycombinator.com/item?id=15756044 https://news.ycombinator.com/item?id=15756044 This was just over a month ago, and published only here.
- slumberlust 9y agoI looked at your post, are you referencing the removal of the entire vulnerabilities section on the grounds that it was promoting Tavis?