3 ms·
Attacker doesn't need to control the login form to use it as an oracle to confirm password reuse.
by bbbbb5 4y ago
Attacker doesn't need to control the login form to use it as an oracle to confirm password reuse.
- tptacek 4y agoReuse of what? If you're assuming the attacker already has a valid password, the list of URLs they use it also irrelevant, as is the password vault. Just do what real attackers do and hit every single known login page on the Internet with it.
- bbbbb5 4y agoThat's exactly what I'm saying :) If the attacker doesn't have the valid password, the knowledge that two different sites share the same password isn't exactly game-changing. And if the attacker does have the password, they'll figure out where it works regardless of access to LastPass db.
- tptacek 4y agoIt's not nothing, and it's weird to be strident about it, but the obvious problem here is the offline cracking of the vault passwords; this isn't worth arguing about.
- bbbbb5 4y ago> It's not nothing, and it's weird to be strident about it To an outsider, hearing people talk about how LastPass used Very Bad ECB mode makes it sound like a fuckup with immediate and dramatic effect on the security of their passwords, that isn't exactly true. Nobody should have been using LastPass, but we can still be realistic about the threats facing those who did. > but the obvious problem here is the offline cracking of the vault passwords; this isn't worth arguing about. Of course not, but that's a completely separate issue from their choice of AES mode.