4 ms·
Am I assuming in this case the engineer was using his home PC to work? This isn't unheard of in the industry, Engineers using BYOD devices or similar to work f
by LilBytes 4y ago
Am I assuming in this case the engineer was using his home PC to work?
This isn't unheard of in the industry, Engineers using BYOD devices or similar to work from home. But with a company with a risk profile as high as LastPass this seems _incredibly dumb_.
You would assume anyone with the keys to the kingdom was working on a company provided device, or any device that fits a compliance framework based on their own risk needs (which should be massive!).
E.g., endpoint management, AV/detection, FIDO2 with Yubikeys to access AWS as an admin and otherwise. Just a few off the top of my head.
- SOLAR_FIELDS 4y agoI could see this kind of sophisticated attack easily working on some random company with fairly lax BYOD policies. Makes sense, it was a rather sophisticated attack when you look at your typical medium sized company. But if your entire company and organization is built around keeping things secure, THIS is what brought you down? This isn’t getting owned by some unforeseen 0day, it’s just sloppy opsec.
- Johnny555 4y agoMy company isn't nearly as high profile or security focused and we're not allowed to use our own computers for any work related purposes,and our work laptops run threat detection software and we have a whitelist of software we're allowed to install. I'm surprised that LastPass's policies aren't at least that strict. My company has what I think is a big hole in this policy in that we're allowed to use our own phone for email, a few corporate apps (like Jira) and our corporate password manager (not LastPass), but IT doesn't do any management of phones (other than being able to wipe them remotely if you're connected to the company email server). I suspect that the company doesn't want to spend the money on giving everyone a managed phone.
- hackernewds 4y agoAs much as LastPass seems to be trying to pin this on a single engineer, and not a broad vuln, the fact that they have such lax policies around access management, especially for a password management system, tells me enough I need to know never to use them again. Waiting for the rebrand and the incoming lawsuits.
- victor9000 4y agoYeah, this is the equivalent of blaming an intern for nuking the prod database. Maybe they were careless of maybe that shouldn't be possible to begin with.
- BLKNSLVR 4y agoYep. The symptom being that a problem of this scale can be caused by a single engineer, which points to the root cause being deeper and potentially systemic. The question for future trust is: what's been / being done to prevent the same thing from happening again due to another single engineer?
- macrolime 4y agoThey answer that question directly here https://support.lastpass.com/help/what-have-we-done-to-ensure-lastpass-is-safe-to-use https://support.lastpass.com/help/what-have-we-done-to-ensur... TLDR;not much
- execveat 4y agoPreventing this thing from happening costs a lot of $$$, so pretty much everyone just "accepts the risk" seeing that probability of something like this happening to your company (during your tenure) is still super low. All companies with somewhat robust security posture I know have had a string of incidents in the past, that seems to be the only thing that can motivate to put $ in security.
- Johnny555 4y agoIt's not really very expensive to issue employees a laptop (which costs a percent or two of an engineers annual salary) and tell them "All work must be done on the work laptop, no personal files/software allowed on the work laptop". For a little more money, they can add active management of the work devices, but just keeping work and personal device use separate would have prevented this.
- trallnag 4y ago
- Bluecobra 4y agoIf your company uses something like Duo they still can do some security posture on mobile devices like prevent rooted/jail broken devices or have a minimum iOS/Android version. It’s also possible that the stuff mobile devices can access are walled off from the internal network with a DMZ or firewall.
- saghm 4y agoThe company I work for has a setup for a separate work profile on my phone, which I understand to have separation enforced at the OS level. The work profile has a separate set of apps installed that are limited to ones that the company sanctions, and even for stuff like web browsing, none of the state is shared if the same browser is installed in my default profile. From talking to coworkers with iPhones though, this doesn't seem to be an option now (not sure if iOS supports it but my company hasn't set it up or if this sort of thing isn't supported on iOS at all). This seems like a much better solution than giving people two separate phones or forcing people to hand over control of their devices to their employers, but I guess not enough companies want to do this enough for it to have become the norm.
- trollied 4y agoMy company fixed that by only allowing SSO login on company devices. Everything else is SSO. Systems that weren’t SSO-enabled were replaced.
- morelish 4y agoHow exactly can your IT department whitelist all software on your device? Are you using any build tools that install third party dependencies or are you using any development tools that do the same? Is your shell locked down so you can’t run command as a super user? I assume your IT just has a whitelist for some stuff but I can’t imagine actually being a developed without super user privileges. Unless your doing some sort of very controlled software development.
- metadaemon 4y agoI don’t think he’s necessarily working on his pc. He probably just had a shared LastPass account between work and his pc.
- wolfi1 4y agoas a devop a shared account mixing private and business? would be a security breach if you ask me
- metadaemon 4y agoI'm betting work gives him a free family subscription, ideally you'd have them as separate accounts, not sure how the local vault works under the hood in that situation.
- scarface74 4y agoThat’s absolutely no better.
- scarface74 4y agoThis is completely unheard of for any company with any level of security. I’ve worked for 60 person startups that wouldn’t allow this.
- bboygravity 4y ago> You would assume anyone with the keys to the kingdom was working on a company provided device, or any device that fits a compliance framework based on their own risk needs (which should be massive!). You mean one of those company devices that is so locked down that they are close to impossible to work on? Like if you need to install a new (part of) a toolchain, you need to go through IT which takes between 3 weeks and 6 months? But your deadline is next week and your manager doesn't care about your IT "excuse", so just use notepad and CLI (or your own PC where you can do in 1 day what would otherwise take you months). Those devices... yeah...
- marak830 4y agoAs someone who works in gaming FQA with crazy locked down machines - we get software installed if necessary. Don't paint everyone with that brush. We also have two PC's per desk(plus consoles) so that our clients software isn't exposed. I don't get how a company like LastPass didn't have basic security like this when a FQA with a whole bunch of semi literate (in IT security) has a ssytem setup.
- rwalle 4y agoYou are making things up. Such a company probably exists somewhere, but I yet need to hear someone telling me a big-name tech company is doing this.
- jhoelzel 4y agoi completly agree. Its not so hard to do MFA all the way down either