7 ms·
Fake LastPass password manager spotted on Apple's App Store
- deleted 3y ago[deleted]
- fsniper 3y agoIsn't this the "App Store" that they are gate keeping for this kinds of threats?
- chrisjj 3y agoPerhaps the Store found no threat? Do note that this article fails to actually identify any threat here.
- tailspin2019 3y agoIt's not difficult to imagine possible threats just by looking at the comparison screenshots alone: https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/ https://blog.lastpass.com/2024/02/warning-fraudulent-app-imp...
- chrisjj 3y agoApp Store does not ban an app for threats imagined from viewing a competitor's screenshots.
- lapcat 3y agoApple has removed the app from the store: https://techcrunch.com/2024/02/08/a-fake-app-masquerading-as-password-manager-lastpass-just-got-pulled-from-the-app-store/ https://techcrunch.com/2024/02/08/a-fake-app-masquerading-as...
- chrisjj 3y ago> Apple has removed the app Fake news. Article does not say Apple removed it. On the contrary: "whether by Apple or the fake app’s developer is yet unclear — Apple has not commented."
- Pfhortune 3y ago> Do note that this article fails to actually identify any threat here. From the article: > ...the app was likely created to act as a phishing app and steal credentials. > If you have installed the fake LastPass app, you should immediately remove it and change your password at lastpass.com. It is then advised to perform the arduous task of resetting all passwords stored in your LastPass vault to be safe. Though one could argue that they have not _definitively_ proven that this app is a threat through testing, it really is not much of a stretch of the imagination that a LastPass-lookalike would be used for phishing. This app is very clearly an illegitimate clone.
- chrisjj 3y ago> ...the app was likely created to act as a phishing app and steal credentials. That a fear, not a threat. > Though one could argue that they have not _definitively_ proven that this app is a threat Why bother arguing that? They haven't claimed any evidence, let alone proof. > it really is not much of a stretch of the imagination that a LastPass-lookalike would be used for phishing. App Store rightly does not ban apps on stretches of imagination.
- lapcat 3y ago> App Store rightly does not ban apps on stretches of imagination. Apple has removed the app: https://techcrunch.com/2024/02/08/a-fake-app-masquerading-as-password-manager-lastpass-just-got-pulled-from-the-app-store/ https://techcrunch.com/2024/02/08/a-fake-app-masquerading-as...
- chrisjj 3y ago> Apple has removed the app Fake news. Article does not say Apple removed it. On the contrary: "whether by Apple or the fake app’s developer is yet unclear — Apple has not commented."
- lapcat 3y agoApple never comments on that, but somehow magically every single time a scam app makes the news media, the app disappears from the App Store.
- phmqk76 3y agoAnd yet Apple removed it after it was publicized, so…
- chrisjj 3y agoThere is no evidence Apple did.
- phmqk76 3y agoCircumstantial evidence is still evidence, Chris. The fact that it was no longer available on the store tends to imply that Apple removed it. Especially since the alternative is that the developer, who clearly acted in bad faith publishing an app masquerading as another app for the purpose of tricking people into making that developer profit, pulled it himself. You can put on your big boy deductive reasoning hat and draw a pretty reliable inference. Or you can simply read: https://www.pcmag.com/news/beware-theres-a-fake-lastpass-app-on-apples-app-store https://www.pcmag.com/news/beware-theres-a-fake-lastpass-app... UPDATE 2/9: Apple has removed the "LassPass" app from its App Store and also pulled the app's developer from its developer program, the company confirms to PCMag. Apple says it has also received a trademark dispute against the now-removed app.
- chrisjj 3y agohttps://www.pcmag.com/news/beware-theres-a-fake-lastpass-app-on-apples-app-store https://www.pcmag.com/news/beware-theres-a-fake-lastpass-app... That (belatedly) is evidence. Thanks. So much for the claim hereabouts that Apple never comments on removals...
- sccxy 3y agoBut Apple said their App Store is so safe that you do not need to worry about these kind of scams
- sunnybeetroot 3y agoSafer than allowing unregulated app stores to exist where an abundance of fake LastPass apps can be found I imagine.
- mdaniel 3y agohttps://play.google.com/store/search?q=lasspass&c=apps&fpr=false https://play.google.com/store/search?q=lasspass&c=apps&fpr=f... shows that Parvati Patel didn't even have the forethought to submit to multiple stores, for maximum phishing. Or, from Apple's perspective, worse may be that they did submit it and Google either caught it or its review cycle is so hopelessly borked it didn't outrun the news coverage. Hard to tell who is the most facepalm of all these actors
- function_seven 3y agoIn the unregulated scenario, you at least know the score. In the current scenario, you have a false sense of security that this must be the real deal, because Apple reviews the app submissions.
- ryan29 3y agoThe problem with app stores is that they sell the idea of verifying trustworthiness when the really can't. The biggest effect they can have is by doing identity verification and they make the same mistake that EV TLS certificates, etc. did. That mistake is assuming business names and trademarks are unique. They're not. The entire software distribution industry could use a mulligan. I think it should start by using domains as identity because it's the only namespace we have with global buy-in and anyone can register / reserve a unique identifier (aka domain) in that system. If the supply chain for that app went back to 'lastpass.com', and that information was prominently displayed, it solves a lot of problems in terms of educating users to help them avoid scams.
- tailspin2019 3y agoHow, in the utter fuck, does this get past app review? It’s not like it’s an edge case either, there are hundreds of apps with obviously and blatantly misleading logos, brands, names etc. Just see ChatGPT / OpenAi for example. I have taken to sharing direct links to Apps in the app store now when recommending things to non-technical friends/family, because I’ve lost all confidence that they will find the “correct” app anymore just by searching, and not one of hundreds of highly dubious clone apps. Difficult to argue against the recent actions of the EU when the supposed benefits of the walled garden are crumbling anyway…
- mdaniel 3y agoAlso, I somehow got the impression that one needed to provide Apple with live credentials to exercise any cloud service that the app fronts; so that makes me wonder if the malicious actor bought a LastPass subscription just to allow Apple to phish themselves?
- donmcronald 3y agoI wouldn't be surprised. The issuers of code signing certificates used to ask the person getting the cert to provide links to public registries of business / phone number listings. I had it happen to me. A lot of the "security" industry is a big scam designed to take your money. Many of the products they sell don't work because they don't have the ability to filter out bad actors. What's the value of a code signing certificate if someone can spin up a company in a corrupt country and get an EV code signing cert for that businesses? The answer is $0.
- euroderf 3y agoDoes not the word review in sentence one needs irony quotes.
- sccxy 3y agoYeah, and my app got rejected because it links to other webpage...
- deleted 3y ago[deleted]
- chrisjj 3y ago>> close examination of the posted screenshots reveal misspellings and other indicators the app is fraudulent Misspellings indicate fraud?? Good grief.
- chrisjj 3y ago> LastPass is warning that a fake copy of its app is being distributed on the Apple App Store Fake news. LastPass's warning does not claim the other app is a fake copy.
- Pfhortune 3y agohttps://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/ https://blog.lastpass.com/2024/02/warning-fraudulent-app-imp... > LastPass would like to alert our customers to a fraudulent app attempting to impersonate our LastPass app on the Apple App Store. The app in question is called “LassPass Password Manager” and lists Parvati Patel as the developer.
- chrisjj 3y agoYup. No fake copy claim there. And the claim of fraud is unsubstantiated.
- lcnPylGDnU4H9OF 3y ago> No fake copy claim there. What would you consider to be such a claim? The part they quote seems to explicitly call out the other app as being a fake copy when they call it "a fraudulent app attempting to impersonate our LastPass app". > And the claim of fraud is unsubstantiated. You seem to be asserting that there is no such claim. What are you trying to say?
- chrisjj 3y ago> What would you consider to be such a claim? "The app is a fake copy." > The part they quote seems to explicitly call out the other app as being a fake copy when they call it "a fraudulent app attempting to impersonate our LastPass app". Explicit would be "fake copy". This callout does not even claim successful impersonation. > You seem to be asserting that there is no such claim. On the contrary, there is such a claim. What I said was is the claim is unsubstantiated.
- phmqk76 3y agoApple: Our devices must remain walled gardens so only the highest quality, legitimate apps are able to be installed. And we require a 30% rent on every transaction for the purpose of maintaining the integrity of our garden. Also Apple: Lets in thousands of scam apps as a matter of course
- DougN7 3y agoThis is my biggest fear - that my password app is hacked. What if the real LastPass (or KeePass, or whatever) dev had a gun held to his head to add code to upload credentials to somewhere, and then signs and uploads the legitimate app. Open source doesn’t help - dev just doesn’t check in the changes. Reproducible builds and open source help in theory, but how many people go to that length if it’s even possible? I don’t.
- deleted 3y ago[deleted]