4 ms·
This points to what is actually quite a large problem with the LastPass vault. A lot of people I know (myself included) keep the password saved on the vault, so
by STRML 13y ago
This points to what is actually quite a large problem with the LastPass vault. A lot of people I know (myself included) keep the password saved on the vault, so that it will offer to AutoFill/AutoLogin when you visit a site you have an account on. It then is set to re-prompt for the master password to actually fill or reveal the site's password.
Unfortunately, passwords are retrievable out of the LastPass vault in exactly the same way as in the article. It is trivial to simply inspect the DOM and pull them out with some basic JS. This is unacceptable IMO and must be fixed; LastPass is barely functional if you don't keep it logged in. But if you do, all it takes is a right click and a few keystrokes to reveal each password.
I feel a lot worse about this product, now.
- giovannibajo1 13y agoThe correct way of using LastPass (or, actually, your computer) is to lock it if you leave it on the table or hand it to a friend. All hell break loose if you hand a logged-in computer to a friend, the security model of all operating systems don't account for that. If you follow this basic security principle, you can keep your LastPass vault logged-in, with a decent timeout (eg: 1 day).
- STRML 13y agoBreaking account locks on Windows is pretty simple, and full-disk encryption is not as easy to pull off as it is on OSX. If someone were to steal the computer, they would have as much time as they needed to break the Windows account and raid LastPass. What else could be the point of the master password reprompt, but to give the perception that your passwords are locked after an idle timeout? If it doesn't actually work, they shouldn't have the feature at all.
- giovannibajo1 13y agoI'm not suggesting to activate the feature that asks you to reenter the master password to USE a specific password. I'm suggesting that you force a logoff of your LastPass vault after inactivity. Using a laptop with full-disk encryption, I think 1-day logoff is more than enough for common scenarios (we're not speaking of NSA-going-after-you, as usual). If you're using a laptop without full-disk encryption, I'd agree that the best way is to configure LastPass to automatically logoff when the computer enters standby/hibernate (for enterprises, this kind of configuration can be enforced for all business accounts as a policy). That's still a much better compromise than having it always logged off and having to relogin for any password you use.
- emn13 13y agoHowever, if you do "break-in" without knowing the password you may gain access to most data, but not data encrypted with the user's auth; stored passwords (hopefully including lastpass stores) typically are therefore not accessible.
- ams6110 13y agoIn what way could any password manager both auto-fill login fields on a web form and also prevent DOM inspection from revealing the password? It seems flatly impossible to me.
- mschulkind 13y agoThis is not what is being claimed here. I do the exact same thing STRML with my lastpass vault. Lastpass has a bunch of fine grained access controls for when the password needs to be entered. Having your password saved on lastpass just lets you view your list of password, as long as you have it set to require the master password before accessing an individual password. Here is how the process goes for logging into a website with these settings: 1) Go to website 2) Click autologin 3) Type your master password 4) Lastpass fills in your password on the website and logs you in This clearly involves your master password before doing anything that would seem to reveal your individual website password. The problem here is that this would appear to be completely false as the article points out. Another way to get the password in lastpass: 1) Open the lastpass vault 2) Search for the target website 3) Click edit 4) Click the eye icon to show your password 5) Type in your master password 6) See the password Once again, exactly as you'd expect, and seems to require the master password before revealing anything. The problem is that you can replace steps #5 and #6 with (in chrome): 5) ctrl-shift-j (brings up dev console) 6) $('input[type=password]').setAttribute('type', 'text') And now your password is sitting there in plaintext without ever requiring your master password, despite telling lastpass to require your master password for any password access. I agree with the rest of the commenters that sharing a password with someone and expecting it to remain secret is a bit foolish, but the problem I described here is a HUGE vulnerability. I'm going to seriously reconsider using lastpass ever again.
- city41 13y agoSo the LastPass vault itself is a web application? If that is the case, I'm a little flabbergasted. I use 1Password (not associated with them at all, just a reasonably happy customer). The 1Password app is a native application which as far as I know has no vulnerabilities like this.