New LastPass Bugs Could Have Been Used To Steal Users' Passwords

Tavis Ormandy showing LastPass exploit proof of concept

Tavis Ormandy, one of the security researchers from Google’s “Project Zero” group, has been looking for (and finding) vulnerabilities in popular password managers for the past few months. He recently found a new bug in LastPass’ extension that would have allowed attackers to steal any of your passwords saved via the service. Another similar-but-different bug was also reported in the utility's Firefox add-on.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • Dark Lord of Tech
    Tried it once , wasn't impressed.
    Reply
  • AC____
    That's why I switched to Enpass, much much safer.
    Reply
  • velocityg4
    You want a bigger bug I've mentioned to them. By default the password manager stays signed in. Rather than automatically signing out after inactivity or closing the web browser.

    For the average user this negates much of the security as anyone who has access to the computer has access to the passwords. Sure you can say that they can change the settings. The average user won't think to do that. Just getting them to use it successfully is a feat.

    There is a huge gulf between people that understand tech and those that don't. Most tech companies don't grasp this. What seems like a very simple concept to a technically minded person is fraught with complexity for those whom don't get it.

    Leaving a huge hole in the security like this and giving them the option to fix it themselves means it will never be fixed. They may as well just leave a piece of paper taped to their wall with a list of passwords. Which I see a lot.
    Reply
  • therealduckofdeath
    By default, LastPass does not stay signed in. In fact, LastPass gives you a double pop-up "are you sure you want to do this?" question when you tick the "always signed in" box.
    I've used LastPass Premium for a couple years now, and it is a really stable and truly platform agnostic service. It works as good on my Android as it does on my desktop and my Microsoft Surface. They have also been really quick with fixing issues reported, like the one in the article above.
    Reply
  • ddpruitt
    Been using LastPass for a few years. Tried KeePass but it won't do the job, I need to be able to sync across devices and LastPass does that without the extra hassle of needing to login to one app to sync keyfiles, open the updated keyfile and then finally loggin.

    They're also probed regularly and have a fast security fix response time.
    Reply
  • alextheblue
    19462099 said:
    That's why I switched to Enpass, much much safer.
    This black box is more secure than this other black box! Because they told me it was.
    Reply
  • dE_logics
    How 'bout you just encrypt your password file or sheet in openssl?
    Reply