LastPass password manager suffers 'major' security problem

>LastPass password manager suffers 'major' security problem

independent.co.uk/life-style/gadgets-and-tech/news/lastpass-hack-security-problem-password-manager-a7658806.html

>LastPass users are being advised to avoid the password manager while it addresses a “unique and highly sophisticated” security issue.
>LastPass hasn’t revealed any further details about the problem, but Google’s Project Zero security researcher Tavis Ormandy, who discovered it, says it’s a serious one.
>“It will take a long time to fix this properly, it's a major architectural problem,” he tweeted.
>we’d recommend disabling LastPass’ browser plugins, just to be on the safe side.

Other urls found in this thread:

blog.lastpass.com/2017/03/security-update-for-the-lastpass-extension.html/
twitter.com/taviso/status/845717082717114368
independent.co.uk/life-style/gadgets-and-tech/news/lastpass-hack-security-problem-password-manager-a7658806.html
ghacks.net/2016/11/22/keepass-audit-no-critical-security-vulnerabilities-found/
twitter.com/AnonBabble

HAHAHAHAHAHAHA

KeePass #1

>not using Master Password
>not being Master Race

but I'm lazy

I'd rather unlock a database once and have my username/emails and passwords available instantly

Why have these things?

I store my shit on my browser.

>I store my shit on my browser.

As you should. Some people are just too retarded to handle that though.

>we’d recommend disabling LastPass’ browser plugins, just to be on the safe side.

Lastpass has not said this

fake news
sage

Are you mentally retarded or just a fucking idiot?

blog.lastpass.com/2017/03/security-update-for-the-lastpass-extension.html/

Fucking mouth breather

>being this angry cause your shitty password manager got BTFO

>lie
>get called out
>try to damage control
>get called out with sources
>lol u mad bro?

Goddamn dimwit

Confirmed for retarded.

The idea of storing a password database in the cloud is completelly retarded.

Yes, indeed it is.

is there anything that can read the lastpass export and put it into a cleaner list?

Post your export and I'll clean it for you.

I don't know what the lastpass export looks like, but I would assume it could be cleaned up with a simple script.

Enjoy having a 13 year old with an install of darkcomet steal your banking info

Enjoy having down syndrome. Retard.

How so?

Is there a password manager where I enter all my passwords into it, it autofills websites on my PC, but I have to use the fingerprint scanner on my phone to do it?

You've have to be retarded to have darkcomet on your systme unchecked.

What is a crypter? Retardo.

>not using UNIX pass
Jesus fucking Christ is this board full of retards or what?

How can you be so profoundly retarded and still manage to continue breathing?

>it's a retard calling everybody else retards episode again

If you weren't such a newfag then you'd know this board is literally full of retards.

Avast sends a push notification to your phone.

...

Can't even compare to the glory of Master Password.

Pleb.

enjoy ur botnet

>literally offline
>botnet
You've exposed yourself as a complete retard.

>using a password manager and not memorizing unique random keyed passwords for everything

retards

>he thinks a company would actually tell you to stop using their software

Holy kek, you're fucking dumb.

>he doesn't know about the offline botnet
Holy shit this guy everyone

You've already outed yourself as a retard, there's no need to prove how retarded you actually are.

>calls others retard
>doesn't realize they are the true retard
really gets the ole noggin a joggin

Why would anyone use a password manager? It's seems like a fucking retarded idea to trust all your passworss with some idiot developers.

>2017
>Not keeping all your passwords encrypted manually onto a piece of paper in invisible ink and storing it in a bulletproof safe in a vault.

>makes an ironic shitpost about calling people retards
>doesn't realize he's profoundly retarded

really gets the ole noodle a doodling

>ctrl f "recommend" to see which one of you is retarded
>recommend not found
wew lad everyone in here is retarded

>invisible ink

Same reason Geek Squad can stay in business
Same reason OS X and iOS are popular

I like how every password manager thread always devolves into everyone calling each other retarded. I take it as proof that password managers are retarded programs made for retarded "people".

is 1password any better?

Easy way to boost personal security (i.e. avoiding shared, easily guessable, whatever passwords).

I'm not trying to fight off the NSA or anything, but now I have unique, """strong""" passwords for all the accounts I care about with little to no inconvenience to me.

Also for what it's worth, KeePass (and probably others) make it easy to change your passwords on a schedule if you desire.

Guess you can place lazy and retarded people in the same camp.

>Replies to an ironic shitpost
>Calls poster retarded
>Doesn't realize he in fact is the retarded one

Yes. Not worth it as individual, so get your whole family on it.

why not as an individual?

Whole family? Would my wife and her boyfriend and I count as a family?

Cause the more passwords in one place, the better. Trust me I'm an expert.

oh I see, you're an expert, thanks!

>using anything based on the ""cloud""
>especially trusting passwords on said """"cloud""""

What's the best way of creating unique passwords for every service you use without using a password manager?

the passwords don't leave your PC, only an encrypted container which is essentially random data

>the passwords don't leave your PC, only an encrypted container which is essentially random data

So is Keepass and it doesn't have this problem tho.

Memorizing a single password at least 32 characters long which was randomly generated.

This has nothing to do with the passwords on the "cloud" being broken, idiot. The plugin is where the problem is, and that could happen to keepAss too if it was integrated to the browser.

wow ur a rude dude

Keepass still doesn't have this problem tho.

sorry.

Use only emojis

We don't even know what the problem is though. It possibly could, we just don't know yet, or the project zero people haven't looked into it yet.

The problem could be anything from a leak in the browser plugin, to a failure at the encryption stage.

and it still doesn't have browser integration
#btfo

And before you say keefox, that plugin is spotty, doesn't work with firefox forks, is going to break with FF soon when xul is deprecated, and may very well have the same vulnerabilities as lastpass

>The problem could be anything from a leak in the browser plugin, to a failure at the encryption stage.
It's some kind of privilege escalation problem twitter.com/taviso/status/845717082717114368

Probably the browser plugin. Not the first time it has caused issues.

>independent.co.uk/life-style/gadgets-and-tech/news/lastpass-hack-security-problem-password-manager-a7658806.html
>“It will take a long time to fix this properly, it's a major architectural problem"

I don't think it's just the fucking addon from this quote, you fuck.

>and it still doesn't have browser integration

Who gives a shit? Never stopped me or anyone else using it. Does your mom still wipe your ass?

>and may very well have the same vulnerabilities as lastpass

Lol doubt it. Enjoy being wrong, again.

LASTPUSSY BTFO!

>I don't think it's just the fucking addon from this quote, you fuck.
>hurr hurr look at me I'm stupid
twitter.com/taviso/status/845717082717114368

>Lol doubt it. Enjoy being wrong, again.
Nobody has ever audited keefox because compared to lastpass, practically nobody uses it. It's probably full of holes a google-tier researcher could find.

I trust the developers of the dozens of KeePass programs even less than I trust LastPass at this point. Didn't one of them purposefully leave a MITM exploit unpatched for advertising money? There's a dozen other options for KeePass programs, but I have no idea how much outside scrutiny any of these programs has had.

I think I'm going to look into 1Password instead. They seem to have a pretty good track record.

1password is all closed-source so I would trust it even less with encryption

>trusting anybody or any software with your passwords
>not writing them down on a notepad
I seriously hope you guys don't do this

>hurr hurr look at me I'm stupid
>twitter.com/taviso/status/845717082717114368

Still waiting on you to prove your claim it's the addon.

>keefox

I don't use this and never mentioned it. You did, therefore, dropped.

>KeePass

Keepass passed an audit by the European union and found a couple negligible issues. I think I know what to trust.

ghacks.net/2016/11/22/keepass-audit-no-critical-security-vulnerabilities-found/

>Still waiting on you to prove your claim it's the addon.
Are you unironically retarded? What else would a privilege escalation vuln mean? Do you think he got codeexed on Lastpass servers?

>I don't use this and never mentioned it. You did, therefore, dropped.
No addon for you then, loser. I'd rather take the 0.000001% risk of the addon leaking something than laboriously copy-paste everything from a separate program tens of times a day

>Are you unironically retarded? What else would a privilege escalation vuln mean? Do you think he got codeexed on Lastpass servers?

Still waiting on you to prove your claim it's the addon.

>No addon for you then, loser

Don't care, it has autofill without addons. Mommy still wipe your ass then?

>Still waiting on you to prove your claim it's the addon.
It's either the addon or he hacked to the lastpass servers, which he didn't do, otherwise he would have said just that. Your IQ must be sub-80 so there's no point in me trying to explain this to you further, you won't get it anyway

So you can't prove your claim. Better luck next time sweetie.

>laboriously copy-paste
Who copy-pastes with KeePass? Just use autotype

>Who copy-pastes with KeePass? Just use autotype

Shhhh, he prefers using vulnerable plugins.

Does that include keepass2?

"site"passwordstring
Won't help if you're specifically targeted, but it will stop an automated attempt spamming your username/password from finding any other matches.

Vulnerable plugins that don't even work except on Windoze

>goto site
>find your keepass window
>search for the site you're currently at
>press ctrl-v
>wait for the slow auto-type to finish
vs
>goto site
>have the field filled out for you

It's regular keepass that had that issue, and the "MITM attack" is just the software letting you know an update is available

Because the reality of Internet security is that passwords are hot fucking garbage and you end up with the choice of either finding a convenient way to manage your huge passwords or not having secure passwords at all

That's an audit of the "official" Windows version of the old deprecated 1.x branch of KeePass. 2.x is a completely different codebase written in .NET of all things.

You haven't really thought this through, have you.

If you don't have a password manager, you probably have a few passwords that you use everywhere. About the best you can possibly do is maybe have a site-specific suffix, but if somebody owns a site and decrypts your password they can probably figure it out just by looking at it. "Oh hey, this one is hunter2reddit.com, I wonder if..."

Now, using a password manager isn't foolproof. The password manager itself can be a weakness, as LastPass has demonstrated. But that is one point of potential weakness, as opposed a potential weakness in literally every website you have ever created an account on.

Storing your passwords in the cloud for ease of use creates a second point of weakness - the cloud provider. However, the only thing that happens if the "cloud" gets popped (no matter if it's a cloud password manager like LastPass or if you store your KeePass data on Dropbox), is that the attackers now have tons of encrypted binary blobs that they have to decode, which takes time.

Password Managers are the best choice of a bunch of imperfect options.

>Keepass passed an audit by the European union
wow a bunch of kikes and other fat fucks in suits spending your money rubber stamped a seal of approval, thank god we have the EU pls fuck my wife mohammed

>storing passwords anywhere other than in your head
it's like you're asking to be compromised

>Using botnet pass
>Not using comfy KeePassX stored in your OpenBSD desktop.

Get raped and kill yourself, you retarded kike loving fucking faggot sack of ugly nigger shit with down syndrome.

Your head can be compromised with a pipe wrench, some pliers, and a car battey

I'm going to delete this anyway because it keeps undeleting logins I deleted for sites like twitter where I lick to troll, so I have lots of them

The only websites that matter have 2-tier mobile authorization (FB, VK, GitHub, Gmail, Skype, anything money related etc.) and I use 20 character pass there. All the other sites are worthless, I use same 6 character password there, because I don't care for them.

>Shill spreads FUD about well known FOSS password manager
>Proceeds to recommend close source password manager that no one has hear about

I hope you are getting paid.

>Not remembering your password in anno domini 2017

Cucked

>Using password managers at all
I though Sup Forums was smarter than this

LOLL

KeePass master race reporting in.

LastPass sucks dick