TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Backdoored password manager stole data from as many as 29K enterprises

178 pointsby vanburenabout 4 years ago

13 comments

1cvmaskabout 4 years ago
Just to clarify the title. It was not a deliberate backdoor on the part of Passwordstate. It was a supply chain attack. There is some history to their security holes (most of the known ones being patched).<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;juanandres_gs&#x2F;status&#x2F;1385689464329187329" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;juanandres_gs&#x2F;status&#x2F;1385689464329187329</a><p><a href="https:&#x2F;&#x2F;github.com&#x2F;NorthwaveSecurity&#x2F;passwordstate-decryptor&#x2F;blob&#x2F;master&#x2F;MORE_INFO.md" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;NorthwaveSecurity&#x2F;passwordstate-decryptor...</a><p>A potential issue in the password management space is that Francisco Partners (owner of NSO Group) owns Lastpass (and LogMeIn).<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;NSO_Group" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;NSO_Group</a><p><a href="https:&#x2F;&#x2F;www.globenewswire.com&#x2F;news-release&#x2F;2020&#x2F;08&#x2F;31&#x2F;2086214&#x2F;0&#x2F;en&#x2F;Francisco-Partners-and-Evergreen-Coast-Capital-Complete-Acquisition-of-LogMeIn.html" rel="nofollow">https:&#x2F;&#x2F;www.globenewswire.com&#x2F;news-release&#x2F;2020&#x2F;08&#x2F;31&#x2F;208621...</a><p>Note: I work in the IAM and PAM space and designed dashboards for saas pass.
评论 #26928747 未加载
评论 #26931898 未加载
cillian64about 4 years ago
Passwordstate doesn’t seem to have automatic update and the update process is mildly annoying, so I can’t imagine very many people were unlucky enough to update during the couple of days they were compromised.<p>Not saying this isn’t very concerning from Click Studios, just that the number is going to be a lot smaller than 29,000.
lmilcinabout 4 years ago
That&#x27;s why I don&#x27;t use password managers. That&#x27;s giving one entity too much power over everything I own.
评论 #26929234 未加载
评论 #26931006 未加载
评论 #26931297 未加载
评论 #26931733 未加载
627467about 4 years ago
Why would any &quot;enterprise&quot; customers trust closed sourced AND small-time password manager?
评论 #26929046 未加载
评论 #26929007 未加载
评论 #26928942 未加载
评论 #26930726 未加载
nprateemabout 4 years ago
I run Keepassxc in a VM with no networking enabled, and no networking stack enabled in the VM. The clipboard is shared 2-way with the host. I keep the DB on a shared volume so it can be backed up by the host machine.
crispyambulanceabout 4 years ago
Nothing is ever perfect. Password managers are good thing and vastly more pragmatic than the folksy homemade &quot;nuclear-launch-code&quot; alternatives some HN&#x27;ers describe here.<p>Sticking with my password manager.
crypticaabout 4 years ago
These days I generally don&#x27;t trust any security product. They are as much malware themselves as the malware which they claim to protect you from.<p>- Many security software providers are hackers or ex-hackers... So you&#x27;re basically paying hackers to protect you from themselves. Why should I trust software which is almost 100% guaranteed to have been written by hackers more than any other random software I might download from the internet which has maybe a less than 1% chance of having been written by a hacker?<p>- The software security industry is more about selling security products than actually helping to keep people and companies secure. The incentives are to sell peace of mind while keeping systems vulnerable (don&#x27;t kill the goose that lays the golden eggs).<p>- Most security products capitalize on fear rather than genuine threats (security tools tend to show lots of false positives to draw attention to themselves or to upsell additional software).
评论 #26929680 未加载
评论 #26931283 未加载
schlotziskabout 4 years ago
The post is linking to the comment section of the article. Can you strip the URL of the query string?
评论 #26928813 未加载
afpxabout 4 years ago
My password manager: a mental hash of some site attributes, my username, and a security level that results in a valid password.<p>A particularly-motivated attacker could easily reverse engineer my hash algorithm, given enough samples. But, good enough for me.
评论 #26931230 未加载
评论 #26930336 未加载
_wlduabout 4 years ago
Related: <a href="https:&#x2F;&#x2F;www.go350.com&#x2F;posts&#x2F;the-design-flaws-of-password-managers&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.go350.com&#x2F;posts&#x2F;the-design-flaws-of-password-man...</a>
shravan20about 4 years ago
a trend, ain&#x27;t it?
tediousdemiseabout 4 years ago
The best password manager is your own salting algorithm and memory.
评论 #26929274 未加载
评论 #26929433 未加载
crypticaabout 4 years ago
That&#x27;s why I never used and will never use a password manager... You can&#x27;t get more security by trusting more intermediaries with your passwords. When it comes to anything that matters, you want to trust as few intermediaries as possible.<p>The more entities have access to your passwords, the less secure you are. I can&#x27;t believe I even have to say it, it seems so obvious.<p>Why not just remember your passwords? There is an infinite number of strategies and secret rules which you can use to easily remember your passwords.<p>Or for low-importance services, why not just use your browser&#x27;s built-in password manager? You have to trust the browser maker anyway.
评论 #26929446 未加载
评论 #26931328 未加载