TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

LastPass’ Authenticator app is not secure

116 点作者 codeka超过 7 年前

11 条评论

zupzupper超过 7 年前
LastPass produces two apps, the Password Manager and this Authenticator App, which looks like a 2FA competitor to Google Authenticator.<p>The bug the article is detailing is in the Authenticator application, not the Password Manager application, which wasn&#x27;t very clear to me on my first read.
评论 #16019405 未加载
评论 #16016536 未加载
dzhiurgis超过 7 年前
I accidentally cought LastPass doctoring their terrible track record of security in wikipedia:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15756044" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15756044</a><p>This was just over a month ago, and published only here.
评论 #16022078 未加载
darrmit超过 7 年前
I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it.<p>So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.
评论 #16016054 未加载
评论 #16018242 未加载
评论 #16016414 未加载
评论 #16016158 未加载
评论 #16016038 未加载
评论 #16016020 未加载
评论 #16016332 未加载
评论 #16016070 未加载
评论 #16016400 未加载
评论 #16016069 未加载
评论 #16016566 未加载
ComputerGuru超过 7 年前
The code, tech, and mindset behind LastPass is a joke. They started just after the “dark ages” of security but don’t seem to have upgraded their mental model of security since. I’ll share with you the moment I discovered something that made me cancel my schedule for the day, research alternatives, write a LastPass to 1Password converter [0], and cancel my LastPass account and subscription.<p>Are you ready?<p>You log in to their support forums and online community with the same password you decrypt your vault with.<p>[0]: <a href="https:&#x2F;&#x2F;neosmart.net&#x2F;blog&#x2F;2017&#x2F;a-free-lastpass-to-1password-conversion-utility&#x2F;" rel="nofollow">https:&#x2F;&#x2F;neosmart.net&#x2F;blog&#x2F;2017&#x2F;a-free-lastpass-to-1password-...</a><p>EDIT:<p>To answer some of the comments, since understandably not everyone is a security expert:<p>What happens if LastPass’s web forum is compromised and all their additional security counts for nothing?<p>Even if not: you have no problem with people being conditioned to enter the password securing all their passwords repeatedly into random pages for random content not related in any way, shape, or form to their vault in a web browser?<p>Containment is the name of the game. It’s hard enough making one app secure enough to enter your password into. Then extending that with an SSO, relying on The security of none other than notoriously crappy phpBB, vulnerable to upstream code injections, XSS, phishing attacks, and god knows what else, and you still think you can trust them to keep your master password secure?<p>LastPass is such a juicy target and this is such an easy attack vector that I can virtually guarantee at some point phpBB - or, more accurately, their abuse of it - will be a massive liability and the source of a huge catastrophe for them, if it hasn’t secretly already.<p>Of course they know to treat changes to their authentication apps very carefully and code review each and every syllable added or removed (well, I hope so). But do they review upstream patches to the forum software they use? What about the third party template they have installed? Do they hold off on patches after a security bug is discovered in phpBB so they can review the code changes? Do they even upgrade their forums? What about a vulnerability in PHP itself? Do they secure the server hosting their authentication apps in the same manner as the server hosting their forums? Do their web developers undergo the same background checks and scrutiny their core developers undergo? How many sysadmins have access to the website? Do they provide the same access monitoring to people managing an ancillary feature like their forum software?<p>The list just goes on forever. You’re as secure as the weakest link. All anyone that want to break into LastPass has to do is get some code into phpBB or the random phpBB themes and plugins they use and it’s game over for millions of LP users and billions of credentials worldwide.<p>See the problem?
评论 #16016312 未加载
评论 #16016409 未加载
评论 #16016288 未加载
评论 #16016195 未加载
评论 #16016621 未加载
scarhill超过 7 年前
As it happens, I switched from Google Authenticator to LastPass Authenticator a few days ago. The app has a feature that allows you to require a PIN or fingerprint in order to use it. That feature is disabled by default. (Note that Google Authenticator has no such feature.) As I understand it, this attack allows someone with access to my unlocked phone to install a activity launcher app and then generate 2FA codes without supplying a PIN or fingerprint. Actually, for my phone they wouldn&#x27;t need to bother with the launcher app, because I didn&#x27;t enable the additional fingerprint&#x2F;PIN feature--it seems to reduce convenience while adding little security.<p>Still, it&#x27;s definitely a bug. They should either fix it or remove the feature so people aren&#x27;t misled into thinking their two-factor codes are secure when they&#x27;re not.
评论 #16020489 未加载
ilyagr超过 7 年前
I&#x27;m very confused about how bad this is, the article seems unclear. Does it allow malicious apps steal the OTA codes? Does it allow malicious apps to steal the keys used to generate the OTA codes? Does it allow a user to see the keys? Is it none of the above?<p>All I get from the article is that the user might be able to see the OTA codes in a roundabout way. If that&#x27;s the entire problem, why is it a problem?
评论 #16017197 未加载
zwerdlds超过 7 年前
Well this is disappointing. In the past, LastPass seemed to have been receptive to patching these kinds of things.<p>But no follow-up via email? Maybe it&#x27;s time to start looking at other options.
exabrial超过 7 年前
Props for the responsible disclosure timeline
strictnein超过 7 年前
So the moral of the story is don&#x27;t let people install applications on your Android device? And the bigger moral is: don&#x27;t hand someone your unlocked Android device and let them play with it for an extended period of time?
评论 #16017254 未加载
david-cako超过 7 年前
Wow, color me surprised. Software developers aren&#x27;t perfect, and closed source software with less eyes on it tends to be even less perfect.<p>I will never trust my passwords all being in one place other than my brain.
评论 #16015970 未加载
评论 #16016416 未加载
mankash666超过 7 年前
The worrying bit is LastPass&#x27; inaction since July 2017, when they were notified of the issue. For a product whose aim is to secure your credentials, this is a lax attitude to security