HN user

pwman

132 karma

You do what with passwords? You need to try LastPass.com

Posts2
Comments58
View on HN

That's not how AppArmor works provided you lock down your server software properly -- say the server running is NTP -- that NTP server is only able to read /etc/ntp/* and /usr/sbin/ntpd only able to write /var/log/ntp* only able to execute /usr/sbin/ntpd Now you've radically limited what an exploit of this particular server can mean.

Interesting, I hadn't heard of Password Alert -- we should definitely share notes if you're open to it -- I'd love to be able to generalize what we're doing to other domains if we could -- it's unfortunately cpu intense how we're doing it.

Yes, we're pushing the notification to a new tab (which can't be blocked or interfered with) once it goes through QA -- likely early next week.

Also even multifactor now must be new location verified so the ability to exploit this is now extremely low. Any attempt utilize those credentials will be blocked an email will be generated just like what happened in the non-multifactor case.

Hopefully you've gained enough attention for the chrome issue: https://code.google.com/p/chromium/issues/detail?id=453093 to be implemented sooner rather than later, if you could do me a favor and follow it to keep the pressure on Google to help mitigate phishing risk we'd appreciate it.

LastPass has pushed Google for years to give us a way to avoid using the browser viewport: infobars was a solution to this issue -- you can see one of my pleas for it back in January 2012: https://code.google.com/p/chromium/issues/detail?id=39511

We do a lot to try to protect our usage of viewports using iframes, but it's not good enough and we'll figure out a way to do better. LastPass has generally told people to use the extension directly to login as it's more secure, we'll need to go further here as well.

Sean was clever using http://chrome-extension.pw which looks close -- but LastPass also detects you enter your master password on an incorrect domain and notifies you immediately of your mistake, mitigating this a great deal. This has existed for a long time before Sean's report and we did not implement as a response to Sean's bug report -- we implemented it as a general way for people to know about password resuse and to be notified of being phished.

Making this practical is a lot tougher than email phishing -- you really need an XSS on a page that people use to login, and unlike email phishing it is immediately caught.

LastPass doesn't have access to your symmetric key, it doesn't have access to your private RSA key either. It's all locally encrypted and locally generated. LastPass does have access to your public key (which is safe and makes sense).

This is accomplished the same way LastPass shares sites.

In fact LastPass didn't have it at first, but after dozens of impassioned pleas from people with disabilities we made the decision to add it with a very strong warning against using it.

LastPass Enterprise has a policy to disable it, which is recommended there.

Full Disclosure: I work at LastPass.

"Turning on 2FA did not worked most of the times"

If you have a security issue here we'd appreciate a report at https://lastpass.com/security/ that said every report of this has always been a case of someone not reading the manual or FAQs so please checkout https://lastpass.com/support.php?cmd=showfaq&id=2775 first.

"Sorry but I will never give trust to a password manager written in PHP"

The password manager is actually written in C++,Objective-C,Java,C# and JavaScript -- depending on platform. You seem to be focused on our website however (which only handles encrypted data with a key never get) which is written in Hack: http://hacklang.org/ actually, not PHP.

Regarding the user experience being less without extensions installed -- yes, that's true, we highly encourage installing those -- the extension-less access should really be used for emergencies only -- it's safer to login to the extensions since it's not relying on JavaScript you just downloaded, it's always preferred.

Mozilla used to be the best place in the world for extension developers -- it was natural to have your best extension on Firefox because you could release early and often. Active developers made the platform.

When Chrome came along they decided to go in a different direction entirely slowly making it more and more painful to accomplish what used to be easy in the name of security. The review process went from automatic if you were trusted to weeks and then months and then more than a quarter year. They started demanding source code. It became scary to release to addons.mozilla.org because you never knew how long it would be before your next release would be approved.

Mozilla needs to realize they're hastening their own demise - Chrome now offers better features than when Mozilla was the leader including releasing to a percentage of users and faster nearly invisible to the user updates. They should go back to their roots and embrace developers again.

LastPass - https://LastPass.com/jobs - Fairfax, VA (DC metro, Dunn Loring metro stop)

Our open tech roles are:

  - Software Engineer iOS
  - Software Engineer OSX
  - Junior Software Engineer
  - Senior Software Engineer
  - Front End Developer

We're growing fast, and we're hiring in essentially all departments including support, sales, and more -- if you would enjoy making LastPass better please reach out!

It's not a 'we let them publish' it's a we respected their wishes in that we would hold off on talking about it until they published.

If we stole the thunder from security researchers by announcing about things they've found before they can we'd risk that they'd consider holding back. I feel it's the right move to encourage the researchers and respect their wishes.

Fairfax VA (Washington DC area near metro) local preferred REMOTE possible for the very talented.

jobs@lastpass.com

LastPass, you know it, you love it, you want to make it better.

Regarding firefox -- Are you speaking of the fact that Mozilla refused our Firefox updates for over a year?

We're happy you found a tool that works for you -- that's what we want everyone to do -- it doesn't need to be LastPass but people need to use something -- reusing passwords constantly is just painful.

We've always had a full blown web browser in the app -- it's been the only viable way to fill passwords in for years. Literally the first option we added.

We also have an extension into Dolphin, and you can utilize Chrome utilizing our fill method -- if you don't like them there are options to disable them too reducing the perceived extra bulk.