HN user

thekos

25 karma

[ my public key: https://keybase.io/kos; my proof: https://keybase.io/kos/sigs/3B9ZlAnm60i1cm532aJmCoc3NAAQ56vWp4I-cDVahQM ]

Posts0
Comments11
View on HN
No posts found.

LastPass does actually know URLs. After logging into LastPass.com, you can navigate to https://lastpass.com/getaccts.php (only accessible post authentication with a valid session cookie.)

This will return an XML document with your vault data. Most of it is encrypted, however an URL parameter is encoded as hex, in plaintext. I am able to look at all URL. They could be storing the blog fully encrypted in a server datastore, but at some point, the LastPass servers are handing the client non-encrypted URLs.

Linode was down 13 years ago

Appears that it cascaded across all of their nameservers. Seems like it could be an attack (remote or local DoS condition bug, since all users can create their own zones), or maybe just a random bug - hopefully they'll update us.

Linode was down 13 years ago

From the #linode IRC channel, caker (CEO) states it was a segfault in bind.

13:53:14 caker@ : They operate completely independently, other than loading from the same zones. This looks to be a segfault in bind itself