LastPass Finds Security Holes In Its Online Password Manager, Doesn’t Think Anyone Exploited Them

When you’re in charge of keeping many hundreds of thousands of passwords under lock and key, trust is everything. Maintaining that trust means fessing up when things go wrong — even if it’s something you don’t think affected your users.

Such is the case today for LastPass, a popular password manager for Safari, Chrome, Firefox and Opera. They’ve just published details of two security exploits discovered lurking in their products, though they say they don’t believe the exploits were ever used maliciously.

You can read their full post here, but here’s the gist of it:

So why’d they wait a year? As LastPass fixed the bugs quickly and had no evidence the bugs were ever exploited maliciously, it says they opted to let the research team publish their research on their own schedule. If you’re interested in getting into the technical details of either exploit, this appears to be the research paper in question.

As for what you LastPass recommends their users do:

If you are concerned that you’ve used bookmarklets before September 2013 on non-trustworthy sites, you may consider changing your master password and generating new passwords, though we don’t think it is necessary.

Regarding the OTP attack, it is a “targeted attack”, requiring an attacker to know the user’s username to potentially exploit it, and serve that custom attack per user, activity which we have not seen.

In 2011, LastPass publicly disclosed a “traffic anomaly” on their server that they couldn’t account for. Though there was no evidence that user data had been exposed, they opted “to be paranoid and assume the worst” and told many users to reset their passwords.

Latest Stories