LastPass,Flashpoint X Porn (1997) the online service that keeps your passwords safe behind one master password, is currently not nearly as secure as it should be.
According to Google's vulnerability researcher Tavis Ormandy, there's at least one unpatched vulnerability in LastPass that allows attackers to steal passwords "from any domain."
SEE ALSO: Change this security setting on WhatsApp right nowOrmandy recently reported a few other LastPass bugs, including vulnerabilities in the LastPass add-ons for Firefox and Chrome.
I found another bug in LastPass 4.1.35 (unpatched), allows stealing passwords for any domain. Full report will be on the way shortly. pic.twitter.com/9VkV7R3vud
— Tavis Ormandy (@taviso) March 21, 2017
One security vulnerability, described in detail by Ormandy here, not only allows for an attacker to steal passwords, but -- in certain circumstances -- it can also be used to run arbitrary code on the victim's computer.
On Tuesday, LastPass announced that that particular issue has been resolved, but on Wednesday, the company acknowledged that there is an unpatched bug in its Firefox add-on.
The issue reported by Tavis Ormandy has been resolved. We will provide additional details on our blog soon.
— LastPass (@LastPass) March 21, 2017
We are aware of reports of a Firefox add-on vulnerability. Our security is investigating and working on issuing a fix.
— LastPass (@LastPass) March 22, 2017
Replying to a commenter to Tuesday's tweet, LastPass said that users needn't do anything at this point. However, the company still hasn't published anything on its official blog regarding these new security holes.
While no software is safe from security holes, vulnerabilities that affect password managers such as LastPass are particularly worrisome, as these services safeguard users' entire password collections. Especially when they come in droves, as they do these days.
This is not the first serious security issue LastPass has encountered. The service got hacked in 2011 and again in June 2015. And in 2013, a bug caused some users' Internet Explorer passwords to get exposed to the public.
UPDATE: March 22, 2017, 6:52 p.m. CET LastPass responded to our query by pointing us to their freshly published blog post, here. In the post, the company says it has worked with Ormandy to investigate and fix these vulnerabilities. The company claims it has fixed all issues now, and patches will be applied automatically for most users. According to LastPass, there is no indication that any of these vulnerabilities were exploited in the wild. The company vowed to provide a more comprehensive overview of these vulnerabilities, as well as its efforts to fix them and prevent further issues, in the future.
Topics Cybersecurity
Facebook will defend Libra before Congress todayGirl Scouts launch 18 new 'Coding for Good' badgesReddit is working again following hours of website issues'The Lion King' is a dutiful recreation of a beloved classic: ReviewGuy documents a 9Girl Scouts launch 18 new 'Coding for Good' badgesTrump's brief Twitter follow reveals possible love for adorable kittensFirst messages to send on Tinder if you want to be forever aloneOh nothing, just a terrifying snake eating another freaking snake on videoHurricane Barry photos show a Louisiana city deep under water: PHOTOSApple's iPhone will reportedly go notchBand has brutally blunt reaction to getting praised in The SunThe Indiana Pacers found a way to troll Mariah CareyThis woman assumed her trainer was flirting, he just thought she looked like Buzz LightyearThat video of a drone shooting fireworks into a crowd is not what it seemsThis toddler watching Superman take flight is the definition of joyJanet Jackson gives birth to her first child at age 50Waze now tells you how much all those tolls will costAI solves Rubik's cube in under a secondTwitter test gives you the power to quiet reply guys 'Bachelor' contestant puts on fake Australian accent, and people aren't convinced Now you can pre Ellen gets real with Kevin Hart, nudges him to host Oscars 2019 Golden Globes: Andy Samberg and Sandra Oh strike a perfect tone 'Erin Brockovich' chemical found in more than 200 million Americans' tap water Nissan's freaky AR concept would project friends in your car, make it look sunny outside Apple is bringing iTunes and AirPlay 2 to Samsung TVs Joss Whedon and his celebrity friends want you to vote on election day 20 monumental things that will turn 20 in 2019 GM unveils autonomous food Samsung's new Space monitor is perfect for tiny offices CES officials recommended a taxi Airbnb and its critics take to TV as tensions escalate Keep the loneliness at bay with Lovot’s $6,000 friendship robot Golden Globes 2019: the full winners list Pottermore's poop tweet reminds us that wizards are gross Sandra Oh and Andy Samberg surprised Golden Globes attendees with, uh, free flu shots Hackers leak data stolen from German politicians and celebrities How one red cap and a ton of suspect merch is boosting Trump's coffers FoldiMate's $1000 laundry
2.0441s , 10130.78125 kb
Copyright © 2025 Powered by 【Flashpoint X Porn (1997)】,Unobstructed Information Network