Login Register






LastPass filter_list
Author
Message
LastPass #1
My sudden thought of the day: is LastPass really the holy grail of password managers?

Don't get me wrong, I've been a supporter of LastPass and in my opinion, LastPass have provided extra security for the average Joe who use only two passwords between 16 websites. I understand that LastPass do not store a master key nor allow password recovery. This gets me because, a simple keylogger could allow the attacker to access your passwords and with that, your passwords can be viewed and distributed.

I just never sat down and thought about the risk of LastPass.

Any thoughts on this? Would you guys recommend KeePass instead?
(This post was last modified: 09-26-2018, 11:28 AM by dismay.)
[Image: 4MtNRt3.gif]

Reply

RE: LastPass #2
I never used one of these password managers, but I heard of them. And as you said for the average Joe it's definitely a new layer of security in place, but for the more technical people I think it's not a big advantage.
As you said a keylogger and other type of malware could steal all of your passwords pretty easily. I didn't looked over how password managers work, but I assume the passwords are stored in memory somehow and probably encrypted also. So you would just need some way to find the key and after dump the memory to get all of the passwords. (If this is wrong, any productive criticism is welcomed)
[Image: iQDVDdD.gif]

Reply

RE: LastPass #3
Password managers are just an extra convenience which doesn't compromise security, but instead pushes users to using better passwords.

@Cr3aTor  anything on the runtime will be decrypted at some point, otherwise your computer would not be able to use it, see here:

https://security.stackexchange.com/quest...y-computer

Coming back to the security of password managers, there's been many attacks against password managers over the years, especially their client-side companions, such as apps and plugins:

https://www.blackhat.com/docs/eu-15/mate...ith-it.pdf
http://www.s3.eurecom.fr/projects/modern...-phishing/

Now although people will try to make them look bad, I think they have way more procs than cons. No matter how good you think you are in remembering passwords or creating secure ones in your brain, after a number, you will start creating patterns. Use a password manager and you can use random long passwords. See this for pros and cons:

https://www.ncsc.gov.uk/blog-post/what-d...d-managers

Finally, what I do, is that I use password managers but with a grain of salt:
  • Do not use LastPass or any other cloud-based provider. Prefer to store the database in my systems, and back it up myself. LastPass been hacked couple of times, and it could have related to it being on the cloud - don't quite remember.
  • Do not use plugins for browsers, do not use auto-fill or any other helpful feature. Go there and copy the password manually.
  • Use any extra security provided to you, such as a database key.
  • Keep the database key isolated from the encrypted database itself. In case of a compromise, the attackers would need to find your key and master password.
  • When you leave your computer, try to shut down your password manager, or ensure its session times out after a while.

Generally speaking, minimise the attack surface, use less features and well-maintained solutions, and keep your eyes open.

Hope the above helps Smile
(This post was last modified: 09-30-2018, 11:16 AM by BitFaces.)

[+] 2 users Like BitFaces's post
Reply

RE: LastPass #4
(09-30-2018, 11:14 AM)BitFaces Wrote:
Spoiler:
Password managers are just an extra convenience which doesn't compromise security, but instead pushes users to using better passwords.

@Cr3aTor  anything on the runtime will be decrypted at some point, otherwise your computer would not be able to use it, see here:

https://security.stackexchange.com/quest...y-computer

Coming back to the security of password managers, there's been many attacks against password managers over the years, especially their client-side companions, such as apps and plugins:

https://www.blackhat.com/docs/eu-15/mate...ith-it.pdf
http://www.s3.eurecom.fr/projects/modern...-phishing/

Now although people will try to make them look bad, I think they have way more procs than cons. No matter how good you think you are in remembering passwords or creating secure ones in your brain, after a number, you will start creating patterns. Use a password manager and you can use random long passwords. See this for pros and cons:

https://www.ncsc.gov.uk/blog-post/what-d...d-managers

Finally, what I do, is that I use password managers but with a grain of salt:
  • Do not use LastPass or any other cloud-based provider. Prefer to store the database in my systems, and back it up myself. LastPass been hacked couple of times, and it could have related to it being on the cloud - don't quite remember.
  • Do not use plugins for browsers, do not use auto-fill or any other helpful feature. Go there and copy the password manually.
  • Use any extra security provided to you, such as a database key.
  • Keep the database key isolated from the encrypted database itself. In case of a compromise, the attackers would need to find your key and master password.
  • When you leave your computer, try to shut down your password manager, or ensure its session times out after a while.

Generally speaking, minimise the attack surface, use less features and well-maintained solutions, and keep your eyes open.

Hope the above helps Smile


Members should certainly take this on board. Very well documented and elaborated.

I certainly agree with this statement.
Quote:I use password managers but with a grain of salt
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

LastPass #5
Thanks @mothered, I haven't been in a forum in a while (years..) so glad to offer my view in detail Smile.

Reply

RE: LastPass #6
Spoiler:
(09-30-2018, 11:14 AM)BitFaces Wrote: Password managers are just an extra convenience which doesn't compromise security, but instead pushes users to using better passwords.

@Cr3aTor  anything on the runtime will be decrypted at some point, otherwise your computer would not be able to use it, see here:

https://security.stackexchange.com/quest...y-computer

Coming back to the security of password managers, there's been many attacks against password managers over the years, especially their client-side companions, such as apps and plugins:

https://www.blackhat.com/docs/eu-15/mate...ith-it.pdf
http://www.s3.eurecom.fr/projects/modern...-phishing/

Now although people will try to make them look bad, I think they have way more procs than cons. No matter how good you think you are in remembering passwords or creating secure ones in your brain, after a number, you will start creating patterns. Use a password manager and you can use random long passwords. See this for pros and cons:

https://www.ncsc.gov.uk/blog-post/what-d...d-managers

Finally, what I do, is that I use password managers but with a grain of salt:
  • Do not use LastPass or any other cloud-based provider. Prefer to store the database in my systems, and back it up myself. LastPass been hacked couple of times, and it could have related to it being on the cloud - don't quite remember.
  • Do not use plugins for browsers, do not use auto-fill or any other helpful feature. Go there and copy the password manually.
  • Use any extra security provided to you, such as a database key.
  • Keep the database key isolated from the encrypted database itself. In case of a compromise, the attackers would need to find your key and master password.
  • When you leave your computer, try to shut down your password manager, or ensure its session times out after a while.

Generally speaking, minimise the attack surface, use less features and well-maintained solutions, and keep your eyes open.

Hope the above helps Smile


Thank you very much for the clarification and for the resources provided. As I said in my post, I was just speculating. So I was hoping someone would come with the knowledge for this in place.
This really helps me for a better understanding. Cheers !
[Image: iQDVDdD.gif]

[+] 1 user Likes Cr3aTor's post
Reply

RE: LastPass #7
(09-30-2018, 11:14 AM)BitFaces Wrote: snip

A very elaborate reply, thank you.

After some consideration, I may convert to alternative paasword managers, even though cloud based are convident, it isn't as safe as I once thought.
[Image: 4MtNRt3.gif]

[+] 1 user Likes dismay's post
Reply

RE: LastPass #8
(09-30-2018, 11:25 AM)BitFaces Wrote: Thanks @mothered, I haven't been in a forum in a while (years..) so glad to offer my view in detail Smile.

Quality contributions are always appreciated, and yours Is no exception.
[Image: AD83g1A.png]

Reply