新闻中心

Critical LastPass security hole would allow hackers to steal your passwords

字号+ 作者:668影视网电视剧大全 来源:行业动态 2024-09-23 14:40:40 我要评论(0)

LastPass, the online service that keeps your passwords safe behind one master password, is currently

LastPass, the online service that keeps your passwords safe behind one master password, is currently not nearly as secure as it should be.

According to Google's vulnerability researcher Tavis Ormandy, there's at least one unpatched vulnerability in LastPass that allows attackers to steal passwords "from any domain."

SEE ALSO:Change this security setting on WhatsApp right now

Ormandy recently reported a few other LastPass bugs, including vulnerabilities in the LastPass add-ons for Firefox and Chrome.

One security vulnerability, described in detail by Ormandy here, not only allows for an attacker to steal passwords, but -- in certain circumstances -- it can also be used to run arbitrary code on the victim's computer.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

On Tuesday, LastPass announced that that particular issue has been resolved, but on Wednesday, the company acknowledged that there is an unpatched bug in its Firefox add-on.

Replying to a commenter to Tuesday's tweet, LastPass said that users needn't do anything at this point. However, the company still hasn't published anything on its official blog regarding these new security holes.

While no software is safe from security holes, vulnerabilities that affect password managers such as LastPass are particularly worrisome, as these services safeguard users' entire password collections. Especially when they come in droves, as they do these days.

This is not the first serious security issue LastPass has encountered. The service got hacked in 2011 and again in June 2015. And in 2013, a bug caused some users' Internet Explorer passwords to get exposed to the public.

UPDATE: March 22, 2017, 6:52 p.m. CET LastPass responded to our query by pointing us to their freshly published blog post, here. In the post, the company says it has worked with Ormandy to investigate and fix these vulnerabilities. The company claims it has fixed all issues now, and patches will be applied automatically for most users. According to LastPass, there is no indication that any of these vulnerabilities were exploited in the wild. The company vowed to provide a more comprehensive overview of these vulnerabilities, as well as its efforts to fix them and prevent further issues, in the future.


Featured Video For You
This automatic smart lock is both convenient and secure

1.本站遵循行业规范,任何转载的稿件都会明确标注作者和来源;2.本站的原创文章,请转载时务必注明文章作者和来源,不尊重原创的行为我们将追究责任;3.作者投稿可能会经我们编辑修改或补充。

相关文章
  • 23 Peculiar Places of 2023

    23 Peculiar Places of 2023

    2024-09-23 14:37

  • iPhone 12 production might be affected by power chip shortage

    iPhone 12 production might be affected by power chip shortage

    2024-09-23 14:26

  • 《月亮公主·迷雾星球》儿童剧在我市开演

    《月亮公主·迷雾星球》儿童剧在我市开演

    2024-09-23 13:57

  • Kim's daughter unveiled last week is his 2nd child: Seoul spy agency

    Kim's daughter unveiled last week is his 2nd child: Seoul spy agency

    2024-09-23 13:40

网友点评