LastPass

Discussion in 'other software & services' started by khanyash, May 20, 2015.

  1. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    At the moment what concerns me is not the functionality of LogMeIn, which seems about as good as any other remote access software I've used, but the fact that LogMeIn is often the scammer's choice for accessing and compromising the systems of unsuspecting users. The LogMeIn folks do business with these people. Do they have no responsibility for how their product is misused? See here:

    http://www.troyhunt.com/2012/06/how-logmein-is-enabling-scammers-to.html
     
  2. Rolo42

    Rolo42 Registered Member

    Joined:
    Jan 22, 2012
    Posts:
    571
    Location:
    USA
    They don't. The only way to decrypt the password was to attack the users' storing it locally. The martivigo.com report details this (a good read).
    Any password stored locally is vulnerable.
     
  3. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    Yes, it can be found here:

    http://www.martinvigo.com/a-look-into-lastpass/
     
  4. Rolo42

    Rolo42 Registered Member

    Joined:
    Jan 22, 2012
    Posts:
    571
    Location:
    USA
    That's the report I was referring to. Where in it does it say a user's LastPass password can be obtained from LastPass?
     
  5. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    And how can any company prevent that without making their software too restrictive for the general public? Sure let's blame the tool, not the user.

    And please don't make nonsensical claims devoid of proof like LogMeIn actually doing business with scammers.
     
  6. Rolo42

    Rolo42 Registered Member

    Joined:
    Jan 22, 2012
    Posts:
    571
    Location:
    USA
    And Linux is the OS of choice. Ban Linux!
    And Windows is typically the target. Let's ban Windows! :eek:

    We'll all be like that author who uses DOS still.
     
  7. AutoCascade

    AutoCascade Registered Member

    Joined:
    Feb 16, 2014
    Posts:
    741
    Location:
    United States
    I keep my master & google passwords on a usb drive that I plug in when I need it.
     
  8. Rolo42

    Rolo42 Registered Member

    Joined:
    Jan 22, 2012
    Posts:
    571
    Location:
    USA
    The point of LastPass is that you can remember one password and therefore don't have to store it. My LastPass password is in my head and in my fireproof double-locked safe in case something goes wrong with my head.
     
  9. TonyW

    TonyW Registered Member

    Joined:
    Oct 12, 2005
    Posts:
    2,741
    Location:
    UK
    Joe Siegrist has updated the original blog post mentioned by WSFfan in post #47:

     
  10. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    Did you read the article that I linked to? The article implies that LogMeIn is complicit with the scammers. The article is making that claim, not me. Perhaps you could comment on what the article states?
     
  11. Rolo42

    Rolo42 Registered Member

    Joined:
    Jan 22, 2012
    Posts:
    571
    Location:
    USA
    Because you inferred does not mean he implied.

    It is one guy's opinion, based on his complaints not causing an immediate, visible fix in his admittedly narrow view. He's only complained that they must 'do something'.

    He hasn't pointed to a problem anyone can fix. You can't fix the social engineering attack surface with technical means. LogMeIn isn't 'complicit' in anything to do with regards to persons letting a total stranger connect to their computer and the author hasn't suggested such.
     
  12. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Like @Rolo42 said, the article did not conclusively prove anything other than it is the author's opinion. And even he did not state LogMeIn is doing business with scammers.
     
  13. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,899
    Location:
    localhost
    The usual FUD on lastpass based on opinion and old articles (2014) :thumbd:
     
  14. sukarof

    sukarof Registered Member

    Joined:
    Jun 22, 2004
    Posts:
    1,887
    Location:
    Stockholm Sweden
    As I understand it I am very secure even if some hacker know my master password since I use two factor authentication (Transact) and only allow two physical computers to even log in to lastpass without the second verification. My home and my work computer are the only ones that are allowed to login without the second authentication. I even have the option in my browser plugin in my main browser at home to remember the password so I am always logged in to lastpass when the browser starts..

    As I see it the only way for someone to use my lastpass, even if he knows my master password, is to sit at some of my desktops that I have allowed. As I see it I can even login with the two factor authentication on a random internet café and let eventual keyloggers steal my master password and I will be safe after I have logged out from the internet café computer. Am I right?
     
  15. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    Not if that hacker is also able to steal your blob from the LastPass servers. 2FA no longer plays a role then...
     
  16. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,899
    Location:
    localhost
    That translated means, if they have physically your database of passwords then they can decrypt it locally with the master password.

    So if an hacker has your master password, first it need to crack the 2FA to be able to access the second server where your database is stored and hack this one. Ah, I forgot that they may need to spoof your location and/or the unique ID of your registered devices as, since some months, lastpass will reject calls if not from your devices/location.

    Paradoxically its easier to hack a typical password software that stores all the information locally.
     
    Last edited: Oct 10, 2015
  17. Rolo42

    Rolo42 Registered Member

    Joined:
    Jan 22, 2012
    Posts:
    571
    Location:
    USA
    As the article stated, that was fixed (they were able to get your QR code to add your account to their 2FA device...which would lock you out of your account if you didn't already have 2FA enabled).
    Until such time, that was a vulnerability. 2FA, like any security mechanism, isn't 100% 100% of the time.
     
  18. TS4H

    TS4H Registered Member

    Joined:
    Nov 5, 2013
    Posts:
    523
    Location:
    Australia
    We need another pole. I would love to know how many users will move away from Lastpass or stay as result of this acquisition. I have no clue about the Logmein debacle etc, and after reading all the comments on the lastpass blogs, 99% are against this buyout. So im at a loss as to what to do. Stay with lastpass or move onto Keepass or Sticky Passwords. Either way, I think its best to explore other options nonetheless.
     
  19. Rolo42

    Rolo42 Registered Member

    Joined:
    Jan 22, 2012
    Posts:
    571
    Location:
    USA
    Why is it even a concern? LastPass is working great today as it did yesterday...
     
  20. TS4H

    TS4H Registered Member

    Joined:
    Nov 5, 2013
    Posts:
    523
    Location:
    Australia
    Never said it was not working great. However will it be the case tomorrow, is to me a cause for concern and for a lot of people.
     
  21. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    I also wonder why they decided to buy this service.
     
  22. sukarof

    sukarof Registered Member

    Joined:
    Jun 22, 2004
    Posts:
    1,887
    Location:
    Stockholm Sweden
    I have never heard of this "logmein" before, but reading about it on the net doesnt give good vibes. If this purchase of Lastpass has any consequences that I dont like, or that peoples worries shows to be true and not FUD, I wont hesitate to end my Premium account and look for something else. Before Lastpass, back in 2009, I was a Roboform user and might try that again if necessary. I dont mind paying for a good software.
     
    Last edited: Oct 11, 2015
  23. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    "I also wonder why they decided to buy this service"

    Their YTD gains and the internet of things group.

    Senior Executives From Under Armour and Symmons Industries Join LogMeIn's Xively IOT Advisory Board

    http://markets.ask.com/ask/quote?Symbol=537:3695053
     
  24. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Almost blind herd-like behaviour seen here of all places... Guess we should prove LogMeIn is innocent instead of the other way around.
     
  25. Rigz

    Rigz Registered Member

    Joined:
    Jun 28, 2015
    Posts:
    65
    Location:
    Earth
    In the event that I suddenly need to completely get rid of LastPass I have an export of all data locked away in a safe. If my info is that important that someone is going to break in with the equipment to remove an old iron safe from my house then have at it (I must be more important that I had originally thought). In the meantime I'll keep using LastPass until I see how everything plays out.

    Maybe we should pool our money, find a secure data center, hire the LastPass employees when LogMeIn fires them, and create our own company.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.