What's new arround internet

Last one

Src Date (GMT) Titre Description Tags Stories Notes
grahamcluley.webp 2016-07-27 11:50:43 LastPass security hole could have seen hackers steal your passwords (lien direct) Mathias Karlsson, a security researcher at Detectify Labs, writes:Stealing all your passwords by just visiting a webpage. Sounds too bad to be true? That's what I thought too before I decided to check out the security of the LastPass browser extension.In his article, Karlsson explains how he was able to trick LastPass into believing that it was on the real Twitter website, and cough up the users' credentials because of a bug in the LastPass password manager's autofill functionality.The same technique could have been used to steal passwords associated with other websites.Yeuch!The good news is that Karlsson believes in responsible disclosure, and so informed LastPass of the problem. In more good news LastPass fixed the issue in less than a day (and awarded Karlsson a $1,000 bug bounty for his efforts).Karlsson recommends that LastPass users disable the autofill functionality and enable multi-factor authentication for better security.Although his discovery is troubling, I agree with Karlsson when he points out that using a password manager is still better than reusing passwords on different websites.PS. Well-known vulnerability researcher Tavis Ormandy has also tweeted overnight that he has also found a flaw in LastPass. Details have not yet been made public, and LastPass is reportedly working with him on resolving the issue.PPS. Readers with good memories will recall that LastPass was acquired by LogMeIn last year to the concern of some. Overnight it has been announced that LogMeIn is itself being acquired by Citrix. LastPass
ZDNet.webp 2016-07-27 07:49:07 LastPass unpatched zero-day vulnerability gives hackers access to your account (lien direct) The security flaw was one of "a bunch of critical problems" discovered by a prominent researcher who simply took a quick look at the software. LastPass
bleepingcomputer.webp 2016-06-08 18:54:45 Windows 10 Build 14361 Released with LastPass Extension and enhanced Docker Support (lien direct) Windows 10 Insider Preview Build 14361 has been released to fast ring and it comes with some nice features and bug fixed. Some of the main improvements include a LastPass extension for Microsoft Edge, native Docker implementation on Windows 10 with Hyper-V containers, Windows Ink improvements, new icons, and Settings improvements. [...] LastPass ★★
Last update at: 2024-06-03 01:07:57
See our sources.
My email:

To see everything: Our RSS (filtrered) Twitter