Stop using password manager browser extensions

It’s been over a year since I presented on LostPass at ShmooCon, and in that time, many more bugs have been found in password managers. The most severe of which are in browser-based password managers extensions such as LastPass. 

Tavis Ormandy yesterday demonstrated a remote code execution on the latest LastPass version. This isn’t the first extremely severe bug he’s found in LastPass, either; there’ve been so many extremely severe bugs in LastPass it would be tedious to list them out. But LastPass isn’t alone: Keeper, Dashlane and even 1Password have had severe vulnerabilities that allowed attackers to steal all of the passwords in a user’s account without their knowledge.

To read this article in full or to leave a comment, please click here

Network World Security