Tag Archive for: Managers

Potent LastPass exploit underscores the dark side of password managers

(credit: Wikimedia)

Developers of the widely used LastPass password manager are scrambling to fix a serious vulnerability that makes it possible for malicious websites to steal user passcodes and in some cases execute malicious code on computers running the program.

The flaw, which affects the latest version of the LastPass browser extension, was briefly described on Saturday by Tavis Ormandy, a researcher with Google’s Project Zero vulnerability reporting team. When people have the LastPass binary running, the vulnerability allows malicious websites to execute code of their choice. Even when the binary isn’t present, the flaw can be exploited in a way that lets malicious sites steal passwords from the protected LastPass vault. Ormandy said he developed a proof-of-concept exploit and sent it to LastPass officials. Developers now have three months to patch the hole before Project Zero discloses technical details.

“It will take a long time to fix this properly,” Ormandy said. “It’s a major architectural problem. They have 90 days, no need to scramble!”

Read 4 remaining paragraphs | Comments

Technology Lab – Ars Technica

Is Your Password Manager’s Promise of “Military-Grade” Security Actually True? – Wccftech


Wccftech

Is Your Password Manager's Promise of “Military-Grade” Security Actually True?
Wccftech
Security experts from TeamSIK of the Fraunhofer Institute for Secure Information Technology in Germany, have analyzed nine Android password managers, revealing that each of them had at least one low, medium or high severity vulnerability. “Applications …

and more »

android security – read more

Keep using password managers — bugs and all

Bugs in several password managers, including the vulnerabilities discovered in LastPass in late July, have scared away some users. But such fears go too far. Millions of users rely on password managers to keep track of passwords for applications and online services, and by all indications, they work better than trying to do it on your own.

Security victories should be embraced — including password managers, which automatically generate complex strings of characters as passwords and deploy a unique password for each site or application. Password managers solve several authentication problems, including easily-cracked passwords and password reuse.

To read this article in full or to leave a comment, please click here

Network World Security

One in four IT managers thwart a data breach every day, research claims – Enterprise Apps Tech


Enterprise Apps Tech

One in four IT managers thwart a data breach every day, research claims
Enterprise Apps Tech
One in four IT managers attempt to stop a data breach every day, according to new research released by data security provider WinMagic. The study, which polled 250 IT managers and 1,000 employees, found that for almost half of employees (41%), …

“data breach” – Google News