LastPass,The Impotent King (2005) in English Subtitles the online service that keeps your passwords safe behind one master password, is currently not nearly as secure as it should be.
According to Google's vulnerability researcher Tavis Ormandy, there's at least one unpatched vulnerability in LastPass that allows attackers to steal passwords "from any domain."
SEE ALSO: Change this security setting on WhatsApp right nowOrmandy recently reported a few other LastPass bugs, including vulnerabilities in the LastPass add-ons for Firefox and Chrome.
I found another bug in LastPass 4.1.35 (unpatched), allows stealing passwords for any domain. Full report will be on the way shortly. pic.twitter.com/9VkV7R3vud
— Tavis Ormandy (@taviso) March 21, 2017
One security vulnerability, described in detail by Ormandy here, not only allows for an attacker to steal passwords, but -- in certain circumstances -- it can also be used to run arbitrary code on the victim's computer.
On Tuesday, LastPass announced that that particular issue has been resolved, but on Wednesday, the company acknowledged that there is an unpatched bug in its Firefox add-on.
The issue reported by Tavis Ormandy has been resolved. We will provide additional details on our blog soon.
— LastPass (@LastPass) March 21, 2017
We are aware of reports of a Firefox add-on vulnerability. Our security is investigating and working on issuing a fix.
— LastPass (@LastPass) March 22, 2017
Replying to a commenter to Tuesday's tweet, LastPass said that users needn't do anything at this point. However, the company still hasn't published anything on its official blog regarding these new security holes.
While no software is safe from security holes, vulnerabilities that affect password managers such as LastPass are particularly worrisome, as these services safeguard users' entire password collections. Especially when they come in droves, as they do these days.
This is not the first serious security issue LastPass has encountered. The service got hacked in 2011 and again in June 2015. And in 2013, a bug caused some users' Internet Explorer passwords to get exposed to the public.
UPDATE: March 22, 2017, 6:52 p.m. CET LastPass responded to our query by pointing us to their freshly published blog post, here. In the post, the company says it has worked with Ormandy to investigate and fix these vulnerabilities. The company claims it has fixed all issues now, and patches will be applied automatically for most users. According to LastPass, there is no indication that any of these vulnerabilities were exploited in the wild. The company vowed to provide a more comprehensive overview of these vulnerabilities, as well as its efforts to fix them and prevent further issues, in the future.
Topics Cybersecurity
Activist wears month's worth of trash to visualize our wasteful habits7 questions to ask before switching cell phone carriersIt's officially been one year since you started using chip cards instead of swipingArgentina vs. Colombia 2025 livestream: Watch World Cup Qualifiers for freeTrump unleashes tweetstorm on former Miss Universe Alicia MachadoStop what you're doing and look at these 23 adorable giant panda cubsKids stuck on a rollercoaster pass the time by dabbing until help arrivesKnicks' Joakim Noah skips cadet dinner over antiThe iPhone is your karaoke mic in tvOS 26's Apple Music SingAnother Miss Universe contestant recalls being bodyChildhood continues to die: The 'Mrs. Doubtfire' house is now on saleHow to hide the Instagram filters you hateYou can now use the Samsung Galaxy Note7 on planes in IndiaAntonio Brown will honor Arnold Palmer with an awesome pair of custom cleatsLuke Cage is Marvel's most vital hero yetEmma Watson learns to box like the badass that she isFilmmaker unknowingly captures stunning drone wedding photoChildhood continues to die: The 'Mrs. Doubtfire' house is now on sale7 can'tTeddy Ruxpin is back and creepier than ever Russian hackers reportedly blackmailing liberal groups because no one learned a damn thing Huge 'Logan' opening might not beat 'X This week in apps: McDonald's, Duolingo's flashcards, and Meet by Google Sorry Arian Foster, but you probably couldn't take down a wolf (we checked) 'Time After Time' boss says it's much more than a time travel show Starbucks is selling cold brew in jars because it wants in on the hipster market too Here’s how you create echo chambers on Facebook Obsessed with the Trump The tool that forces you to take a quiz before commenting is now available to everyone The latest leak of the Samsung Galaxy S8 reveals a lot about its home button Listen to Willow Smith sing the song Carrie Fisher wrote with Sean Lennon The hat for Elon Musk's 'Boring Company' is predictably boring 'The Americans' lucks out with its ads in the New York Times Construction worker with the voice of an angel does a mean Pavarotti Pizza dipped in milk is the most disrespectful pizza crime yet Looking for hope on climate change under Trump? Cities are where the action is. This chatbot helps refugees claim asylum, for free Chrissy Teigen gives more unwavering honesty in an essay on postpartum depression Forget Facebook and Google: The ad world thinks this tech giant is 'terrifying' Kate McKinnon's Kellyanne Conway will sit and text just about anywhere on 'SNL'
2.5824s , 10131.8828125 kb
Copyright © 2025 Powered by 【The Impotent King (2005) in English Subtitles】,Pursuit Information Network