Security28.07.2016

How to keep safe online with LastPass

Lastpass

Two LastPass security concerns made headlines recently, and the company has now addressed these issues.

LastPass was responding to two security reports that were disclosed to its team.

One report was disclosed on 27 July, while the other was reported and fixed over a year ago.

Both reported security exploits required tricking a user via a phishing attack into going to a malicious website.

The first report was disclosed by Mathias Karlsson, who recently posted his findings on the URL parsing bug.

All browser clients were updated and Karlsson confirmed the fix.

The second report was made by Google Security Team researcher Tavis Ormandy, who revealed a message-hijacking bug that affected the LastPass Firefox add-on.

First, an attacker would need to lure a LastPass user to a malicious website.

Once there, the website can execute LastPass actions in the background without the user’s knowledge, such as deleting items.

This issue was addressed and a fix was pushed for all Firefox users using LastPass 4.0.

Further recommendations

LastPass recommended the following safety measures to users:

  • Beware of phishing attacks. Do not click on links from people you don’t know, or that seem out of character from contacts and companies.
  • Use a different, unique password for every online account.
  • Use a secure master password for your LastPass account that you never disclose to anyone.
  • Turn on two-factor authentication for LastPass and other services like your bank, email, Twitter, and Facebook.
  • Keep a clean machine by running antivirus and keeping software up to date.

More on LastPass

LastPass accounts can be “completely compromised”

LastPass vulnerable to simple phishing attack

LastPass hacked – you need to change your master password

Show comments

Latest news

More news

Trending news

Sign up to the MyBroadband newsletter