FacebookInstagramTwitterContact

 

Study Claims Drinking A Mug Of Black Tea Provides Enough Nutrients To Prevent COVID Infection           >>           Buyers Beware: Turmeric Products Are Often Contaminated With Lead           >>           Calcium: Why You Need It, Debunking Myths About It, And The Best Plant-Based Food Sources Of This Important Mineral           >>           Rubber Duck Washes Up On Scottish Beach 18 Years After It Was Released In Ireland           >>           Sainsbury’s Finally Gets The Price Of Freddo Right — After 19 Years           >>           Raya Joy for Hospital Patients           >>           Job Recruitment Interview           >>           Bilateral Exercise           >>           Hari Raya Aidilfitri can Alleviate Homesickness           >>           Spectrum Exhibition 2024           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


Critical security flaws found in LastPass on Chrome, Firefox (updated)


PashaIgnatov via Getty Images

 


 March 24th, 2017  |  09:28 AM  |   1067 views

ENGADGET.COM

 

Between server-side fixes and updated extensions, the issues have been addressed.

 

Last year Google Project Zero researcher Tavis Ormandy quickly found some "obvious" security problems in the popular password manager LastPass, and now he's done it again. Last week Ormandy mentioned finding an exploit in one version of its extension for Firefox, before following that up with a new bug that affected both Chrome and Firefox, and finally a third vulnerability that could allow "stealing passwords for any domain."

 

The first vulnerability has apparently not been addressed yet, which Ormandy mentions may be the result of Mozilla needing time to review the updated extension before pushing it to users. Based on his tweet, it could reveal a user's password, but not all of the details have been revealed yet.

 

The second issue could be more serious, with the ability to steal a user's passwords or, if the binary version of the extension is installed, run any code the attacker tells it to (in an example, Ormandy causes the target's computer to open a Calculator program.) According to LastPass the issue has been resolved, although a promised follow-up blog post with more details has yet to appear.

 

There's even less info available about the latest vulnerability identified (updated -- see below.)

 

The pace of these discoveries and the lack of information from LastPass is certainly troubling, although using a password manager to maintain unique passwords can help protect you from being hacked. We've contacted the company and will update this post with any news, however, it may be wise to disable the affected browser extensions for now. If you're suddenly looking for another service to store your important login information, Tavis (who makes a habit of poking holes in security products) suggested KeePass, a manager that doesn't use browser extensions to keep a layer of security between websites and your vault.

 

Update: LastPass has responded with a blog post. Regarding the bug above that affected clients in Chrome, Firefox and Edge, the company says it applied a server-side workaround. As far as the bug for Firefox 4.1.35a, the company says this has been addressed in a new version pushed last night, so users of that browser should make sure they've updated to 4.136a.

 

Finally, the bug Ormandy noted in the older (and soon to be deprecated) version of the LastPass Firefox extension is fixed in a new update, so users of that version should update to 3.3.6, via the browser's built-in system.

 


 

Source:
courtesy of ENGADGET

by Richard Lawler

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

Solomon Islands: The Pacific Election Being Closely Watched By China And The West

 2024-04-18 00:06:57

Whistleblower 'Would Not' Put Family On Boeing 787 Jet

 2024-04-18 01:01:12