Security

LastPass scrambles to fix another major flaw – once again spotted by Google's bugfinders

Ormandy sets snowflakes off over disclosure


For most of us, Saturday morning is a time for a lie in, a leisurely brunch, or maybe taking the kids to the park. But for some it's bug-hunting time.

Tavis Ormandy, a member of Google's crack Project Zero security team, was in the shower and thinking about LastPass – after finding a number of flaws in the password manager over the past week. Then he had an epiphany and "realized how to get codeexec in LastPass 4.1.43," he said, and filed a bug report.

The timing couldn't have been worse for LastPass engineers. They spent last weekend sorting out Tavis' other bug finds, and now it looked like they'd be back in the office again this weekend. LastPass has now confirmed that the new find is an issue and they are working on it.

"This attack is unique and highly sophisticated. We don't want to disclose anything specific about the vulnerability or our fix that could reveal anything to less sophisticated but nefarious parties. So you can expect a more detailed post mortem once this work is complete," the firm said.

"We want to thank people like Tavis who help us raise the bar for online security with LastPass, and work with our teams to continue to make LastPass the most secure password manager on the market."

That last statement is a kicker, because some on Twitter got very upset at Ormandy for disclosing that there was an issue with LastPass. It seems some people prefer to think that ignorance is bliss.

It seems a fair few people don't understand the rules of responsible disclosure. Researchers are perfectly free to go public by saying there is a flaw in a particular piece of code, so long as they don't say exactly what it is or how to exploit it before a patch is available.

There are some who suggest researchers shouldn't even highlight that a flaw exists. That ends up being counterproductive, since it reduces the incentive for manufacturers to fix their code. Companies might be fine with that, but it can put users at risk.

Google and others have 90-day disclosure rules for just this reason – the thinking is that if a company can't be bothered to sort out an issue in that time then they aren't really trying – although almost every researcher will give a manufacturer more time if needed. It seems some people have forgotten this. ®

Send us news
36 Comments

Atlassian loses half its CEOs, but customers stay solid after Server products exit support

Discloses ongoing experiments with usage-based pricing

Intel excited by PC sales pop and GPU prospects, but investors aren’t because the outlook is poor

Chipzilla's Foundry business weighs down the Gelsinger gang - for now

What's up with Alphabet and Microsoft lately? Profits, sales – and AI costs

If ML proves an expensive habit in future, these money printers won't have much to worry about ... probably

Amazon to blow $11B on cluster of Indiana bit barns

Talk about going round the (South) Bend

Cops cuff man for allegedly framing colleague with AI-generated hate speech clip

Athletics boss accused of deep-faking Baltimore school principal

Ring dinged for $5.6M after, among other claims, rogue insider spied on 'pretty girls'

Cash to go out as refunds to punters

ByteDance 'would rather' torpedo TikTok than sell it off

As app boss vows to nuke America's divest-or-ban law in the courts

FCC votes 3-2 to bring net neutrality back from the dead

Law responds again to pings

Detecting drift and dealing with the Silicon Valley mindset

Pulumi's CEO on new products and that other Infrastructure as Code company

Two cuffed in Samourai Wallet crypto dirty money sting

Suspects in Portugal and the US said to have laundered over $100M

TSMC says first 1.6nm chips coming in 2026

Watch out Intel ... Angstrom-class A16 with Super Rail backside power tech incoming

Spotify claims Apple wants 'tax' for in-app pricing tweak

App maker accuses Cupertino of defying EU rules