Hacker News new | ask | show | jobs
by punjabisingh 3618 days ago
It's confusing that the LastPass site is claiming only Firefox is impacted. [1] Whereas the security researcher's site (detectify.com) shows the vulnerability running in Chrome. [2]

Furthermore, the current live version on Firefox addons repository is 3.x [3], which the LastPass team claims is not vulnerable. [1]

[1] https://blog.lastpass.com/2016/07/lastpass-security-updates.... [2] https://labs.detectify.com/2016/07/27/how-i-made-lastpass-gi... [3] https://addons.mozilla.org/en-US/firefox/addon/lastpass-pass...

1 comments

The Firefox reference is in the second vulnerability discussed in your link 1, and is unrelated to your link 2 and parent submission. That second vulnerability apparently only affected the version 4 line of the Firefox plugin, which is marked beta in the Mozilla repository.