Hacker News new | ask | show | jobs
by blahaj 129 days ago
Just an anti recommendation: Do not use Lastpass. Reading the security breach section of their Wikipedia article should be enough reason.

For anyone reading this who uses LastPass: Switch away!

1 comments

According to the wiki, a one-click exfiltration vulnerability has existed for more than half a year and hasn't been fixed:

> In their default configurations, these extensions were shown to be exposed to a DOM-based extension clickjacking technique, allowing attackers to exfiltrate user data with just a single click. LastPass version 4.146.8 (September 12, 2025), which was intended to address the issue, remains vulnerable

https://en.wikipedia.org/wiki/LastPass#Security_incidents

Update, with Apple's 'Passwords' app, it appears all someone needs to do to get access to every single stored password, is grab your iPhone while it's unlocked, or sneak it from you while sleeping and use face id to unlock it.

Or, they could shoulder surf to get a 6 digit pin to unlock the phone, then steal it, then they're in.

Seems way less secure than 'Correct Horse Battery Staple'.

Faced is required to unlock the passwords app if you enable stolen device protection