{"id":79,"date":"2021-02-26T14:17:26","date_gmt":"2021-02-26T19:17:26","guid":{"rendered":"https:\/\/gryph.one\/?p=79"},"modified":"2021-02-26T14:17:26","modified_gmt":"2021-02-26T19:17:26","slug":"lastpass-youre-still-making-security-worse","status":"publish","type":"post","link":"https:\/\/gryph.one\/index.php\/2021\/02\/26\/lastpass-youre-still-making-security-worse\/","title":{"rendered":"LastPass, You&#8217;re Still Making Security Worse"},"content":{"rendered":"\n<p>The thing about password managers is that a security issue there tends to be significantly more severe than with most another applications on a device. Even if you all you get is data exfiltration&#8230;well, you&#8217;re still exfiltrating some pretty fucking important data.<\/p>\n\n\n\n<p>Which is why <a href=\"https:\/\/www.theregister.com\/2021\/02\/25\/lastpass_android_trackers_found\/\" data-type=\"URL\" data-id=\"https:\/\/www.theregister.com\/2021\/02\/25\/lastpass_android_trackers_found\/\">this story<\/a> about trackers in LastPass for Android&#8230;is less than encouraging.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>Quick summary of the story is that German researcher Mike Kuketz saw LastPass listed in Exodus Privacy&#8217;s database of apps with tracking code embedded and decided to look at what was being sent back&#8230;which turned out to be a lot more than was really a good idea.<\/p>\n\n\n\n<p>Now, trackers and analytics code can potentially be used for good &#8212; there&#8217;s a reason developers appreciate having crash reports handy when something breaks &#8212; but they&#8217;re also very easy to use for evil. If you&#8217;re going to stick things like that into your app, you need to be careful about what data you&#8217;re gathering. Especially if the app in question is a password manager.<\/p>\n\n\n\n<p>LastPass is not an example of being careful.<\/p>\n\n\n\n<p>Most password managers on Android don&#8217;t stick trackers in at all, and those that do usually stick to ones designed for analytics and crash reporting. <a href=\"https:\/\/reports.exodus-privacy.eu.org\/en\/reports\/com.x8bit.bitwarden\/latest\/\" data-type=\"URL\" data-id=\"https:\/\/reports.exodus-privacy.eu.org\/en\/reports\/com.x8bit.bitwarden\/latest\/\">Bitwarden, for example<\/a>, uses Google Firebase and a Microsoft Visual Studio crash report plugin. However, LastPass includes multiple trackers designed specifically for advertising. Integrating code you don&#8217;t control into your software can be a dicey proposition, but there are plenty of times when it&#8217;s safer than the alternative. Taking code literally written for the purpose of monetizing every bit of activity you do and integrating it into a password manager is not one of those times.<\/p>\n\n\n\n<p>I could go on a very long rant about just how scummy Internet advertising is as an industry (well, advertising in general, really), but Bill Hicks summed it up way better than I ever could. (CW: suicide)<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Bill Hicks on Marketing\" width=\"656\" height=\"492\" src=\"https:\/\/www.youtube.com\/embed\/tHEOGrkhDp0?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<p>If a stand-up comedian who <a href=\"https:\/\/www.texasmonthly.com\/the-daily-post\/the-conspiracy-theory-that-alex-jones-is-actually-legendary-long-dead-texas-comedian-bill-hicks\/\" data-type=\"URL\" data-id=\"https:\/\/www.texasmonthly.com\/the-daily-post\/the-conspiracy-theory-that-alex-jones-is-actually-legendary-long-dead-texas-comedian-bill-hicks\/\">may or may not have faked his death to become Alex Jones<\/a> can figure out not to trust people who work in advertising, why the FUCK can&#8217;t the rest of you?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The thing about password managers is that a security issue there tends to be significantly more severe than with most another applications on a device. Even if you all you get is data exfiltration&#8230;well, you&#8217;re still exfiltrating some pretty fucking important data.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[14,15],"class_list":["post-79","post","type-post","status-publish","format-standard","hentry","category-security-news","tag-lastpass","tag-password-manager"],"_links":{"self":[{"href":"https:\/\/gryph.one\/index.php\/wp-json\/wp\/v2\/posts\/79","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gryph.one\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gryph.one\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gryph.one\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/gryph.one\/index.php\/wp-json\/wp\/v2\/comments?post=79"}],"version-history":[{"count":3,"href":"https:\/\/gryph.one\/index.php\/wp-json\/wp\/v2\/posts\/79\/revisions"}],"predecessor-version":[{"id":82,"href":"https:\/\/gryph.one\/index.php\/wp-json\/wp\/v2\/posts\/79\/revisions\/82"}],"wp:attachment":[{"href":"https:\/\/gryph.one\/index.php\/wp-json\/wp\/v2\/media?parent=79"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gryph.one\/index.php\/wp-json\/wp\/v2\/categories?post=79"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gryph.one\/index.php\/wp-json\/wp\/v2\/tags?post=79"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}