LastPass Vulnerable To Simple Phishing Attack

Megalith

24-bit/48kHz
Joined
Aug 20, 2006
Messages
13,000
Those of you who use the password manager should check this out and take the necessary precautions.

I call this attack LostPass. The code is available via Github. LostPass works because LastPass displays messages in the browser that attackers can fake. Users can't tell the difference between a fake LostPass message and the real thing because there is no difference. It's pixel-for-pixel the same notification and login screen.
 
Been using LastPass for a while now. Honestly, if something wants me to relog, I'll open a new browser window and go directly to lastpass.com and sign in.
 
Back
Top