Password Vault – LastPass is scrambling to patch critical security flaws that malicious websites can exploit to steal millions of victims’ passphrases.
The programming cockups were spotted by Tavis Ormandy, a white-hat hacker on Google’s crack Project Zero security team.
He found that the LastPass Chrome extension has an exploitable content script that evil web pages can attack to extract usernames and passwords.
LastPass works by storing your passwords in the cloud.
It provides browser extensions that connect to your LastPass account and automatically fill out your saved login details when you surf your favorite websites.
However, due to the discovered vulnerabilities, simply browsing a malicious website is enough to hand over all your LastPass passphrases to strangers.
The weak LastPass script uncovered by Ormandy can be tricked into granting access to the manager’s internal mechanisms, which is rather bad news – culled from theregister.com
This is just the tale of one of the leading password managers…
These and more are some of the resons we need to take total control of your data.
ACTION TIME - HOW TO CREATE A SECURITY FOLDER
DIYs Using Gmail
Sign up for a Gmail account if you have none.
Login to your account.
Proceed to enable a 2-FA verification process.
To enable 2-FA verification, Follow through the steps below else Check the video later on.
a. Go to my account
b. Go to Sign in & Security
c. Enter your Password & click Sign-in
d. Scroll down and Click the 2 step verification navigation to turn on.
e. Click on Get Started
f. Enter your email username & Password
g. Choose how you want to get codes (Text message or Phone Call) and click NEXT
h. Enter the code
i. Click Next and follow through. Viola, you’re done!
Now, from where we stopped,
Login to your Gmail account once more.
Compose a simple message and send to your account.
Open the message in your Inbox
Click Move to folder
- Scroll down to create new . CHECK OUT THE REST - http://bit.ly/2v97qGA
Hi! I am a robot. I just upvoted you! I found similar content that readers might be interested in:
https://www.darknet.org.uk/2017/03/lastpass-chrome-extension-leaking-passwords/