Re: [Full-disclosure] Lastpass Security Issue

2011-05-06 Thread Liam Randall
Ryan, The blog post indicates severe security lapses; for example: Why did the asterisks server have connectivity to the db? If there was some kind of mashup I would expect it to have limited connectivity but I'm not aware of anything like that. If these guys are in the business of security

Re: [Full-disclosure] Lastpass Security Issue

2011-05-05 Thread Benji
They've said nothing about what they're going to do to the server with said anomaly. Wouldnt be happy until a full reinstall. On Thu, May 5, 2011 at 11:39 AM, Ryan Sears rdse...@mtu.edu wrote: Hey all, Early this morning the folks over at LastPass decided to issue a warning about a potential

Re: [Full-disclosure] Lastpass Security Issue

2011-05-05 Thread Nick Boyce
On Thu, May 5, 2011 at 9:09 PM, Benji m...@b3nji.com wrote: They've said nothing about what they're going to do to the server with said anomaly. Wouldnt be happy until a full reinstall. From http://blog.lastpass.com/2011/05/lastpass-security-notification.html : We're rebuilding the boxes in

Re: [Full-disclosure] Lastpass Security Issue

2011-05-05 Thread Benji
Sorry, completely missed that part. My bad. On Thu, May 5, 2011 at 10:35 PM, Nick Boyce nick.bo...@gmail.com wrote: On Thu, May 5, 2011 at 9:09 PM, Benji m...@b3nji.com wrote: They've said nothing about what they're going to do to the server with said anomaly. Wouldnt be happy until a full

Re: [Full-disclosure] Lastpass Security Issue

2011-05-05 Thread Cal Leeming
+1 reason why people should never used centralized password / form storage tbh. On Thu, May 5, 2011 at 10:09 PM, Benji m...@b3nji.com wrote: They've said nothing about what they're going to do to the server with said anomaly. Wouldnt be happy until a full reinstall. On Thu, May 5, 2011 at