Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pwman
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
pwman
8y ago
This has been the case since at least 2003... The agents also see you page history, search terms, can cobrowse with you to show you things. Anything to make them quicker and more effective is implemented.
2.
▲
by
pwman
9y ago
Have you had your levels checked by your doctor? My doctor said I was low for a year, as they came up I started sleeping much better -- can't see many other differences.
3.
▲
by
pwman
9y ago
That's not how AppArmor works provided you lock down your server software properly -- say the server running is NTP -- that NTP server is only able to read /etc/ntp/* and /usr/sbin/ntpd only able to writ
4.
▲
by
pwman
9y ago
LastPass
5.
▲
by
pwman
9y ago
A request to https://1min-ui-prod.service.lastpass.com was necessary to attack this, that request has a referring URL sent by default by Chrome / Firefox / Safari.
6.
▲
by
pwman
10y ago
Considering your size you should definitely checkout a trial of LastPass Teams: https://www.lastpass.com/teams Full Disclosure: Work for LastPass
7.
▲
LastPass logo changing
(blog.lastpass.com)
1 points
by
pwman
11y ago
|
0 comments
8.
▲
by
pwman
11y ago
Interesting, I hadn't heard of Password Alert -- we should definitely share notes if you're open to it -- I'd love to be able to generalize what we're doing to other domains if we could -- it's unfortunately cpu int
9.
▲
by
pwman
11y ago
Yes, we're pushing the notification to a new tab (which can't be blocked or interfered with) once it goes through QA -- likely early next week. Also even multifactor now must be new location verified so the ability to exploit this
10.
▲
by
pwman
11y ago
LastPass has pushed Google for years to give us a way to avoid using the browser viewport: infobars was a solution to this issue -- you can see one of my pleas for it back in January 2012: https://code.google.com/p/chr
11.
▲
by
pwman
11y ago
LastPass doesn't have access to your symmetric key, it doesn't have access to your private RSA key either. It's all locally encrypted and locally generated. LastPass does have access to your public key (which is safe and
12.
▲
by
pwman
11y ago
Washington DC has been doing it as long as I can remember: https://en.wikipedia.org/wiki/Slugging Basically pickup someone random so you can utilize HOV.
13.
▲
by
pwman
11y ago
Heartbleed showed us that many certificate authorities reissue certificates from the original date they were first issued.
14.
▲
by
pwman
11y ago
LastPass has AD Sync capability and has for years with large customers using it: https://enterprise.lastpass.com/enterprise-administration-ba...
15.
▲
by
pwman
11y ago
Some of your sites are storing your password in plain text, see http://plaintextoffenders.com/ for a few. Once a single one of those is hacked your method is exposed and it goes from improbable to practical.
16.
▲
by
pwman
11y ago
Yes, but it's after 100,000 rounds of PBKDF2.
17.
▲
by
pwman
11y ago
Understood -- you may want to consider a combination open source command line version + mobile + mac apps: https://github.com/LastPass/lastpass-cli If your coworkers aren't using something they're likely reu
18.
▲
by
pwman
11y ago
In fact LastPass didn't have it at first, but after dozens of impassioned pleas from people with disabilities we made the decision to add it with a very strong warning against using it. LastPass Enterprise has a policy to disable it, w
19.
▲
by
pwman
11y ago
Full Disclosure: I work at LastPass. > "Turning on 2FA did not worked most of the times" If you have a security issue here we'd appreciate a report at https://lastpass.com/security/ that said every r
20.
▲
by
pwman
11y ago
Mozilla used to be the best place in the world for extension developers -- it was natural to have your best extension on Firefox because you could release early and often. Active developers made the platform. When Chrome came along they de
21.
▲
by
pwman
11y ago
Correct -- It's a pet peeve of mine when login processes obscure this saying invalid password when the sign up process doesn't -- if you're going to tell people usernames aren't available then you shouldn't be avoid
22.
▲
by
pwman
12y ago
LastPass - https://LastPass.com/jobs - Fairfax, VA (DC metro, Dunn Loring metro stop) Our open tech roles are: - Software Engineer iOS - Software Engineer OSX - Junior Software Engineer - Senior Software Engineer
23.
▲
by
pwman
12y ago
How are LastPass' organization features broken? Over 7,500 companies are using them successfully. https://enterprise.lastpass.com/enterprise-administration-ba...
24.
▲
by
pwman
12y ago
It's not a 'we let them publish' it's a we respected their wishes in that we would hold off on talking about it until they published.
25.
▲
by
pwman
12y ago
If we stole the thunder from security researchers by announcing about things they've found before they can we'd risk that they'd consider holding back. I feel it's the right move to encourage the researchers and respec
26.
▲
by
pwman
12y ago
Fairfax VA (Washington DC area near metro) local preferred REMOTE possible for the very talented. jobs@lastpass.com LastPass, you know it, you love it, you want to make it better.
27.
▲
by
pwman
12y ago
Exactly!
28.
▲
by
pwman
12y ago
Regarding firefox -- Are you speaking of the fact that Mozilla refused our Firefox updates for over a year? We're happy you found a tool that works for you -- that's what we want everyone to do -- it doesn't need to be LastPa
29.
▲
by
pwman
12y ago
NO! It's all done locally via JavaScript -- we never want to get your master password / encryption key -- we go through great pains to ensure that never happens.
30.
▲
by
pwman
12y ago
Thanks, looks like a good lead.
More ›