1Password has none, KeePass has none... So why are there seven embedded trackers in the LastPass Android app?
- Reference: 1614278349
- News link: https://www.theregister.co.uk/2021/02/25/lastpass_android_trackers_found/
- Source link:
German infosec bod Mike Kuketz [1]spotted LastPass's trackers in analysis produced by Exodus, which describes itself as "a non-profit organization led by hacktivists [whose] purpose is to help people get a better understanding of the Android applications tracking issues."
[2]
The [3]Exodus report on LastPass shows seven trackers in the Android app, including four from Google for the purpose of analytics and crash reporting, as well as others from AppsFlyer, MixPanel, and Segment. Segment, for instance, gathers data for marketing teams, and claims to offer a "single view of the customer", profiling users and connecting their activity across different platforms, presumably for tailored adverts.
LastPass has many free users – is it a problem if its owner seeks to monetise them in some way? Kuketz said it is. Typically, the way trackers like this work is that the developer compiles code from the tracking provider into their application. The gathered information can be used to build up a profile of the user's interests from their activities, and target them with ads.
[4]
Even the app developers do not know what data is collected and transmitted to the third-party providers, said Kuketz, and the integration of proprietary code could introduce security risks and unexpected behaviour, as well as being a privacy risk. These things do not belong in password managers, which are security-critical, he said.
Kuketz also investigated what data is transmitted by inspecting the network traffic. He found that this included details about the device being used, the mobile operator, the type of LastPass account, the Google Advertising ID (which can connect data about the user across different apps). During use, the data also shows when new passwords are created and what type they are. Kuketz did not suggest that actual passwords or usernames are transmitted, but did note the absence of any opt-out dialogs, or information for the user about the data being sent to third parties. In his view, the presence of the trackers demonstrates a suboptimal attitude to security. Kuketz recommended changing to a different password manager, such as the open-source [5]KeePass .
LastPass to limit fans of free password manager to one device type only – computer or mobile – from next month [6]READ MORE
Do all password apps contain such trackers? Not according to Exodus. 1Password has none. KeePass has none. The open-source Bitwarden has two for Google Firebase analytics and Microsoft Visual Studio crash reporting. Dashlane has four. LastPass does appear to have more than its rivals. And yes, lots of smartphone apps have trackers: today, we're talking about LastPass.
Password managers are essential for most users since the number of passwords to be managed exceeds our ability to remember them, and the complex passwords needed for security are particularly hard to memorise. Using the same password across multiple services is poor practice because it increases the impact if a password is stolen or inadvertently disclosed.
The discussion about trackers in LastPass comes at a bad time. Earlier this month the company (which is owned by LogMeIn) [7]crippled its free offering to support only a single device type, and many users have said they would switch as a result – like user Mattias Ahnberg, who wrote [8]on Twitter : "This means I will finally migrate away to 1Password instead of being blocked by such a limitation that you're adding." Losing free users may even have been the intention, but the tracking issues affect paid users as well, which would be more of a concern.
A LastPass spokesperson told us: "No sensitive personally identifiable user data or vault activity could be passed through these trackers. These trackers collect limited aggregated statistical data about how you use LastPass which is used to help us improve and optimize the product.
"All LastPass users, regardless of browser or device, are given the option to opt-out of these analytics in their LastPass Privacy Settings, located in their account here: Account Settings > Show Advanced Settings > Privacy. We are continuously reviewing our existing processes and working to make them better to comply, and exceed, the requirements of current applicable data protection standards." ®
[9]
Editor's note: This article was corrected after publication to refer to the more popular KeePass rather than KeyPass. Neither have trackers.
Get our [10]Tech Resources
[1] https://www.kuketz-blog.de/lastpass-android-drittanbieter-ueberwachen-jeden-schritt/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YDgsDNxB3GwEmE9OeTDs9QAAAFI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://reports.exodus-privacy.eu.org/en/reports/165465/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YDgsDNxB3GwEmE9OeTDs9QAAAFI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://sourceforge.net/projects/keepass/
[6] https://www.theregister.com/2021/02/16/lastpass_pricing_changes/
[7] https://www.theregister.com/2021/02/16/lastpass_pricing_changes/
[8] https://twitter.com/ahnberg/status/1361802216869425168
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YDgsDNxB3GwEmE9OeTDs9QAAAFI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://whitepapers.theregister.com/
Re: Privacys is an "advanced option".
Sounds like they sadly missed the opportunity to add a "Beware of the Leopard. Are you sure you don't want to proceed? Y/N" pop-up in the sequence.
Not in my settings!
All LastPass users, regardless of browser or device, are given the option to opt-out of these analytics in their LastPass Privacy Settings, located in their account here: Account Settings > Show Advanced Settings > Privacy
Well in my version of Lastpass in Firefox on OS X there is no such setting!!
Re: Not in my settings!
Not in iOS app either
Re: Not in my settings!
Not in Chrome Windows nor Android app.
Re: Not in my settings!
In one of LastPass' numerous UI design fails, there is also (from the browser)
Security Dashboard -> Account Settings . A dialog comes up with a "Show Advanced Settings" button at the bottom. Click that and scroll down to the bottom, where there is a Privacy section with two checkboxes:
* Keep track of Login and Form Fill History
* Send anonymous reporting data
This is different to what you get from the Account Options menu on the browser add-in, and also to the Advanced Options on the Security Dashboard
The Security Dashboard is just a clusterf*** of poor design that this latest news and the imminent expiry of my LastPass Premium subscription has motivated me to move to another product.
The more doors, the more locks, the more vulnerabilities.
Seriously, security software should be just that. Nothing extra or sponsored by any party.
For each corp
have own agenda and policies and skills.
Next
Nor Android
martingreybeard@gmail.com
KeyPass as an alternative? Are you sure you didn't mean KeePass?
There was a product many years ago that was called KeyPass. Don't think it is still alive.
KeePass is open source, well maintained, has versions that run on all major platforms (well, perhaps not CPM-80).
Re: KeyPass as an alternative? Are you sure you didn't mean KeePass?
Only problem was keeping all my devices in synch between several OS on several laptops plus a mobile phone was a pain in the butt, especially if you have to add a password to your iPhone.
In any case time to give 1password a look. If I’m paying for a service (and I am paying for a family subscription of LastPass), it should not have any 3rd party trackers in it at all!
Re: "Only problem was keeping all my devices in synch"
Just use a cloud service to keep the KeePass DB and use it on all devices, works without a hitch and KeePass even offers to merge the changes when you make them on different copies of the DB
Re: "Only problem was keeping all my devices in synch"
yeah.... When I'd finally decided to use a password vault, I've faced the problem of accesing and synching from multiple devices. Google Drive (because is there for free) work like a charm between my both PC and phones.
(using KeePassDX in the phones downloaded from Druidics, not from GooglePlay)
Re: KeyPass as an alternative? Are you sure you didn't mean KeePass?
Yes, yes, see the note at the end of the article: we meant KeePass. Though KeyPass does exist and also has no trackers, I'm told.
Don't forget to email corrections@theregister.com if you spot anything that looks wrong, please, so we can fix it immediately.
C.
Re: KeyPass as an alternative? Are you sure you didn't mean KeePass?
KeePass is great - I love MacPass implementation for macOS
The company says users can opt out if they want.
The company says users can opt out if they want.
Read: "It's in there somewhere, just search if you really want it"
or "Most users won't care anyway so it doesn't matter it YOU shut it off"
or "Good luck figuring out which magic buttons to press, Muahahahaha!"
or something else that's equally arrogant and/or condescending.
Tracking should be OPT IN or NOTHING. no exceptions.
Re: The company says users can opt out if they want.
Tracking should not be allowed no exceptions.
Re: The company says users can opt out if they want.
"Tracking should be OPT IN or NOTHING. no exceptions."
Tracking MUST be OPT IN or NOTHING. no exceptions. FTFY
Under GDPR and the UK equivalent, all cookie options must be opt-in. Opt-out is not acceptable.
Re: The company says users can opt out if they want.
"Under GDPR and the UK equivalent, all cookie options must be opt-in. "
Which makes me wonder why so many European and UK sites still have only the blarb that says you can change options in your browser. It's about time, if Europe and the UK are serious about their legislation, that they had a simple reporting system for sites that don't comply with the regs.
Re: The company says users can opt out if they want.
"...all cookie options must be opt-in."
Try telling that to Google and its Youtube tentacle. There it's opt-out and the bastards even sneak in one for Doubleclick but somehow forget to mention it.
I was mulling over whether I should report this to the ICO but having been fobbed off in the past I have hesitated. I might give them a buzz and see if I can get any joy this time.
No, no, no.
In that order
> " All LastPass users, regardless of browser or device, are given the option to opt-out of these analytics in their LastPass Privacy Settings, located... "
..next the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying 'Beware of the Leopard.
It's hardly discoverable, if people are unaware of it to begin with, is it?
Lockdown cabin fever
Just before my dad was diagnosed with dementia he kept forgetting all his passwords so I set him up with a password keeper so he'd only have to remember one. He instantly forgot it, and also forgot where he'd written it down.
On the upside we got a bottle of pink gin delivered six months ago but it came with one of those magnetic security seals on it. We got the price discounted but it has been mocking my engineering skills since then. YouTube videos are out of date, here is what I did to get to the nectar. I cut a couple of millimetres on either side of the metal bolts, and then I pulled like fuck. Brute force attack, literally. Wouldn't work in-store, somebody would notice, but fine in your house.
Just justified the reason to leave.
First of all this is a back stab move from Last pass!
Few months ago I became committed to move all my passwords from google to Last pass and just before I heard the news for use on one device I was considering the family pass account.
Now this nonsense with tracking is totally not what I expected. Especially for my kids! They should not and may not be tracked when under aged! (EU law)
Sorry last pass you just lost a potential paying customer!! I'm leaving!!
Re: Just justified the reason to leave.
If you're in the EU, report them to the local data protection authority before you leave. This pressure could do something about that.
moving company now.
After the price increase earlier I moved my personal lastpass over to bitwarden. Now with this revelation I'll be moving the entire companies lastpass over to something else.
Privacys is an "advanced option".
... Welp. ....