3 ms·
Breaking account locks on Windows is pretty simple, and full-disk encryption is not as easy to pull off as it is on OSX. If someone were to steal the computer,
by STRML 13y ago
Breaking account locks on Windows is pretty simple, and full-disk encryption is not as easy to pull off as it is on OSX. If someone were to steal the computer, they would have as much time as they needed to break the Windows account and raid LastPass. What else could be the point of the master password reprompt, but to give the perception that your passwords are locked after an idle timeout? If it doesn't actually work, they shouldn't have the feature at all.
- giovannibajo1 13y agoI'm not suggesting to activate the feature that asks you to reenter the master password to USE a specific password. I'm suggesting that you force a logoff of your LastPass vault after inactivity. Using a laptop with full-disk encryption, I think 1-day logoff is more than enough for common scenarios (we're not speaking of NSA-going-after-you, as usual). If you're using a laptop without full-disk encryption, I'd agree that the best way is to configure LastPass to automatically logoff when the computer enters standby/hibernate (for enterprises, this kind of configuration can be enforced for all business accounts as a policy). That's still a much better compromise than having it always logged off and having to relogin for any password you use.
- emn13 13y agoHowever, if you do "break-in" without knowing the password you may gain access to most data, but not data encrypted with the user's auth; stored passwords (hopefully including lastpass stores) typically are therefore not accessible.