3 ms·
I use Yubikey 2FA. That still doesn't fix the problem that all of your data is accessible while logged in, and that the usability goes to hell if you don't stay
by STRML 12y ago
I use Yubikey 2FA. That still doesn't fix the problem that all of your data is accessible while logged in, and that the usability goes to hell if you don't stay logged in.
- ttt 12y ago"That still doesn't fix the problem that all of your data is accessible while logged in" This sounds like a non-vulnerability to me. You can't get mad at Ford because someone stole your car when you sat them in the front seat and left the keys in the ignition. Why not log out?
- STRML 12y agoOkay, this is a crappy metaphor, but imagine they had a feature where you could put the car in standby while you went out for a quick errand, and just press a button to start the car up again without inserting the key, but the key has to be in your pocket. Except, as it turns out, you don't need the key, it'll just start if you jiggle the wires under the steering column a bit. So the standby feature is useless. LastPass has a series of reprompt options for all sorts of actions, such as opening password /secure note entries, logging in with a password, etc., and you can make those reprompts time out; so, for example, you can keep the thing turned on (so autofills will be prompted, passwords can be generated, etc), but doing anything meaningful with it will require a reprompt after a short amount of time. As I've discovered, even with the reprompts enabled, you can access the data, so the option is IMO totally useless.
- lectrick 12y agoAre... you sure it's possible to get what you think it is you want to get? Because it sounds like you want to have your cake and eat it too, which may not be possible in this case.
- STRML 12y agoI like the reprompt feature as they have it - you can stay logged in, you can be prompted to autofill on websites, and you can use the password generator, but in order to open or save a site or note you are reprompted after a timer (x minutes since the last reprompt). That reprompt doesn't require the 2FA device but it still requires your master password. Perhaps I am overreacting but this was a really nice workflow, and it's disappointing to see that it doesn't quite work from a security standpoint. It is perhaps better to not use it at all, but to set a very fast idle timeout so in case of a stolen laptop, in the time it would take an attacker to crack your login password (if it happens at all), LastPass completely logs out.