3 ms·
I think you're misunderstanding how you bypass the reprompt. LastPass has two separate features - auto-logoff and reprompt, and you can tick a bunch of boxes to
by STRML 12y ago
I think you're misunderstanding how you bypass the reprompt. LastPass has two separate features - auto-logoff and reprompt, and you can tick a bunch of boxes to decide which features you want reprompt for. I usually tick most of them.
You can then set a reprompt delay (from 0 to 24 hours), and while still logged in, you are reprompted at every interval when you try to use LastPass' features. This is a nice alternative to simply having it log out at intervals or log out when idle; some defense against a swiped computer or malicious coworker, etc. Of course the usual rules apply and you should never leave your computer unlocked but it is a nice feature.
I would except that many LastPass users use the reprompt model instead of the auto-logout model, as it allows you to use some nice features (like site/form detection) that you wouldn't get when logged out. So the workflow with reprompt is simply: go to a site, click the autofill button, get prompted & type password, continue on. This is significantly easier than clicking the extension button, deliberately logged in, waiting for decryption, then clicking the autofill button.
Unfortunately, if you rely on reprompts and somebody does get a hold of your computer, they can do some trickery with the inspector and lift your passwords so long as you are still logged in. This makes the reprompt useless; may as well not have it at all.
- Someone1234 12y agoSo your reason to drop LastPass is that you don't like their implementation of an optional feature even though an alternative is readily available (auto-logout)?