Reply to post:

LastPass now supports 2FA auth, completely undermines 2FA auth

MrPete

It's not as if people tend to jump to conclusions either :)

Note that the guy who reported "serious problems" with LastPass Authenticator app later had to retract his primary concern: NO, it never was possible to hack in and gain access. That was his own misunderstanding based on an invalid test (using a local image rather than the actual LP-site-based image.)

Their only real vulnerability was to remote turn-off of 2FA. And that's been fixed.

Interestingly, LastPass has proven the security of their system the hard way: their central servers were hacked... and nothing useful was obtained or obtainable about their customers! They don't know, and don't have access to, your passwords, keys or anything else of use to a hacker.

I agree with others, based on experience: NO technology is completely secure. Everything has bugs, everything can in some way be hacked given sufficient time and knowledge of the humans involved. At this point, after extensive testing, I am using LP personally and with family.

LP certainly is not perfect: I have found numerous bugs in the UI, pain-in-the-neck feature implementations, etc etc. But nothing that exposes confidential information. (The main thing I don't like: I can share a record with another account, but the actual password is locked from visibility. In many use cases, that is unacceptable.)

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon