• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

LastPass Hacking Method Highlights Digital Security Issues

January 22, 2016

LastPass Hacking Method Highlights Digital Security IssuesLastPass, the popular password manager service, is coming under some scrutiny in the wake of a hacker’s claims that he has found a way to overcome its major security processes.

The hacker in question is Sean Cassidy, Praesidio’s CTO, who spoke about his method, which he calls “LostPass”, at the ShmooCon hacker conference. Essentially, his method boils down to developing software that mimics the LastPass login overlay that pops up prompting a user to enter her master password, and even her second authentication factor, if that extra layer is enabled. The hacker would then gain access to the user’s main repository of password information.

It isn’t a perfect scheme, though. The LostPass method requires a user to visit a malicious or infected site, and it isn’t clear that it could actually capture the user’s second authentication factor if the user has opted for a fingerprint scan in that case. Meanwhile, LastPass has been highlighting solutions to this issue, and working on more. For example, the platform sends out email verification for instances in which a user tries to access LastPass from an unknown IP address, which should potentially prevent a hacker from gaining access from remote location, given that the user has a strong password—and, better still, two-factor authentication—for email. The company also advises users to always log in via their LastPass browser extensions, as the LostPass hack will suggest they have been logged out of LastPass when they haven’t.

Going forward, the implementation of even more sophisticated security measures like multimodal biometric authentication could act as a further bulwark against this kind of attack. For now, though, the digital security battle wages on.

Sources: The Guardian, LastPass

Related News & Articles

Apple Patent Expands the Touch Bar with Face ID and Retinal Scanning

Zwipe Sees No Negative COVID-19 Effects in Q1 Update

‘MaliBot’ Malware Can Hack Android Phones and Get Past MFA Security

Primary Sidebar

Learn About Mobile ID and Aviation

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • NordPass, Yahoo! Japan, and Regula Keep Up Mobile Biometrics Momentum
  • NordPass Enables Biometric, TOTP-secured 2FA for Business Users
  • Mastercard Solution Certified Under UK’s Digital ID Framework
  • Transatlantic Digital Traveler Identity Project Gets High-Profile Tech Partner
  • Digital Identity Tech Demo Online Event

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld