• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

LastPass Bug Fix Points to Importance of Multi-Factor Security

January 3, 2018

“The new LastPass Authenticator update provides a straightforward fix: Now you can’t access the TOTP codes without a fingerprint scan or PIN, if that additional security feature is enabled.”

LastPass has upgraded the security of its LastPass Authenticator app to address a reported bug.

LastPass Bug Fix Points to Importance of Multi-Factor SecurityThe issue revolved around the password manager app’s time-based one-time password (TOTP) feature, and its support for multi-factor authentication via a fingerprint scan or PIN. Users have the option of adding the latter security so that even if their device is unlocked, a third party can’t gain access to their LastPass vault without a fingerprint scan or PIN; but a security researcher recently found a way to access the app’s TOTP codes without fingerprint or PIN authentication.

The new LastPass Authenticator update provides a straightforward fix: Now you can’t access the TOTP codes without a fingerprint scan or PIN, if that additional security feature is enabled. But even before the fix, the TOTP bypass issue wasn’t so devastating. As the company points out in its announcement of the app update, “the one-time codes are useless without the username and password for the services they are used.” In other words, a hacker would need the victim’s key credentials to take advantage of the TOTPs, so at the point the victim would already be pretty deeply compromised anyway.

Still, for a password manager app like LastPass, the fix was absolutely necessary, given the critical nature of watertight security in this area, and the importance of combining password-based security with biometrics, or at the very least a PIN.

Filed Under: Industry News

Related News & Articles

Trustonic’s ALPS Security Platform Will Discourage Smartphone Theft

Code Suggests Apple’s Mobile ID Will Use Selfie Onboarding

NatWest Trial of Biometric Payment Cards Features FPC Tech

Primary Sidebar

Learn About Mobile ID and Aviation

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • NordPass, Yahoo! Japan, and Regula Keep Up Mobile Biometrics Momentum
  • NordPass Enables Biometric, TOTP-secured 2FA for Business Users
  • Mastercard Solution Certified Under UK’s Digital ID Framework
  • Transatlantic Digital Traveler Identity Project Gets High-Profile Tech Partner
  • Digital Identity Tech Demo Online Event

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld