Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Using LastPass 'One Time Passwords' to Protect Your Data From Key-loggers

Loading...

Sign in or sign up now!
50,569
Loading...
Alert icon
Sign in or sign up now!
Alert icon
There is no Interactive Transcript.

Uploaded by on Jan 20, 2009

Explains how to create and use LastPass 'One Time Passwords' to protect your LastPass vault when using an untrusted computer. LastPass is the Last Password you'll ever have to remember, and is available at LastPass.com

  • likes, 0 dislikes

Link to this comment:

Share to:
see all

All Comments (8)

Sign In or Sign Up now to post a comment!
  • Your master password is kept safe by this mechanism, but if you use any of your stored passwords on a machine with a key logger, then the ones you used can be compromised. If you manually type any in, those are certainly exposed.

    For auto fill is something done to protect against key logging?

    Maybe someone from LastPass can comment on this.

  • A+ work to the Lastpass team.

  • @bestSVMS Not quite sure. However, the database is encrypted and decrypted without them knowing, it's all done client side. So this is likely. From a talk by Steve Gibson, he mentioned a lot of this, and how they go about checking stuff.

    Though I worry that these are soft mechanisms (the software checks and says yes or no) as opposed to hard mechanisms (they can't decrypt without it). The recovery mechanisms some of them have (like the grid), suggest these are soft mechanisms.

  • @uriahsw

    so if you generate 10 otp, it would be encrypted 10 times?

  • @bestSVMS The could transcode it client side. Additionally, you might find that the header is encrypted with your hashed password/etc, and the header then just has to be transcoded. Though given how small the data is, it's likely the whole package is.

    Though I am uncertain. I would like to see more movies about the infrastructure and architecture behind LastPass.

  • so you use one time password insted real password so one stoll the real one?

  • in order to build in the one time passwords, wouldn't that involve LP knowing your password and username? From one of the other videos, he said that username and pass is hashed, and that is used for authentication. That is then hashed again, to encyprt the database. In order to provide the OTP, somehow the database has to be decypted without them knowing the key, which doesn't seem like the case.

  • Excellent tutorial. Awesome program.

Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more