• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

FindBiometrics

FindBiometrics

Global Identity Management

  • Biometrics
    • What are Biometrics?
    • FAQ
    • Biometric Associations
    • Companies
    • Premier Partners
  • News
    • Featured Articles
    • Interviews
    • Thought Leadership
    • Podcasts
    • Webinars
    • Year in Review
  • Applications
    • Biometric Security
    • Border Control and Airport Biometrics
    • Consumer and Residential Biometrics
    • Financial Biometrics
    • Fingerprint & Biometric Locks
    • Healthcare Biometrics
    • Justice and Law Enforcement Biometrics
    • Logical Access Control Biometrics
    • Mobile Biometrics
    • Other Biometric Applications
    • Physical Access Control Biometrics
    • Biometric Time and Attendance
  • Solutions
    • Behavioral Biometrics
    • Biometric Sensors and Detectors
    • Facial Recognition
    • Biometric Fingerprint Readers
    • Hand Readers & Finger Scanners
    • Iris Recognition
    • Biometric Middleware and Software
    • Multimodal Biometrics
    • Physiological Biometrics
    • Smart Cards
    • Vein Recognition
    • Voice and Speech Recognition
  • Stocks
  • Events
  • Companies
  • Podcasts

LastPass Authenticator Update Fixes Reported Bug

January 4, 2018

“The new LastPass Authenticator update provides a straightforward fix: Now you can’t access the TOTP codes without a fingerprint scan or PIN, if that additional security feature is enabled.”

LastPass has upgraded the security of its LastPass Authenticator app to address a reported bug.

LastPass Authenticator Update Fixes Reported BugThe issue revolved around the password manager app’s time-based one-time password (TOTP) feature, and its support for multi-factor authentication via a fingerprint scan or PIN. Users have the option of adding the latter security so that even if their device is unlocked, a third party can’t gain access to their LastPass vault without a fingerprint scan or PIN; but a security researcher recently found a way to access the app’s TOTP codes without fingerprint or PIN authentication.

The new LastPass Authenticator update provides a straightforward fix: Now you can’t access the TOTP codes without a fingerprint scan or PIN, if that additional security feature is enabled. But even before the fix, the TOTP bypass issue wasn’t so devastating. As the company points out in its announcement of the app update, “the one-time codes are useless without the username and password for the services they are used.” In other words, a hacker would need the victim’s key credentials to take advantage of the TOTPs, so at the point the victim would already be pretty deeply compromised anyway.

Still, for a password manager app like LastPass, the fix was absolutely necessary, given the critical nature of watertight security in this area, and the importance of combining password-based security with biometrics, or at the very least a PIN.

—

(Originally posted on Mobile ID World)

Related News

  • Identity School: These Seven Questions Can Save You From a Biometrics Privacy LawsuitIdentity School: These Seven Questions Can Save You From a Biometrics Privacy Lawsuit
  • EVENT REPLAY: The Enterprise Biometrics Virtual Identity SummitEVENT REPLAY: The Enterprise Biometrics Virtual Identity Summit
  • Aratek to Showcase New Border Kiosk at 6th Annual BMICAratek to Showcase New Border Kiosk at 6th Annual BMIC
  • Liberia Picks a Winner in Biometric Voter Registration Project: Identity News DigestLiberia Picks a Winner in Biometric Voter Registration Project: Identity News Digest
  • Future-Proof MFA with BiometricsFuture-Proof MFA with Biometrics
  • ID Talk Podcast: Charting the Road Ahead for Biometrics and Identity with Acuity’s Maxine MostID Talk Podcast: Charting the Road Ahead for Biometrics and Identity with Acuity’s Maxine Most

Filed Under: News Tagged With: Biometric, biometrics, Fingerprint, LastPass, LastPass Authenticator

Primary Sidebar

Identity is Shaping Air Travel – Time to Invest

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

TECH5 logo

TECH5 is an international technology company founded by experts from the biometrics industry, which focuses on developing disruptive biometric and digital ID solutions through the application of AI and Machine Learning technologies.

TECH5 target markets include both Government and Private sectors with products powering Civil ID, Digital ID, as well as authentication solutions that deliver identity assurance for various use cases. 

Learn more: www.tech5.ai

Mobile ID World Logo

Mobile ID World is here to bring you the latest in mobile authentication solutions and application providers. Our company is dedicated to providing users with the best content and cutting edge information on technology, news, and mobile solutions for your mobile identity management needs.

Recent Posts

  • NECAM Gets a New CEO: Identity News Digest
  • Onfido Delivers 15-second Identity Verification for UK’s Co-operative Bank
  • Two-Thirds of the Planet Have Biometric ID – ZKTeco USA President Manish Dalal at ISC West 2023
  • Biometrics and Mobile ID on the Innovation Highway: Sponsors and Sessions Announced
  • Who Are Moscow’s Surveillance Tech Vendors?—Identity News Digest

Biometric Associations

IBIA and fido

Tweets

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 FindBiometrics