LastPass explained

Thu Apr 10, 2014 3:30 pm

In light of all this HeartBleed stuff, can someone explain in layman's terms how LastPass (or something else similar) actually works. I currently use a handful of different passwords for all my accounts/logins, but it relies simply on my memory. I feel the need to use LastPass, but I just can't seem to wrap my brain around how it works.
Thanks for any insight or advice.
Re: LastPass explained

Thu Apr 10, 2014 3:42 pm

Lastpass stores an encrypted blob on their website that's synced to any of your browsers and/or mobile devices using their service. They never see your plaintext, so in theory they're pretty proof against outside attack. Even though their site was vulnerable to Heartbleed, it didn't matter because all traffic between you and it is encrypted client-side with Javascript before being sent.

When you visit a site you've got an account on, the browser extension notices and can populate your user/pass into the login fields, and optionally automatically log in. It can also generate random passwords of any length and complexity, and automatically create entries in your vault when you create new accounts. You can also create "secure notes" storing things like your Wifi password, SSN, credit card numbers, insurance info, &c. Multiple types of multi-factor authentication are supported, including Google Authenticator, Yubikey (a USB stick with a keyfile), and a grid that you print off and carry in your wallet.

They've got a helpdesk with a bunch of FAQs and tutorial videos, etc.:
Re: LastPass explained

Thu Apr 10, 2014 3:44 pm

LastPass doesn't really protect you against the Heartbleed threat per se, as any password uncovered by the exploit would still grant access to the account on that site, regardless of whether generated/managed by lastpass. What lastpass will do, is generate different passwords for websites/accounts, so that if one site is hacked and a password is compromised, it won't be the one you use for numerous other site.

Somewhat ironically, the laspass site was actually vulnerable to Heartbleed, at least a t first. However, I believe Lastpass employs additional encryption that would have prevented any compromising of user passwords.
Re: LastPass explained

Thu Apr 10, 2014 3:45 pm

This is a little long but this is where I first heard of lastpass and it will give you everything you would need to know about lastpass. I am trying it out now for the first time and it seems pretty easy to use IMO.

