Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

https://pberba.github.io/security/2020/05/28/lastpass-phishi...

From what I can tell, all of lastpass mfa options are based around some form of otp not webauthn.

We tested the above in our own environment, since we had control of the devices we did not need urls to do it. We just grabbed the data locally to confirm if it was true. At the time lastpass told us webauthn was in the pipeline so we stayed.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: