Online password manager By: Anthony diveronica LastPass •••l I would like to begin by saying that I had no idea what LastPass was before this project. I believe I referred to it as a possible “navigation app” during the selection process in class. While LastPass certainly isn’t a service used for navigation, it can be a metaphor for an “EZ pass” in that it removes some of the friction from navigating various sites and services you use that require passwords. Online password manager By: Anthony diveronica
What is LastPass? LastPass is a free online password manager that securely stores usernames and passwords, and makes them available on multiple devices and platforms. LastPass uses state of the art AES256 encryption and SHA-256 password iteration technology to encrypt you information on your machine, and on their web site. LastPass is a free centralized credential service that will store the any number of usernames and passwords a person may have, in one location, that can be accessed across many platforms and devices. LastPass can also store passwords for non-web based services such as applications and protected documents. LastPass uses AES256 encryption and PBKDF2 SHA-256 password iteration technology to encrypt your “master password” both on your local machine, and on the LastPass server. Locally your password is run through a default of 5000 iterations before it is sent to LastPass for authentication.
What is LastPass? LastPass was founded in 2008 Based in Fairfax, VA Office in Paris, France LastPass was acquired in 2015 by LogMeIn Acquired for $110 million dollars Rated first place by PC World magazine Only product reviewed that offers features in all 13 categories tested Site traffic and DAU’s not published Ranked 1,230th most visited site in the US Average user spends about 3 minutes on the site when they visit LastPass was founded in 2008 in Fairfax, Virginia and currently has an office in Paris, France. LastPass was acquired by LogMeIn in 2015 for $110 million. In a May 2017 review of password management sites by PC world LastPass tied for first place with a 5 star score, and was the only password management site to offer features in all 13 categories that were tested. LastPass is ranked as the 1,230th most visited site in the US, and the average visitor spends about 3 minutes on the site.
The heart of LastPass is the vault The heart of LastPass is the vault. This is the area of the web site, or application that contains all of the credentials you have entered into LastPass. It is the first thing you will see when you log into the site. The LastPass vault can also securely store notes, form fill data, shared folders; it also contains links to other areas of the site such as settings and advanced options. Web site credentials are organized into folders based on category. Sites can be moved from one category to the other via drag and drop. The vault also contains a search bar that allows you to search the entire contents of your vault such as web sites, notes, and form fills. LastPass “home page” once you login Web sites are organized by category Additional secure storage features are accessed on the left side of the page The search bar at the top of the screen searched the entire vault
Adding a site to LastPass is easy To add a web site to LastPass, simply navigate to a site that you use often. LastPass provides in form functionality to add credentials. Simply click the LastPass button and select add site. The information is visible in your vault right away. You can now access this information on any device that you have LastPass installed on. The LastPass browser extension provides “in form” username and password capture Once you credentials are entered use the LastPass button in the form to add the site The site and credentials are instantly added to your vault
Adding a site to LastPass is easy Credentials on known sites are auto filled LastPass will show the number of available credentials for the site Once a site is stored in LastPass your credentials auto fill each time you visit it The LastPass button will indicate the number of credentials stored for this website
LastPass works on mobile too In iOS LastPass is accessed via the share button in safari. Tapping the LastPass button will launch the LastPass browser extension. Here, you will be given a choice of credentials for the web site you are on. or you have the option of adding the site. On iOS LastPass in Safari is accessed via the share button Tapping LastPass launches the LastPass extension and displays available credentials You can add a site as well by tapping the 3 dots in the upper right corner
Additional LastPass features Secure Notes Can be used to store wifi passwords, in app passwords, safe combinations, etc… Text entered into the note field is encrypted with the same technology as passwords Notes can have attachments up to 10mb, attachments are encrypted as well Free users get up to 50mb of encrypted data Form Fills Store and auto fill credit card forms, address, bank information, and custom fields Form data is encrypted, and auto fill can be password protected Shared Folders Share files with other LastPass users Files in LastPass folders are encrypted Emergency Access Allow a friend or family member to access you vault in the event of an emergency Defined time delay allows you to decline access
LastPass Premium Features – $12.00/yr Unlimited number of devices Two factor authentication for specific logins Shared folders can have up to 5 users Support for desktop applications Encrypted data storage increased to 1Gb LastPass Enterprise Features – Price varies Shared folders can have an unlimited number of users Administrators console Single sign-on for users Advanced documentation and reporting
Notable Issues Since 2011 the site experienced 6 different security breaches LastPass reports no user data was compromised Support for in application desktop password support is limited Support for “in app” mobile passwords is limited Only applications listed on the LastPass site are compatible User experience is disjointed Different user interface across browsers Different user experience across platforms Will not work on more secure web sites Sites that use separate user name and password pages don’t always work correctly
In conclusion, if you use a single PC and you typically use one browser, LastPass is a great way to store and retrieve your password credentials. If you use multiple PCs, and more than one mobile device you will find the LastPass experience somewhat frustrating and borderline confusing. In a multiple device environment LastPass will function well for a secure place to store information, just don’t expect seamless cross-platform integration.