LastPass Fixes Fingerprint Bypass In Latest Authenticator Update

A programmer identified as “Dylan M.” recently revealed that he found a vulnerability in the LastPass Authenticator, a two-factor authentication (2FA) Android app similar to Google Authenticator, Authy, and others like them. The flaw could allow malicious applications to bypass the fingerprint/PIN authentication entirely and extract users' 2FA codes. After seemingly waiting six months to fix the bug since the programmer disclosed it privately, LastPass has now issued a patch that fixes the flaw.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • Vatharian
    Last Pass tries again. They are solely responsible for great deal of people staying away from password managers.

    They also bought and killed Xmarks - one and only way to synchronize your profiles across devices using your own server (by WebDAV, but still).
    Reply
  • therealduckofdeath
    It doesn't nullify the reason to use 2FA, it reduces its security. For many years we've used Google's Authenticator without worrying about it not having any built-in security.
    Reply
  • Brian28
    "Additionally, if everyone used a strong unique password, then 2FA apps would largely not be needed"
    That's not true! Even a strong unique password won't protect you against keystroke capture, or phished credentials, but 2FA does.
    Reply
  • therealduckofdeath
    Yeah Brian28, this news post is so full of bad facts it's almost like we're at some phone gadget site.
    Reply