Chrome Extension: Add option to allow "Open My Vault" only after entering again Master PW

cancel
Showing results for 
Search instead for 
Did you mean: 

Chrome Extension: Add option to allow "Open My Vault" only after entering again Master PW

0 Kudos

Chrome Extension: Add option to allow "Open My Vault" only after entering again Master PW

When opening Chrome (or probably any other browser that supports the LastPass extension) and a user is logged in, the extension is active (red icon with the three dots).  When clicking on the extension icon, there is the menu item "Open My Vault" for accessing the complete vault, without the need to bypass any other barrier.

 I consider this a potential security risk. Assuming that a user may leave her computer unattended for a short time, a person passing by could access with a single click the complete vault.

Hence my request: add an option to require entering the master password again when opening the vault. 

 

Thanks. 

 

 

   

2 Comments
GlennD
GoTo Manager
Status changed to: New

Hi @Damos 

 

Thank you for the feedback. There are already preferences in the browser extensions (logout when browser is closed), and the Account Settings (Require Master Password Re-prompt), that solve for this use case.

 

SJ7771
New Member

The above solution does not solve the issue the OP was asking.   Instead it provides a manual bandaid.    What OP and others are asking for is for this security flaw to be addressed in a proper manner.

 

IF WE CLOSE chrome, the Lastpass Extenstion should sign out, hence we reopen chrome, the Lastpass extension should prompt for the Master Password instead of automatically logging in.   

 

1 - logout when browser is closed solution does not sign LastPass extension out when closing the chrome browser.

2 - Require Master Pasword Re-prompt is a manual bandaid,  reducing the efficiency of Last Pass