Page 1 of 1

How does LastPass verify computers?

PostPosted: Thu Nov 22, 2012 6:43 pm
by Hungry_Man
I enabled Two Factor Authentication via Google Authenticator. I then set my computer to not need to use Two Factor Authentication since I use it often and it doesn't leave the apartment. How is this computer trusted though? What is that based on?

In short: How does lastpass verify that "this computer" is "this computer"? IP? MAC? User ID?

Re: How does LastPass verify computers?

PostPosted: Thu Nov 22, 2012 10:27 pm
by jonat
It stores an authentication token in "trusted storage". The method varies by OS.

Re: How does LastPass verify computers?

PostPosted: Thu Nov 22, 2012 10:30 pm
by Hungry_Man
Are there any more details available? Specifically for Windows I suppose. How is the token generated, for example?

Re: How does LastPass verify computers?

PostPosted: Fri Nov 23, 2012 10:30 pm
by jonat
I don't know how the token is generated. Now that I think about it some more, it seems to be some sort of ID generated by LastPass and stored on their server, since you can review a list of trusted computers in Account Settings.

Re: How does LastPass verify computers?

PostPosted: Sun Nov 25, 2012 5:39 pm
by Hungry_Man
Yeah, it's accessible on the web server so I'm not really sure how it works. It has to be storing the identity of the computer somehow.

Re: How does LastPass verify computers?

PostPosted: Sun Nov 25, 2012 11:38 pm
by Bubbly
Does it really matter? The important factor is that it doesn't work correctly everywhere.

I'm in another country right now and have been on the same IP for a month, I have had to reauthorize over 10 times by now.

Re: How does LastPass verify computers?

PostPosted: Sun Nov 25, 2012 11:45 pm
by Hungry_Man
As it works for me, what matters is whether it's secure or not, yes.