Security Notification Emails - Site Password Change

What do you love about LastPass? What do you hate about it? Tell us why you like it, why you don't, and why.

Moderators: admin, anatoly_LP, chantieLP, JoeSiegrist, robyn

Security Notification Emails - Site Password Change

Postby oakside » Tue May 15, 2018 12:40 am

I recently started getting emails from LastPass after every change of password to any site. Examples:

LastPass Security Notification: Site Password Change
Site Password Change
You recently requested a secure operation for your LastPass account.
You utilize a SECURITY EMAIL so you must check THAT email account to view the security notification.

LastPass Security Notification: Site Password Change
Site Password Change
This is an advisory notice letting you know that one of the sites stored in your LastPass vault has had its password changed.
Site Hostname xxxxxxxxxx.com
Time of Change 2018-05-14 xx.xx.xx
From IP Address xx.xx.xx.xx


Yes, I'm actually getting two emails now (a second to my "security email") for every single password I change. Is this intended? (Why is a basic password change now considered a "secure operation for your LastPass account"?) This means people are going to get so many LastPass emails that it will inevitably lead to other more serious problems, like not fully reading them (they will soon feel like useless "false positive" alerts), filtering into trash, not changing passwords as often, etc.

Please: Keep these security notification emails important. Do not send these emails for every password change. Or at least allow people to opt out of these particular emails, which I must note that we've done absolutely fine without for years now. It seems some people on the dev team may be going insane and really overthinking this.
oakside
 
Posts: 6
Joined: Fri Apr 04, 2014 5:22 am
Location: Internets, USA

Re: Security Notification Emails - Site Password Change

Postby nicmart » Tue May 15, 2018 4:26 am

Yes, please this is very annoying. Ther eis no option in the vault account settings to disable those spam email notifications either!
nicmart
 
Posts: 1
Joined: Wed Dec 23, 2015 8:23 am

Re: Security Notification Emails - Site Password Change

Postby umtul » Tue May 15, 2018 8:52 am

I have already made a ticket about this a few hours before you opened this thread. This real shitty feature must be brand new, like 1 day old.

Look what they answered me:

Hi there,

Thanks for reaching out to LastPass support, we're happy to assist!
Please follow the steps provided in this article to help resolve this issue:
https://lastpass.com/support.php?cmd=showfaq&id=6266


They have shown me the way to disable promotional mails. This setting does not affect those security mails, I have tested it.

I am a year long user, what the heck is this? Why does LastPass expose my data to an unsecure email? When I change usernames I know that I have changed them, I don't need a notification. Please, there must be a possibility to deactivate them! Otherwise this is a deal breaker for a lot of people with privacy concerns. Certainly will be leaving LastPass if this is not fixed.
umtul
 
Posts: 3
Joined: Tue May 15, 2018 8:49 am

Re: Security Notification Emails - Site Password Change

Postby s3condsunr1se » Wed May 16, 2018 10:09 am

I've started getting these emails as well. It's sending one email to the email address used to login to LastPass and an additional email to my security email address. This is so annoying and THERE'S NO WAY TO DISABLE THEM! Why would you do this LastPass? This needs to be posted in r/crappydesign
s3condsunr1se
 
Posts: 2
Joined: Wed May 16, 2018 10:03 am

Re: Security Notification Emails - Site Password Change

Postby jpenny84 » Wed May 16, 2018 11:05 am

s3condsunr1se Wrote:I've started getting these emails as well. It's sending one email to the email address used to login to LastPass and an additional email to my security email address. This is so annoying and THERE'S NO WAY TO DISABLE THEM! Why would you do this LastPass? This needs to be posted in r/crappydesign


You can go into your email preferences and shut them off:

https://lastpass.com/support.php?cmd=showfaq&id=6266
jpenny84
 
Posts: 7981
Joined: Tue Mar 06, 2012 9:10 pm

Re: Security Notification Emails - Site Password Change

Postby s3condsunr1se » Wed May 16, 2018 1:50 pm

You can go into your email preferences and shut them off:

https://lastpass.com/support.php?cmd=showfaq&id=6266


No, you can't.

As stated by umtul above:

They have shown me the way to disable promotional mails. This setting does not affect those security mails, I have tested it.


I have also tried changing these settings and they do not affect the emails.
s3condsunr1se
 
Posts: 2
Joined: Wed May 16, 2018 10:03 am

Re: Security Notification Emails - Site Password Change

Postby iamjamieq » Wed May 16, 2018 2:20 pm

I was so hoping I'd find a solution here. Looks like they implemented a new feature but not the way to opt-out yet. Which is annoying, especially considering the bottom of the email says that email opt-out settings were ignored. I'm to going to create a Gmail filter, which will effectively solve the problem for me. But I shouldn't have to.
iamjamieq
 
Posts: 3
Joined: Wed May 16, 2018 2:18 pm

Re: Security Notification Emails - Site Password Change

Postby oakside » Fri May 18, 2018 4:50 am

Thanks for the feedback and support on this issue, everyone.

iamjamieq Wrote:I was so hoping I'd find a solution here. Looks like they implemented a new feature but not the way to opt-out yet. Which is annoying, especially considering the bottom of the email says that email opt-out settings were ignored. I'm to going to create a Gmail filter, which will effectively solve the problem for me. But I shouldn't have to.

Yup. My first thought was, "I guess it's time for a Gmail filter." But we would all like to avoid that, as it can cause other complications if not careful. Also, I did notice that statement ("opt-out settings are ignored") at the bottom of the emails, which makes it sound like there will not be any settings via LastPass that disable them.

Obviously I don't want important security notifications disabled. However, "site password change" does not seem to be important enough to warrant inclusion into that critical group. It should be classified as some other notification, with an option to disable.
oakside
 
Posts: 6
Joined: Fri Apr 04, 2014 5:22 am
Location: Internets, USA

Re: Security Notification Emails - Site Password Change

Postby fugue » Fri May 18, 2018 7:55 am

My problem with this (apart from the minor irritation) is that I consider my sites confidential information. This new "feature" is effectively broadcasting sensitive corporate URLs and porn viewing habits using insecure e-mail. I would expect a notification by e-mail only when suspicious activity was detected on my account.
fugue
 
Posts: 1
Joined: Fri May 18, 2018 7:51 am

Re: Security Notification Emails - Site Password Change

Postby FlyingHawk » Fri May 18, 2018 11:01 am

Emails from LastPass are sent over TLS. As long as your email service supports TLS (e.g. Gmail), it's encrypted in transport and not inherently insecure.
FlyingHawk
 
Posts: 456
Joined: Wed Mar 18, 2015 12:04 pm

Next

Return to Feedback

Who is online

Users browsing this forum: No registered users and 17 guests