XKCD Secure Password

Tell us what features would make LastPass even better and vote for features that are most important to you

Moderators: admin, anatoly_LP, chantieLP, JoeSiegrist, robyn

XKCD Secure Password

Postby TomC » Mon Sep 09, 2019 9:44 pm

One XKCD online comic pointed out that the best password and encryption is only as safe as the user is safe from being beaten to reveal it.

Could there be a feature where a user could pick a secondary 'HELP!' password which is accepted exactly as if it were the main password, but also signals a LastPass service to notify a trusted authority that the user is being coerced into entering their password?

Users might be advised to make their emergency password be their usual password with several characters or a word added or changed. That would make it easier to recall under duress, but hard to accidentally enter. The modified password also shouldn't raise suspicions - e.g. the user should NOT just add "911" to the end!

Perhaps there might be optional features like activating the user's device camera / microphone to live-stream to an online service, so the authorities can quickly get a better idea what is going on. (Though this might be an issue if the camera/microphone turns on an LED when active, as some laptops do.)
TomC
 
Posts: 2
Joined: Mon Sep 09, 2019 8:42 pm

Re: XKCD Secure Password

Postby FlyingHawk » Tue Sep 10, 2019 2:15 am

Directly contacting the authority can be very problematic and difficult to implement.
Sending an email/message/push notification to one or a few trusted contacts of the user's choosing may be practical though.
Activating camera/microphone seems way out of scope for LastPass.

The idea is cool, but I suspect it would have little practical use for it to be a priority, especially compared to many other feature/bug fix requests that users have.
FlyingHawk
 
Posts: 798
Joined: Wed Mar 18, 2015 12:04 pm

Re: XKCD Secure Password

Postby TomC » Tue Sep 10, 2019 3:35 am

OnStar is able to notify authorities if a client needs help or doesn't respond after an apparent accident, so I don't see a particular difficulty on that side of things. Possibly the task could even be jobbed out to OnStar.

It won't be a common occurance, of course - but certain clients are more likely than others to need it and want to pay for it - e.g. the sort of person who puts a 'safe room' in their home.

On the other hand, when you need it, you REALLY want it, whether you're very rich or not. Even a middle-class person might be willing to pre-authorize a significant service charge that would only be applied if they do make use of it.

And yes, activating the camera/microphone does add to the complexity, but I thought it was worth mentioning.
TomC
 
Posts: 2
Joined: Mon Sep 09, 2019 8:42 pm

Re: XKCD Secure Password

Postby FlyingHawk » Tue Sep 10, 2019 12:55 pm

TomC Wrote:OnStar is able to notify authorities ...

OnStar is sooo different from LastPass that comparison isn't meaningful.
One big freaking difference is that OnStar controls the hardware (AFAIK). Also it's a subsidiary of GM!
In comparison LastPass is a tiny software only company.
FlyingHawk
 
Posts: 798
Joined: Wed Mar 18, 2015 12:04 pm


Return to Feature Requests

Who is online

Users browsing this forum: No registered users and 16 guests