Using Your Android, iOS, Or Blackberry Device To Secure LastPass And More
In a blog post a while back I wrote about LastPass, a sophisticated password manager that provides an incredibly secure way to sync all of your passwords across various browsers and computers. In the guide I walk you through how to set LastPass up and set your PBKDF2 iterations to whatever number you like. This post will deal with setting up Two-Step authentication via Grid or Google Authenticator, and I’ll cover a few more minor features.
Grid Multifactor Authentication
In your LastPass settings panel under the Security tab you’ll find the option to enable Grid Multifactor Authentication.
When you enable MultiFactor Authentication you’ll be presented with two options.
1) Allowing mobile and bookmarkets to bypass grid authentication (NOT recommended, I have it checked there but I shouldn’t)
2) Allowing offline access (I personally wouldn’t use this, but it can make things easier, it just means an encrypted container will be kept on the system)
You should immediately copy, print, and store the grid somewhere secure. Ideally you would keep it printed on paper and carry it with you. This is less than ideal as it could easily be torn. My preferred method is to keep the grid on a USB drive (or two) although I don’t use Grid MultiFactor Authentication.
Your grid will look something like this:
Yours will have different numbers and letters and yours won’t repeat – I have quickly obfuscated my grid by copy/pasting one portion over the entire thing (and then i got lazy and blotched two areas out, poorly). I actually just reset my grid anyways so I don’t know why I bothered… moving on!
When you try to log into an account from a device that hasn’t been whitelist you will be met with a prompt, asking you to fill in coordinates. It will say something like “B9, z7, 4A” and you’ll pick it out form there. There’s a massive combination here.
An attacker who has somehow compromised your password would also need either physical access to your vault or they would have to somehow guess your grid, which is statistically unlikely.
It’s important to note that while your password encrypts your vault the Grid is only a method of authentication, it will not encrypt your passwords. If an attacker has physical access to the vault they will effectively bypass this authentication.
Google Authenticator
This is my personal choice for security, the Google Authenticator. I have an Android device on me at all times (my Galaxy Nexus) so it’s ideal for me.
Google Authenticator, like LastPass, is a way to only allow access to your account by someone with physical access to a key that remains separate from your password. In this case the key is generated every 30 seconds as a 6 digit code, which you then enter in when you wish to log into your LastPass account. As with the Grid Authentication an attacker will need physical access to the device or to your vault as well as already having your password in order to compromise your account.
You can set up Google Authenticator in less than two minutes by installing the app from the Google Play Store and using it to take a picture of your QR code. The QR code would be where my very poor representation is.
Other Features
There are a few other features you may want to check out on the General Tab:
1) Only login from selected countries.
This seems like it would probably be quite simple to bypass, but if you aren’t one to travel outside of the country you can always enable this without worry. Or if you use a proxy to log in you can enable the country it resides in.
2) Disable logins from the TOR network.
The TOR network is built to be completely anonymous. It’s incredibly slow, making it completely unlikely to be used for a bruteforce attack, but some other attack may be possible despite high latency and low bandwidth, so disabling the network is a good idea anyways.
If you set up two factor authentication and follow my guide for creating strong passwords and increasing LastPass iterations you’re going to make your LastPass account incredibly secure, beyond practical attack. In the first guide we make bruteforcing the database impractical, and now we’ve made accessing the database impractical.
3) Check Insecure Logins – Under LastPass Settings, Advanced
LastPass will warn you when you’re filling in a form that’s considered ‘unsafe’. I’m assuming it checks to see if any encryption is used to hash your password or some such thing.
Get Free LastPass Premium (for both of us!) for one moth with this link: https://lastpass.com/f?420446
blog comments powered by Disqus