Recommended Posts

Hey, so I've started using LastPass and I'm in the process of updating passwords to randomly generated ones.

This is fine when I'm using my own computer, as the plugin is installed so all I need to remember is my master password.

But what's the solution if I'm using a different computer and can't install the plugin? (e.g. public computer, friend's computer etc)

Link to comment
https://www.neowin.net/forum/topic/985678-using-lastpass-without-plugin/
Share on other sites

just access the lastpass website and you can access all your passwords.

you could also store passwords on thumbdrive, etc.

http://helpdesk.lastpass.com/lastpass-portable/

https://lastpass.com/support_faqs.php

AES utilizing 256-bit keys.AES-256 is accepted by the US Government for protecting TOP SECRET data. AES is implemented in JavaScript for the LastPass.com website, and in C++ for speed in the Internet Explorer and Firefox plug-ins. This is important because your sensitive data is always encrypted and decrypted locally on your computer before being synchronized. Your master password never leaves your computer and your key never leaves your computer. No one at LastPass (or anywhere else) can decrypt your data without you giving up your password (we will never ask you for it). Your key is created by taking a SHA-256 hash of your password. When you login, we make a hash of your username concatenated with your password, and that hash is what's sent to verify if you can download your encrypted data.

Your LastPass Master password and encryption key generated from it never leaves your computer - so you are the only person who can decrypt your data

passwords are never "displayed" in clear text. Unless you go into the interface and say show.

You can copy the usernames and passwords from the website from a public computer, or you could use a complete portable solution with say firefox on a usb and lastpass on the usb as well.

  On 28/03/2011 at 16:40, xWhiplash said:

So when you log in to it on a public computer without the plugin, are the passwords displayed in plain text? How does it work on public machines?

Yeah you're able to copy + paste without revealing the passwords themselves, though you can 'show' if you want (which is a little too easy to click for my liking, but it's ok)

  On 27/03/2011 at 17:30, Bhav said:

Hey, so I've started using LastPass and I'm in the process of updating passwords to randomly generated ones.

This is fine when I'm using my own computer, as the plugin is installed so all I need to remember is my master password.

But what's the solution if I'm using a different computer and can't install the plugin? (e.g. public computer, friend's computer etc)

Ohhh interesting, didn't know it did this.

I'll have to go have a look at it, I assume there is a firefox extension? Yes I know pretty lame thing to ask when it takes a minute to look up, but I'm heading out in 5.

  On 28/03/2011 at 17:20, Audioboxer said:

Ohhh interesting, didn't know it did this.

I'll have to go have a look at it, I assume there is a firefox extension? Yes I know pretty lame thing to ask when it takes a minute to look up, but I'm heading out in 5.

Yeah if you just download the exe off the website, you can install plugins for Firefox, IE and Chrome in one go.

And the plugin itself has the random generator, with which you can specify number of characters, upper/lower case, numbers etc.

It usually detects that you're changing passwords too, so a little bar drops down offering to fill your current password and generate a new one. Pretty clever really.

There are lots of LastPass guides/tips you might want to google for, as they give a good idea of all its nifty features.

Hmm...maybe I'm wrong, looks like copy + pasting without revealing doesn't work, it just pastes the masked dots.

So yeah this seems like a bit of a weakness.

On the one hand, you can log into your lastpass account anywhere, create a bookmarklet and that will let you log into wherever you need.

On the other hand, if you log into your lastpass account, you can easily reveal your password by clicking "show"...which obviously shouldn't really be so simple.

I guess that's why the master password needs to be extremely strong.

(The bookmarklet also works on Android)

Edit: Oh! When you log into the lastpass website, you can just double click on the site you want to log into. So no need to go anywhere near revealing the password. You just double click, it takes you to the site and tries to log in.

http://forums.lastpass.com/viewtopic.php?f=12&t=114&start=0

  On 28/03/2011 at 17:57, Bhav said:

Hmm...maybe I'm wrong, looks like copy + pasting without revealing doesn't work, it just pastes the masked dots.

So yeah this seems like a bit of a weakness.

On the one hand, you can log into your lastpass account anywhere, create a bookmarklet and that will let you log into wherever you need.

On the other hand, if you log into your lastpass account, you can easily reveal your password by clicking "show"...which obviously shouldn't really be so simple.

I guess that's why the master password needs to be extremely strong.

(The bookmarklet also works on Android)

Edit: Oh! When you log into the lastpass website, you can just double click on the site you want to log into. So no need to go anywhere near revealing the password. You just double click, it takes you to the site and tries to log in.

http://forums.lastpass.com/viewtopic.php?f=12&t=114&start=0

Awesome! I'm just back and was doing a bit of reading and it's good to see it'll be easy to use sites on other people's computers. I was a bit apprehensive to use generated passwords as there is NO chance I'm remembering them :laugh:

  On 28/03/2011 at 18:05, Audioboxer said:

Awesome! I'm just back and was going a bit of reading and it's good to see it'll be easy to use sites on other people's computers. I was a bit apprehensive to use generated passwords as there is NO chance I'm remembering them :laugh:

Yeah precisely, that was my apprehension too. But actually my using of firefox has changed very little because everything is just saved in a very similar way to the built-in password manager. The make-or-break will be whether or not it works smoothly when I'm using a different computer...which I'll test properly later.

  On 27/03/2011 at 17:33, BudMan said:

just access the lastpass website and you can access all your passwords.

you could also store passwords on thumbdrive, etc.

http://helpdesk.lastpass.com/lastpass-portable/

Have been using lastpass for a while now but never knew about this thanks :D

Ah damit.

So just went onto my brother's computer, which doesn't have the plugin installed.

Logged into lastpass.com, tried double clicking on a site in my list of logins, and it just opens up that entry and offers to show the password.

I guess that'll get the job done, but it's not ideal. So the most appropriate solution will be to use a bookmarklet (or the portable usb thing, which is too much hassle imo)

  On 28/03/2011 at 18:08, Bhav said:

Yeah precisely, that was my apprehension too. But actually my using of firefox has changed very little because everything is just saved in a very similar way to the built-in password manager. The make-or-break will be whether or not it works smoothly when I'm using a different computer...which I'll test properly later.

When you're on another computer without lastpass and you login to your vault, double clicking or clicking visit URL does NOT automatically enter the password. You have to manually copy it which means clicking show.

edit: Just noticed your post above :p

  On 28/03/2011 at 18:47, Bhav said:

Yeah, think I might post on the official forums, see if they have a solution (or at the very least, highlight that it's something they should look into).

Bookmarklets does the trick, the only thing is if you leave it as a bookmark on someones PC can they not just have a field trip with your passwords? Guess you just have to remember to log out of lastpass.com.

  On 28/03/2011 at 18:51, Audioboxer said:

Bookmarklets does the trick, the only thing is if you leave it as a bookmark on someones PC can they not just have a field trip with your passwords? Guess you just have to remember to log out of lastpass.com.

Yeah you need to log out. Again, not ideal.

It really would be the best solution if you could just double click!

Anyway, will see what they say over there.

http://forums.lastpass.com/viewtopic.php?f=12&t=65639

  On 28/03/2011 at 18:56, Bhav said:

Yeah you need to log out. Again, not ideal.

It really would be the best solution if you could just double click!

Anyway, will see what they say over there.

http://forums.lastpass.com/viewtopic.php?f=12&t=65639

Look forward to seeing if there's any other solutions. I don't think they'll be able to get it working from double clicking - I think that only works for us as the plugin is installed. Don't think there will be a way to inject your username/password on a vanilla setup, hence why they have the bookmarklet option.

Hmm yeah you're probably right there...I'm guessing it's the whole local encryption/plugin combo.

Gah, well I guess the bookmarklet is workable in most situations I'm likely to come across...and perhaps a relatively small price to pay for security.

While I was reading up on this, it kinda dawned on me how poor my password set up was. I mean, if one crappy website/forum I'd signed up to revealed my email address and password, anyone would have access to my amazon, play.com, paypal etc. Would be a *slight* disaster :unsure:

  On 28/03/2011 at 19:03, Bhav said:

Hmm yeah you're probably right there...I'm guessing it's the whole local encryption/plugin combo.

Gah, well I guess the bookmarklet is workable in most situations I'm likely to come across...and perhaps a relatively small price to pay for security.

While I was reading up on this, it kinda dawned on me how poor my password set up was. I mean, if one crappy website/forum I'd signed up to revealed my email address and password, anyone would have access to my amazon, play.com, paypal etc. Would be a *slight* disaster :unsure:

Same I used the same password for nearly everything, with a little bit of variation on some sites.

I guess the scare with lastpass though is if anyone gets THAT password you're royally ****ed :p

you can always recover the password, and since you would be using the password prob daily, if not multiple times a day - if you forget it you clearly are severely mentally challenged ;) And prob wouldn't know the difference between a computer and a etch-a-sketch anyway ;)

http://helpdesk.lastpass.com/account-recovery/

  On 28/03/2011 at 19:49, BudMan said:

you can always recover the password, and since you would be using the password prob daily, if not multiple times a day - if you forget it you clearly are severely mentally challenged ;) And prob wouldn't know the difference between a computer and a etch-a-sketch anyway ;)

http://helpdesk.lastpass.com/account-recovery/

Me? I wasn't talking about forgetting my password, I meant if someone found it out :p

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I happen to try it today not knowing about the update and was happily surprised; it is great.
    • Hello, Hardware Support Applications are a special kind of Microsoft Store app and have to go through additional checks and certifications because they can communicate directly with their driver, which means that a vulnerability in one of them could allow an attacker access to kernel space memory through the HSA ←→ device driver interface.  In other words, a BYOVD (bring your won vulnerable driver) attack, but with the HSA being used as an extra step. Remember, the Microsoft Store is strategic to Microsoft's long-term goals: they see it as the means to get the same 30% of every application sale that Apple and Google get through their stores, which is why it has been a fixture of Windows since Windows 8 was introduced in 2012 despite a low adoption rate.  Microsoft cannot afford to have anyone get an app through their store which causes a security issue for their end users.  Even if the app was written by and uploaded to the Microsoft Store by a partner, it is Microsoft's name on the store, and they are the ones that will have reputational/brand damage if they allow something malicious into their store. Regards, Aryeh Goretsky  
    • This is more from my childhood, when nickelodeon just launched and had to license shows to have something to air. Left a big an impact, but probably more emotion positive / childhood thing. Europe got the follow up season's decade's latter with the animation studio that did Air Bender but never licenses for the US. I miss the day's of longer intro's. Nier (PS3) Intro is epic, and was very unexpected.  PS1 Xengears was also epic and an amazing game.  
    • Sayan Sen, do you think one day an image of the Windows Vista desktop or the wallpaper could be used in the primary image of an article? (When I think of CDs and DVDs I think of that release of Windows and of earlier releases; it is the one that debuted IMAPI 2.0 and other features.)
    • Big fan of EAC Here's a good non-default naming scheme I found on the web (can't take credit) File Name Scheme - %albumartist%\%year% - %albumtitle%\%tracknr2% %title% Various Artists Naming Scheme - Various Artists\%year% - %albumtitle%\%tracknr2% %title% Also, I need test but there is a new flac.exe binary & dll you can drop in the folder to upgrade flac support. I did this pre EAC 1.8. EAC 1.8 did upgrade it to 1.4.3. Flac 1.5.0 came out this year. https://ftp.osuosl.org/pub/xiph/releases/flac/ I don't know how much of a difference / impact will make.
  • Recent Achievements

    • Week One Done
      maimutza earned a badge
      Week One Done
    • Week One Done
      abortretryfail earned a badge
      Week One Done
    • First Post
      Mr bot earned a badge
      First Post
    • First Post
      Bkl211 earned a badge
      First Post
    • One Year In
      Mido gaber earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      485
    2. 2
      +FloatingFatMan
      263
    3. 3
      snowy owl
      240
    4. 4
      ATLien_0
      227
    5. 5
      Edouard
      188
  • Tell a friend

    Love Neowin? Tell a friend!