
When set up, you’re given a 10 x 26 grid of random characters which you save. In addition, so-called “grid” authentication is supported. Other forms of proof can include SMS messages or even a simple confirmation prompt from the app. The advantage is that no connectivity is required. The proof typically takes the form of entering a random number generated by the app when requested by LastPass at login time. The free version of LastPass supports a number of apps, including Google Authenticator, Authy, Microsoft Authenticator, and LastPass’s own authentication application. The most common proof is an application, or app, running on your smartphone. In addition to knowing the account ID and password, you also prove you have something specifically associated with your account in your possession. Two-factor improves security by adding a factor to identity authentication. My recommendation is that before enabling two-factor authentication, and especially if you’ve never used two-factor before, back up the contents of your LastPass vault and save it in a secure location.Īctually, my recommendation is to back up your LastPass vault periodically, regardless of whether you use two-factor or not. The folks at LastPass do not have a back door to regain access to your account (should you lose your password, for example), so you’d likely be on your own.

It’s not very likely, but when adding additional security, it’s possible a mis-step along the way could get you locked out of your LastPass account. That’s why I recommend adding two-factor authentication to your LastPass account.

The most common concern about password vaults is this: what if someone, somehow, gets the master password to your LastPass vault? While extremely unlikely, the cost of failure is pretty high: that person would have access to every account stored in your LastPass vault. Using a tool like LastPass makes you more secure by creating long, complex passwords you don’t need to remember, because LastPass remembers them for you. LastPass is a utility used to store and remember your login credentials. With two-factor authentication enabled, hackers can’t log in to your account, even if they know the password. Two-factor (or multi-factor) authentication is one of the most reliable ways to secure an account from being hacked. Important update: What to Do About the LastPass Breach
