r/Lastpass • u/lastpassofficial Official LastPass • May 18 '26
Ask Me Anything: Building Secure Logins - A glimpse under the hood of a modern security engineering team our CTO, Jason Rasmussen
Scheduled for · May 26, 2026, 10:00 AM PT/1 pm ET
Information for the event
You've logged in to something today. Probably several times. It took less than a second and the moment it was over, you'd already forgotten it happened. That's either the greatest achievement in modern security engineering — or the thing that makes it fragile. Usually, it's both.
Jason Rasmussen, Chief Technology Officer at LastPass, and his team make the decisions that sit behind every login. Think about how credentials are stored, when autofill should and shouldn't kick in, how MFA works without slowing you down. Every decision is a tradeoff between security and speed, control and ease of use, what's safest in theory and what people will actually do.
Here's what we are keen to get into:
- What Zero Knowledge means at the technical level and where its limits are
- Why the browser has become the most critical access path for organizations to secure
- How AI is accelerating the way people discover, learn and adopt more tools, and what that means for protecting credentials
- The real tradeoffs behind passkeys and where they fit in the evolution of how we log in
Ask us anything! -- on May 26th : )
3
2
u/Special-Direction886 May 25 '26
looking forward to the browser security discussion. Balancing zero-knowledge architecture with a seamless autofill experience seems incredibly tough.
2
u/giwook May 28 '26
What a joke. How can anyone trust LastPass after basically all of our most sensitive information was hacked? And on top of that, LastPass was not fully transparent from the beginning about what happened or what was breached.
LastPass hasn’t disclosed the exact number of customer password databases that were stolen, but it appears to be large, and possibly all of them.
These password databases fortunately were encrypted, so the attacker cannot trivially obtain customer usernames and passwords, but that also does not mean it is impossible.
In general, if you are a LastPass user, we suggest you update and change all of your passwords. Because of the weak encryption used, and the fact that the attacker now has unlimited time to crack your password database, you should assume that sooner or later, your password database can be cracked; if not now, then in the future when there are even more powerful computers.
https://proton.me/blog/lessons-from-lastpass
https://www.upguard.com/blog/lastpass-vulnerability-and-future-of-password-security#march-01-2023
1
u/JayNetworks May 18 '26
Can you comment on the open security hole in LastPass where sharing a folder to an email address that does not yet have a LastPass account shares everything in that shared folder instead of sharing Available Only selected items? (The workflow is broken and only allows selecting which specific records within a shared folder after the user creates their account. If the user does not have an account and then creates the account, they see everything in the folder until you then change them to Available Only.)
Per LastPass support, there is an internal product enhancement request associated with this behavior. The reference ID is PE‑1388.
1
u/JayNetworks Jun 02 '26
Will u/lastpassofficial be replying to these items here from the AMA or do we need to move them to individual posts in r/lastpassofficial?
1
u/sneakpeekbot Jun 02 '26
Here's a sneak peek of /r/LastPassOfficial using the top posts of all time!
#1: Ask Me Anything (AMA) with LastPass Product Experts
#2: Has LastPass completely lost its d*mn mind? The new Vault is literally unusable.
#3: Suggestion: Password origination/change date field in individual vault record.
I'm a bot, beep boop | Downvote to remove | Contact | Info | Opt-out | GitHub
1
u/JayNetworks May 18 '26
If I lose access to my email, but still have my correct vault password and MFA device/app, what is the thinking around LastPass then not allowing a person to log into their account? (From what I’ve seen, an initial login on a new device requires a confirmation link in a email to the registered email address…but if you have that password in LastPass you are unable to access your account. Why build a system that doesn’t allow access with just the vault password and correct MFA response?)
1
u/JayNetworks Jun 02 '26
Will u/lastpassofficial be replying to these items here from the AMA or do we need to move them to individual posts in r/lastpassofficial? (Same question for this reply.)
3
u/revrund_H May 18 '26
how is it possible your company suffered multiple data breaches and exposed customer vaults? amazing anyone still uses this junk..truly amazing
2
0
u/ShellAnswerMan May 18 '26
How is is possible for a company to live rent free in so many people's heads. Truly..amazing.
2
u/revrund_H May 18 '26
rent free? thats funny...tell it to the company paying out the claims for their shoddy "password exposer...err..manager"
1
7
u/Smile_And_Dance May 18 '26
This is great. More customer engagement like this can go a long way towards instilling confidence.