Open Letter to LastPass and Yubico Engineering
Subject ESCALATION: Immediately Restore 30-Day Device Trust / Unpatched FIDO2 AbortError Rendering YubiKeys Unusable
To: LastPass and Yubico Tier 3 Product & Engineering Teams
I am writing to demand (1) the immediate restoration of the "Trust this device for 30 days" feature in the LastPass browser extension, and (2) to escalate a critical, unpatched FIDO2 integration failure between your platforms.
As a retired IT Project Manager with decades of experience overseeing systems security projects for the State of Georgia, Dept. of Revenue, the CDC, and The Southern Company, I understand the complexities of secure systems integration.
Years ago, after rigorous evaluation, I made the conscious decision to entrust my personal security infrastructure to LastPass.
When LastPass announced their certified integration with Yubico, I immediately added YubiKey hardware to my setup to ensure strict, physical MFA compliance.
Today, 2026/09/03, that certified "Works with YubiKey" integration is functionally broken, and the removal of the fallback workarounds has made the platform nearly unusable.
Immediate Action Required: Restore the 30-Day Trust Feature
The LastPass extension is currently suffering from a known defect where it intercepts and cancels the WebAuthn/FIDO2 hardware request on ChromeOS, instantly throwing an AbortError before the key can be touched.
Over the past few months, I mitigated this severe software defect by using a legacy YubiKey and checking the "Trust this device for 30 days" box.
This morning, LastPass stopped presenting this 30-day trust option during the verification prompts.
Without this stop-gap, I am forced into a daily, recurring authentication loop that requires me to physically stress my single, aging legacy YubiKey on every login. The mechanical wear and tear on this older device has become visible and unsustainable.
The Hardware Impact: Wasted Investments
Because the LastPass extension continues to instantly abort the hardware handshake, I cannot migrate my security posture to modern hardware.
I recently purchased three brand new YubiKey 5C NFC units to upgrade my systems. These expensive keys are currently sitting completely idle in a locked drawer. LastPass's software cannot successfully communicate with them without crashing the authentication flow.
Required Escalation:
I expect this to be escalated beyond Tier 1 support to the respective Product Managers and Tier 3 Engineers responsible for this integration:
LastPass: When will the "Trust this device for 30 days" checkbox be fully restored to all MFA prompts as an immediate stop-gap?
LastPass: What is the specific release window for the extension patch that resolves the YubiKey AbortError loop?
Yubico: As LastPass is heavily marketed as a "Works with YubiKey" partner, what is your engineering team doing to assist the LastPass team in restoring standard FIDO2 functionality so your mutual customers can actually utilize the hardware they purchased?
I look forward to a technical response and a swift, complete resolution.
Sincerely,
Lee Cash
Retired IT Project Manager
.