quality-time icon indicating copy to clipboard operation
quality-time copied to clipboard

Some field trigger LastPass password change prompt

Open Sebastiaan127001 opened this issue 3 years ago • 2 comments

This is a known issue from LastPass. This also happens to other application. This morning, a colleague of mine had the same problem. It happens when a user opens the sources tab of a metric. I can provide more details (for reproduction) if required.

I believe this could be easily fixed by changing the field-names.

see also https://www.ecosia.org/search?q=lastpass%20is%20triggered%20by%20non%20password%20field&addon=opensearch

Sebastiaan127001 avatar Jan 05 '22 16:01 Sebastiaan127001

Apparently, LastPass doesn't fill in fields that have data-lpignore="true", so we can try to add that attribute to username and password fields.

On the other hand, what's the bug here? The sources tab does have username and password fields, so why is it a bug if the LastPass tries to help you with filling in a username and password?

fniessink avatar Jan 14 '22 13:01 fniessink

The bug here is that Lastpass assumes that the credentials from the source are the credentials from the Quality Time instance and if the user confirms, LastPass overwrites the Quality Time login (ldap) .

Sebastiaan127001 avatar Feb 01 '22 14:02 Sebastiaan127001

Given the LastPass troubles (see for example https://www.theverge.com/2022/12/28/23529547/lastpass-vault-breach-disclosure-encryption-cybersecurity-rebuttal) we won't put energy into supporting LastPass.

fniessink avatar Dec 29 '22 09:12 fniessink

fully agree

Sebastiaan127001 avatar Dec 29 '22 09:12 Sebastiaan127001