/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

LastPass fixes vulnerability in Authenticator Android app that let you bypass PIN/fingerprint lock to access 2FA codes; flaw was reported to LastPass in June

UPDATE: The issue has been fixed.  Please see below.  —  I've found a really easy way to bypass the fingerprint/PIN authentication that protects all of your 2FA codes.

Hacker Noon Dylan

Context & Ripple Effects

LastPass built its own authenticator app after launching one for Android, iOS, and Windows Phone in 2016, positioning it as a TOTP companion to the vault. This story closes a loop on that product: a researcher found a way past the PIN/fingerprint screen protecting stored 2FA codes, reported it in June, and LastPass shipped the fix at the end of December.

The multi-month gap between report and patch matters because it is not an isolated slip — LastPass had already [[a:945913|fixed a Chrome and Opera extension bug that exposed credentials entered on previously visited sites]], making client-side lock and input handling a recurring weak point across its apps.

First-order effects

  • Android users who relied on the app's PIN or fingerprint lock had their TOTP codes readable by anyone with brief physical access to an unlocked phone until they installed the fix.

Second-order effects

  • For a company whose trust position was already fragile — the 2015 breach disclosure preceded this, and the later source-code theft and vault lockouts followed — each client-side bug gives users a concrete reason to move codes off LastPass Authenticator onto separate apps or hardware tokens.

Third-order effects

  • The recurring pattern of local-lock bypasses in password-manager companions points toward software-only device locks being treated as convenience, not security, pushing the industry toward hardware-backed or OS-level protection for second factors.

The trend: Password managers bundling their own authenticator apps keep accumulating local-bypass flaws, steadily shifting user trust away from all-in-one credential apps toward separated, hardware-anchored authentication.