FlyerTalk Forums - View Single Post - 300,000 miles stolen from my Avios BA account
Old Mar 24, 2017, 3:25 am
  #56  
waffle
 
Join Date: Apr 2016
Programs: SK Gold, BA Gold
Posts: 180
Originally Posted by Jeannietx
I signed up with Lastpass, and started adding sensitive accounts, but somehow I thought it would generate new and difficult passwords, but it didn't. It just has my passwords. What am I doing wrong?
I don't use LastPass any more, but I used to. I think you may have misunderstood what a password manager does for you.

Its most basic function is, as you've discovered, simply storing your passwords. The idea is that you should be using a strong, random password for each site, but since there's no way you're going to be able to remember them all, you need somewhere to write them down. In that regard, LastPass is just a more secure version of that Post-it note you stick on your screen.

LastPass does a few other things to make your life easier though. If it already has your login information for a site you are visiting, it will offer to fill the login form for you so there's no manual copying and pasting.

It can also generate strong passwords for you. This is useful both when you first sign up on a website as well as when you're filling the "change password" form (where you have to type your old password and then your new one twice). LastPass will usually notice that you've added or changed a password and offer to store/replace it for you. This works pretty well, use it.

It sounds like you were expecting LastPass to change your passwords for you. It's very tricky for a computer to do that because the process is different for each website, however I distinctly remember LastPass doing that for me once or twice to my amazement. I'm not quite sure where that action was buried, it may have been part of the "security audit".

But in any case, you'll have to go through your list and change most of your passwords by hand. It's not that bad though: let LastPass open the web page and log you in, then find the "change password" page, let LastPass fill in your old password for you, use its password generator to generate and fill in a new one. Then submit the form and LastPass should ask you if you'd like it to update the login data for that site in its database, to which you say yes.
waffle is offline