Open
Bug 1458709
Opened 7 years ago
Updated 2 years ago
lastpass.com bypasses container isolation
Categories
(Core :: DOM: Security, defect, P3)
Tracking
()
UNCONFIRMED
People
(Reporter: jgbailey, Unassigned)
References
(Blocks 1 open bug)
Details
(Whiteboard: [domsecurity-backlog1])
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0
Build ID: 20180502100112
Steps to reproduce:
I have multi-factor authentication enabled on my lastpass.com account.
1. In a new container, go to lastpass.com and log in.
2. Enter a multi-factor authentication code at the prompt and select the 'trust this computer for 30 days' checkbox.
3. After logging in, close the tab.
4. Open a new container and go to lastpass.com
5. Log in.
Actual results:
You are not prompted to enter a multi-factor code on the second login attempt, even though you are in a new container.
Expected results:
I should have been prompted to enter a code. I would not expect whatever state the 'trust this computer' checkbox sets to persist across containers.
Updated•7 years ago
|
Updated•2 years ago
|
Severity: normal → S3
You need to log in
before you can comment on or make changes to this bug.
Description
•