2

Lastpass recently (march 2016) released a new app called lastpass authenticator. Reading their blog post and the description of the app features, it looks like to me that the app does nothing more than TOTP.

Now the algorithm for TOTP is well documented: on linux you can roll your own implementation or use a ready made solution in a shell script, and on android you have choices such as google authenticator or the excellent FreeOTP (and maybe others).

My question is then what is the added value of lastpass authenticator? Why should I use their app instead of FreeOTP, which is opensource and does exactly the same job?

They already supported google authenticator, so I do not believe that they would go through the trouble of building and releasing another app, while there are already other good implementations that do exactly the same thing. There are problably extra security features, or major usability improvement that I missed.

What did I miss? Or is there no actual improvement offered by the app?

user48678
  • 233
  • 2
  • 7
  • I guess closer integration with their services. But why don't you ask them? They also provide [list of supported apps](https://lastpass.com/multifactor-authentication/), where is for example Google authenticatior – Jakuje Mar 18 '16 at 14:04
  • I actually did ask them as a [comment](https://blog.lastpass.com/2016/03/lastpass-authenticator-makes-two-factor-easy.html/comment-page-6/#comment-170205) on their blog, they just did not bother to answer, hence my question here :) – user48678 Mar 18 '16 at 14:42

1 Answers1

0

I am copying here the answer I got on their blog:

At the moment, the main advantage is being able to log into your LastPass account with one tap instead of having to fire up Google Authenticator (or another authenticator app) and type in a 6-digit code. Also the ability to get codes by SMS, which Google Authenticator does not support. There will be additional features rolling out in future releases.

It is actually great, I guess the OTP transits directly from your phone over the network, which is faster than typing it. Not so great when your phone does not have internet, but then you can fall back to typing the code.

user48678
  • 233
  • 2
  • 7