After one proper YubiKey login to LastPass, restarting the browser does not validate the YubiKey further & will let you login with the first 12 characters of it.
Ofcourse with your own YubiKey strings only but this defeats the purpose of MFA by turning it into a static password. Reported to LastPass via Bugcrowd but marked as N/A.
rootup•1h ago
Ofcourse with your own YubiKey strings only but this defeats the purpose of MFA by turning it into a static password. Reported to LastPass via Bugcrowd but marked as N/A.