Trust No Program
Reply to topic
tzuk


Joined: 22 Jun 2004
Posts: 15154
Reply with quote
We did talk, and someone from LastPass reviewed the compatibility settings in Sandboxie and approved them. I'm going to try to improve the detection of LastPass in Sandboxie, but other than that, no other changes.

_________________
tzuk
View user's profileSend private message
BUN B Fan


Joined: 02 Apr 2012
Posts: 13
Location: Trill OG Land
Reply with quote
That would be great

I gave them detail explanation of what's going on, and where and when my problems do appear, but as you might think, the easiest thing to do for them is to jump on the first ball and blame sandboxie.

Although I did mention couple of time, that I did get connection errors running just FF (un-sandboxed), but, like I said, it's easiest to blame it on some other software
not blaming not defending either one

Also, I will check upon them to see if they found out something

If you could improve compatibility, that would be awesome, as LastPass as well as Sandboxie are both great, and It would be shame if they didn't work flawlessly with each other

Thank you for you will to improve Sandobxie's compatibility with LastPass

Also, I want to take this opportunity, to wish you a Happy Easter personally, and to all forum members, and to all in general

If I can be of any assistance, do not hesitate to contact me
Take care
View user's profileSend private message
BUN B Fan


Joined: 02 Apr 2012
Posts: 13
Location: Trill OG Land
Reply with quote
tzuk, any news?

i did get a msg from LastPass team that I still have +200 one time passwords generated, and that they will send me info as how to remove those

i did clean on all the cache in Ie32bit and Ie64bit
I run them both as Admin and as non admin, and cleaned everything

also, I did cleaned everything in Firefox

and I make sure that In all Ie versions and firefox, "save OTD passoword for acc recovery" is disabled
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15154
Reply with quote
I'm not sure what to tell you. They told me that if your LastPass folder is not going through the effect of sandboxing, then you shouldn't have a problem with one-time passwords. Do you have the LastPass compatibility settings in Sandboxie turned on? In Sandboxie Control, Configure menu, Software Compatibility.
View user's profileSend private message
BUN B Fan


Joined: 02 Apr 2012
Posts: 13
Location: Trill OG Land
Reply with quote
yes, I do have LastPass compatibility enabled
don't know whats going on then..
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15154
Reply with quote
I don't know. Maybe the one-time data has something to do with cookies.

You can try to go into Sandboxie Control > Sandbox Settings > Applications > Web Browser > (whatever browser)
find the setting that gives direct access to cookies and enable it.
View user's profileSend private message
BUN B Fan


Joined: 02 Apr 2012
Posts: 13
Location: Trill OG Land
Reply with quote
hi there

but that would lower my security!

i have disabled my OTP passwords, and I am waiting from Last Pass to tell me are there still +200 OTP generated on the servere side, or are they removed
I am using Sandboxie for this particular reason not to have cookies stored and for everything to be deleted

If you find something, please do let me know!
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15154
Reply with quote
The person from LastPass that I talked to did say that multiple one-time passwords were generated because the LastPass data folder was being recreated in the sandbox, not because of cookies. I'm suggesting cookies because you say the problem still persists.

As for a security issue, cookies aren't really known for being a security vulnerability, it's more about web sites "remembering" you.
View user's profileSend private message
BUN B Fan


Joined: 02 Apr 2012
Posts: 13
Location: Trill OG Land
Reply with quote
how can I avoid OTP being generated? i have that option disabled in my plugin, in IE and in FF

also, I ain't having no more connection errors, ever since I disabled that option, but LastPass support informed me that I still have +200 OTP generated on the server (as they can see it)

I did clean all my cache, and then requested them to check again, and I am still waiting for reply

do you have some ideas as to how avoid OTP being generated? i don't see how they could be generated if I have that option disabled now? must have been previous ones
how to disable them? i bet there is something that needs to be removed from HDD that plugin generated

p.s.
i don't want sites tracking my movement by cookies
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15154
Reply with quote
I'm sorry, I don't know enough about LastPass to answer specific questions. I can only repeat to you what the person from LastPass has told me.
View user's profileSend private message
BUN B Fan


Joined: 02 Apr 2012
Posts: 13
Location: Trill OG Land
Reply with quote
okey

if I find out something new, I'll post here
View user's profileSend private message
BUN B Fan


Joined: 02 Apr 2012
Posts: 13
Location: Trill OG Land
Reply with quote
hi all

to help others, i'll post what the lastpass supported just sent me over the email

...


"You can search for this file location: %appdata%\..\LocalLow\LastPass and delete the .sotp files, although they shouldn't be accessible any longer. If you have other operating systems, the other file locations are referenced here: https://lastpass.com/support.php?cmd=showfaq&id=425&questiondefault=%25appdata if you'd like to ensure the .sotp files are not present for any browser or computer. "

I hope this helps others
View user's profileSend private message
BUN B Fan


Joined: 02 Apr 2012
Posts: 13
Location: Trill OG Land
Reply with quote
Hey Guest 10,

I can confirm now that this problem was due to the option "save disabled 1 time password"
The moment I turned it off, it went away.

Also, I've been wanting to ask you one thing

I want to find out what registry entries are created/modified by Audicity portable version ( http://audacity.sourceforge.net/download/windows ).

I did run the program in sandbox, and closed the program (not deleted from sandboxie)
Then I've loaded the registry hive, but there seems to be more entries then by just the program itself?

How can I exactly inspect what happened when I ran this program outside of Sandboxie?

Thank you for your time Guest!
Take care
View user's profileSend private message
Can't get LastPass plugin to autologin / remember password
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 5 of 5  

Use the RSS feed to watch this topic for replies
  
  
 Reply to topic  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 212,984,707 times since June 2004