I do the exact same thing STRML with my lastpass vault. Lastpass has a bunch of fine grained access controls for when the password needs to be entered. Having your password saved on lastpass just lets you view your list of password, as long as you have it set to require the master password before accessing an individual password.
Here is how the process goes for logging into a website with these settings:
1) Go to website
2) Click autologin
3) Type your master password
4) Lastpass fills in your password on the website and logs you in
This clearly involves your master password before doing anything that would seem to reveal your individual website password. The problem here is that this would appear to be completely false as the article points out.
Another way to get the password in lastpass:
1) Open the lastpass vault
2) Search for the target website
3) Click edit
4) Click the eye icon to show your password
5) Type in your master password
6) See the password
Once again, exactly as you'd expect, and seems to require the master password before revealing anything. The problem is that you can replace steps #5 and #6 with (in chrome):
5) ctrl-shift-j (brings up dev console)
6) $('input[type=password]').setAttribute('type', 'text')
And now your password is sitting there in plaintext without ever requiring your master password, despite telling lastpass to require your master password for any password access.
I agree with the rest of the commenters that sharing a password with someone and expecting it to remain secret is a bit foolish, but the problem I described here is a HUGE vulnerability. I'm going to seriously reconsider using lastpass ever again.