(March 30, 2016 at 3:51 pm)Minimalist Wrote:Quote:LastPass officials warned Monday that attackers have compromised servers that run the company's password management service and made off with cryptographically protected passwords and other sensitive user data. It was the second breach notification regarding the service in the past four years.Oops.
Yup, but if you look up their security model it's pretty decent. If people have strong enough master passwords (which they encourage you to have), then they could literally publish everyone's password vaults online and nobody would be able to get to the actual passwords.
My LastPass password is 30+ characters long (it's basically a nonsense sentence) and you need to know that exact password in order to unlock the vault. As far as I'm aware, not even LastPass know the master password, as all the decryption is done in your web browser.