Jump to content

LP Vault Manager: A Workflow for LastPass


Recommended Posts

FWIW, I was looking into the security of Lastpass (and others) last night.

 

It seems that the password used to log into the online service is derived from your master password in such a stupid way as to make your master password hundreds of times easier to crack than an offline-only copy of your database would be.

 

They also do some rather questionable things, like storing known, encrypted text in the database, which also makes cracking your master password much simpler than it would otherwise be. And ironically, the known text in question is "lastpass rocks"…

Link to comment
  • 5 months later...
  • 5 months later...
  • 4 weeks later...
  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...