Hacker News new | ask | show | jobs
by jlgaddis 3818 days ago
Read the content in the right hand column (at your link), under the various headings...

The "Emergency Contact" must be a LastPass user, so they already have a public/private keypair. Your vault is encrypted with their public key and, when the time comes, they're given access to your encrypted vault and are able to decrypt it using their own private key.

Sounds good, in theory, but I'm certainly no cryptography expert. Regardless, I'm not sure if I trust it/"them".

(It won't matter much for me, anyways. When the announced that LogMeIn had bought the company, I jumped ship and moved to 1Password.)