|
|
|
|
|
by hackuser
3658 days ago
|
|
> I use https://lastpass.com/ I feel like it's almost certain that Lastpass is owned, as are other popular online password stores. No security is perfect; all you can do is make it more expensive than it's worth to the attacker. How much would it be worth to have all the passwords to every account of every Lastpass user? Does Lastpass really have the resources and skill to protect something that valuable? Is it even possible? |
|
Lastpass (supposedly) stores the encrypted password vault, never the decrypted. Decryption occurs on the users end. You would need to either have a keylogger on the target users machine to grab their master password, or compromise the software. Neither is impossible, but both are a little harder than simply break in and access Lastpass's storage.
I say supposedly because I do not know of any 3rd party verification.