Hacker News new | ask | show | jobs
by aasasd 2617 days ago
They could do that in theory, yes, but we don't know if they did so back in 2015, or what they did at all. Because there was no documentation as to what actually was happening—except that emails which are in a leak are very likely exposed to the Lastpass backend, since LP sends a notification to that address.

And my objection here is not to a leak of passwords (as they're not what is checked)—I don't want my emails or usernames to be thrown around either.