|
|
|
|
|
by jimmydorry
1633 days ago
|
|
Lastpass simply downloads your password database as an encrypted blob which you unlock locally with your master password. The fact that this unlocking is somewhat automated does not change the fact that it acts identically to your proposed solution. |
|
- There's no way a flaw in an authentication protocol could compromise a master password (because the file sync software is completely detached from the password manager).
- Someone who compromised your master password can't get your passwords without first obtaining your database files.
That being said, I don't think online password managers are inherently insecure or anything like that.