|
|
|
|
|
by 0daystock
1483 days ago
|
|
> There's a feature where you can even share the login to a site on it, but they can't view the password - only lastpass can fill it up. Prime example of Lastpass security theater - what exact problem did they think this feature solved? |
|
Sure, its not too hard to get around that feature, you could just inject your own javascript on the page to dump the contents of the password field. But it does block the low hanging fruit of the millions of users who don't know how to do that who might abuse having access to the password because they don't really know better.
In essence, it helps to prevent those users who don't know better from leaking the password to places it shouldn't be. Obviously it doesn't prevent people who know how to get around it from getting around that protection, but in those circumstances you shouldn't really be sharing your password with someone who will abuse your trust.