Hacker News new | ask | show | jobs
by olliej 1405 days ago
It shouldn't be a "and the design means that they can't access it" that should be the only behavior?

I agree with your other points

Assuming the LastPass encryption key is a separate token I would say LastPass wins, but that is solely assuming similar architecture, obviously you can make design decisions that mess up everything.