Hacker News new | ask | show | jobs
by rosnd 1271 days ago
>Remember that last pass has just been caught lying about their security, and you can't trust what they say.

I'm curious, what were they caught lying about?

>What proof do you have that last pass uses that encryption scheme? Is there any evidence to suggest that it meets rigorous standards?

LastPass has been extensively reverse engineered. There are, for example, public Defcon talks about it.

>Changing passwords in the face of a breach like this is standard practice and is the only logical step forward.

This is not logical at all.

>You cannot trust last pass security from this point forward.

Why not? Because they disclosed a breach?