Hacker News new | ask | show | jobs
by BuildTheRobots 1266 days ago
[1] makes it seem like the number of rounds is included unencrypted at least on the client side binary databases. As it's sent over the wire when downloading the vault, lastpass would _have_ to have that in clear text somewhere.

[1] https://github.com/cfbao/lastpass-vault-parser