Hacker News new | ask | show | jobs
by olkingcole 1208 days ago
Does this mean they got access to unencrypted vaults? I have had a few beers and cannot comprehend from the article or lastpass's statement.
1 comments

I don't think so. Per Lastpass's description of their architecture, their server never sees your unencrypted passwords. (Though substantial metadata, such as the website URLs, are not encrypted.)

To get unencrypted vaults, they'd need to change the client-side code. But we haven't been told that this happened.

(As a best practice, it's probably best to assume everything in LastPass vault was compromised at this point.)