Hacker News new | ask | show | jobs
by mike-cardwell 4752 days ago
Lastpass could be compelled to send modified JavaScript down to your browser which records your password when you enter it, and reports it back, meaning they then have complete access to your password vault contents. They would also be capable of retrieving meta data including the list of sites you log into, when you log into them, and from what IP addresses.