Hacker News new | ask | show | jobs
by tokenizerrr 4355 days ago
I really want to like LastPass, but I can't get over all of my passwords being stored on someone elses server. Doesn't that seem like a terrible security risk?
3 comments

The LastPass vulnerabilities affected only bookmarklets (used by less than 1% of LP users, according to LP) and OTPs (no estimates for use).

I've been using LP for over a year, didn't know either feature existed until the disclosure: I use it strictly for its main capability, encrypted and unique site passwords.

The data is decrypted client side only. The server only stores an encrypted version that you send via SSL.
I'm a big fan of KeyPassX which you use can easily store locally or sync via Dropbox.