3 ms·
It isn't that I don't trust LastPass the company. It is that I'm no longer sure if the entire model of the product/service offers enough additional (or comparab
by spinchange 11y ago
It isn't that I don't trust LastPass the company. It is that I'm no longer sure if the entire model of the product/service offers enough additional (or comparable) security over what Chrome offers, wrt to the syncing of encrypted credentials to the cloud.
If your're only considering vulnerabilities that pertain to that, I would think native Chrome has an inherent security advantage over a Chrome plugin. I am happy to be wrong about this, though.
Edit/Addition: While I give them props for the full disclosure about the salts being exposed, we don't have any evidence that this has ever happened to Google, so setting everything else aside, we already know for certain LastPass has been exploited in a way we don't have any evidence that Google has. That's not intended to be a slight on LastPass or praise for Google, just that, "it is what it is."