3 ms·
The lock cannot be replaced, but it can be put behind another lock or temporarily taken out of commission. In the case of the Lastpass exploit it would've been
by cryptarch 10y ago
The lock cannot be replaced, but it can be put behind another lock or temporarily taken out of commission.
In the case of the Lastpass exploit it would've been to not use Lastpass for a few days. That's one benefit of direct disclosure to the user.
- AnkhMorporkian 10y agoThat really isn't an option for most users. People who use a password manager are pretty much forced to use that password manager, at least if they're using it properly. Most users won't know how to export it to a CSV and then use that without a browser extension and/or import that to another password manager.
- pluma 10y agoAlso "not using it" depending on the kind of exploit may mean completely shutting down the account until the vulnerability is fixed.
- Thrillington 10y agoIsn't that the right thing to do for truly sensitive passwords? I'd much rather transcribe my financial account passwords to paper, or not log in for a couple days than have multiple months where a vulnerability might be exploitable
- scott00 10y agoThis vulnerability didn't affect Android or iOS apps. A user could have transcribed passwords from mobile to browser for a few days.