3 ms·
Answer: Its okay to store the encrypted passwords there. Since they are encrypted.
by derpherpsson 7y ago
Answer: Its okay to store the encrypted passwords there. Since they are encrypted.
- wglb 7y agoBut does the server have the ability to decrypt?
- geofft 7y agoNo, for all the major / well-respected password managers (and probably for all the minor ones too), all the crypto is done client-side. 1Password, for instance, has a pretty good security doc about it: https://1password.com/files/1Password%20for%20Teams%20White%20Paper.pdf https://1password.com/files/1Password%20for%20Teams%20White%...
- wglb 7y agoIt is unclear if LastPass is well-respected, and if I recall correctly, at least at one point, the master key was accessible by the server.