4 ms·
It's possible to silently do this as part of logging in. I've done this with normal login for several (legacy) systems I've worked on, migrating users from md5
by gregmac 4y ago
It's possible to silently do this as part of logging in.
I've done this with normal login for several (legacy) systems I've worked on, migrating users from md5 or sha1 to better algorithms.
- d1str0 4y agoTheres a big difference. If you’re hashing a password for storage you end up getting the password first. LastPass NEVER gets your master key server side. All encryption is done locally. Also, hashing a password is extremely quick. To unencrypt the full vault and re-encrypt it does take an amount of focused time. Might not be able to be done “silently” in the background, but obviously LP should have been forcing an upgrade on login.
- coder543 4y ago> To unencrypt the full vault and re-encrypt it does take an amount of focused time. The entire vault should not be encrypted directly with the user's password. That would go against standard best practices. See this comment written hours before yours, right under the comment you replied to: https://news.ycombinator.com/item?id=34127993 https://news.ycombinator.com/item?id=34127993 There is no "big difference" here, and it could be done trivially during login. The fact that it would be done client side instead of server side is a very minor implementation detail.