3 ms·
Extensions/Downloads are all cryptographically signed -- I'd hope if you're installing password management software like this that you see that it's unsigned or
by pwman 13y ago
Extensions/Downloads are all cryptographically signed -- I'd hope if you're installing password management software like this that you see that it's unsigned or signed by someone other than LastPass.
Using the extensions to login -- it doesn't matter nearly as much if you're MITM as it would if the website was MITM and you login from the website -- what's in the middle is mostly useful only to do things like mess with you -- delete your sites / DOS your account, but in no way exposes your encrypted data.
The combination of extension use instead of going to the website, perfect forward security, data that's encrypted with a key that doesn't leave your devices, the fact that what you'd most likely leak is a session ID which will be replaced on your next login and that we haven't actually seen anyone utilize heartbleed to get a SSL key yet combine to make LastPass a tough target.
Given everything it'd be far easier to target all the banks and email clients that simply send your credentials right over the wire.
This is definitely a big problem and we're currently working on tools to try to help people recognize what's at risk and help them update it.