5 ms·
You don't get very much by MITM of LastPass compared to other targets -- the extensions aren't going to pull down Javascript, the update process only uses signe
by pwman 13y ago
You don't get very much by MITM of LastPass compared to other targets -- the extensions aren't going to pull down Javascript, the update process only uses signed binaries... You might be able to put people utilizing LastPass.com to login which we don't recommend and isn't done by the vast majority of people.
- icebraining 13y agoThe vast majority of people haven't logged in to LastPass.com in the last two years, since OpenSSL has been vulnerable?
- phord 13y ago(Frequency of LastPass.com login via web page on insecure network) * ( odds of MITM attack on that network) = scary low odds