4 ms·
Wait. When I click "Security Check" in my LastPass Tools... menu (this is in Chrome), I get taken to an internet-hosted web page where I'm prompted to enter my
by davidp 13y ago
Wait. When I click "Security Check" in my LastPass Tools... menu (this is in Chrome), I get taken to an internet-hosted web page where I'm prompted to enter my master password. [1] I am not taken to a chrome:// page or some other client-side tool.
I take this to mean that I'm giving LastPass's web server my actual master password, and that they will do server-side decryption of my Vault and have server-side access to my passwords in cleartext.
Is that accurate?
[1] https://lastpass.com/index.php?securitychallenge=1&lang=en-US&fromwebsite=1&lpnorefresh=1 https://lastpass.com/index.php?securitychallenge=1&lang=en-U...
- Fishkins 13y agoPer what pwman said in a previous thread, I believe it's decrypting your info client-side using JS. https://news.ycombinator.com/item?id=7554974 https://news.ycombinator.com/item?id=7554974
- nly 13y agoLastPass is proprietary closed source software. For all you know they've never not had access to your vault.
- tempestn 13y agoIf you wanted to, it's not too tough to extract the source code of their browser add-ons to verify for yourself that your vault is encrypted before being sent to their servers, and that your master password is not sent. (And of course with this tool it's relatively trivial to look through the javascript to verify the same.) So while you can't look at the code running on their servers, it seems to me that you certainly can know they don't have access to your vault.
- lawnchair_larry 13y agoThis comment is funny because this thread is about an OpenSSL bug that has been giving up your keys for 2 years.
- pwman 13y agoNO! It's all done locally via JavaScript -- we never want to get your master password / encryption key -- we go through great pains to ensure that never happens.
- MichaelGG 13y agoBut there's like, no way for a customer to verify that. It's good practise, but a customer should not rely on that as part of their security model.
- joosters 13y agoIt's a lastpass.com site and you are already implicitly trusting them by using LastPass. How does this make it less secure?