Rich Freeman on 5 Jan 2016 08:29:17 -0800

Re: [PLUG] password safe

On Tue, Jan 5, 2016 at 11:13 AM, Keith C. Perry
<> wrote:
> From what I saw on lastpass's website their encrypted value mechanisms would be acceptable to me but it's still not something I would use.

My biggest concern with lastpass is that if they're hacked somebody
can potentially change your client.  It is all Javascript with local
encryption, but if you can change the code you can just have it pass
the key back to the compromised server.

So, an attack that just grabs their entire database isn't a huge
threat since the data is all locally encrypted.  However, a persistent
undiscovered attack is a much larger threat since it can be used to
skim passwords as people run the client.

That is actually a threat if somebody compromises your distro and
updates you to a compromised version of Keepass or such as well, but I
don't think people update their software as often as they reload their
