Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

LastPass is proprietary closed source software. For all you know they've never not had access to your vault.


If you wanted to, it's not too tough to extract the source code of their browser add-ons to verify for yourself that your vault is encrypted before being sent to their servers, and that your master password is not sent. (And of course with this tool it's relatively trivial to look through the javascript to verify the same.)

So while you can't look at the code running on their servers, it seems to me that you certainly can know they don't have access to your vault.


This comment is funny because this thread is about an OpenSSL bug that has been giving up your keys for 2 years.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: