Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem I tend to think of is that they store the urls in the clear, so an attacker (who can bypass SSL) will potentially be able see which sites you have passwords saved for. There's a writeup that mentions it here: http://www.martinvigo.com/even-the-lastpass-will-be-stolen-d...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: