Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Security Analysis of Web-based Password Managers [pdf] (devd.me)
10 points by tinco on July 11, 2014 | hide | past | favorite | 1 comment


tl;dr is that among 4 other LastPass had some serious security flaws last year. An attacker could, if they had control over the website the victim was browsing, read any password from the database by exploiting the bookmarklet.

The issue was resolved by hosting the encryption key in an iframe and communicating requests via postMessage.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: