> We also found how it is possible to abuse account recovery to ultimately obtain the encryption key for the vault.
If a 3rd party can help recover your information, your information is not secure because account recovery can typically be bypassed by social engineering.
E:
Someone posted the blog outlying more details:
>With all this information, we where finally able to obtain master passwords in cleartext. Woo hoo! Our attack only covers users that click the “Store my password” option though so, don’t store your master password!
So it's hackable, but only if you're an idiot who stores your master password or sets your password reminder to contain your password.
Seems my bet with my friend wages on. I'll probably be out $20 by the years' end.