https://www.dropbox.com/s/pzmdqex81tsicyk/Screenshot%202015-...
https://www.dropbox.com/s/pzmdqex81tsicyk/Screenshot%202015-...
Alerts confirming things happen all the time and so users have been trained to click yes to make things work. I'd suspect only 20% might actually read that sentence and even less will understand what it means and why.
Instead that login screen should change and have large, clear text and iconography that violates expectations and thus forces users to read. Having buttons that explain like "make less secure" makes it more likely to be understood than "yes" "no."
Can you explain how this is correct? Because i use only webclient thinking that the plugins may be more vulnerable because other plugins may read what lp plug in does.
Criticism to using the webapp is generally JS crypto being broken. Code delivered every time coupled with the browser not being good place for crypto (any code can eat any other code..).
Extensions, being a separate program that lives mostly apart from the web pages your browser visits is slightly a more trustworthy environment
The insecurity comes from someone already having physical control of your machine, and if you had alowed saving of your master password (which Lastpass and anyone sane encourages against).