what's the issue with that? maybe they have some SSO system
what's the issue with that? maybe they have some SSO system
It's also really dumb, because the whole point of the product is to make it easy to not reuse passwords. They could have even had the signup process automatically create those accounts for you and insert the passwords into your vault, and it would have been just as easy for the user.
1.) LastPass login page hashes MasterPassword on the login page to produce a hash
2.) Hash is sent to the forums, and is checked against the same hash as the vault system
3.) Hash is confirmed, and you're logged in.
1.) Later hash is grabbed by an attacker.
2.) Attacker sends the hash to get the encrypted vault
3.) Attacker gets the encrypted vault
4.) Attacker is sad, because they don't have the MasterPassword, and thus have no access to all your passwords
Note that I'm not saying that they are awesome, and/or are doing the above. But it's not immediately obvious that a MasterPassword can't hash a forum login and a vault request at the same time. I mean, that's literally what the "MasterPassword never leaves the client" is supposed to mean.
1.) Game over.
2.) Modify login.php to send form username/password to attackers server.