isn't this wildly insecure? at the very least it means lastpass can read all your passwords at any time.
isn't this wildly insecure? at the very least it means lastpass can read all your passwords at any time.
When you designate someone for emergency access, it also encrypts your vault with their public key. In a way the person and Lastpass hold each other accountable because:
1. Lastpass only gives the encrypted vault data to the emergency contact after the waiting period. They cannot decrypt the vault without having the encrypted vault data.
2. The person's private key is encrypted inside their vault by their master password. As lastpass doesn't know their master password for their vault, lastpass doesn't have the key to your vault.
I would not call this "wildly insecure", but definitely has more risk factors than not doing it. For most people I think this is a reasonable tradeoff if they want people to be able to access their data without huge inconvenience.
Not if it's been done right. They'd use some kind of multi-key secret sharing scheme (like shamir), where the password database would be encrypted with the public keys of both lastpass (the custodian) and the designated person. (This would be done on the client side, by the designator.)
https://en.m.wikipedia.org/wiki/LastPass#2011_security_breac...
LastPass’s history is troubling but they’re also the biggest target out there. IMO, the entire space of “cloud” password managers is inherently untrustworthy.