These cloud based solutions perform hashing+salting+KDFing locally and then add additional compute cost on the cloud level.
I don't see any issues with that.
I don't see any issues with that.
Via the master-key, the program derives(locally) the key to encrypted the data and a different secondary key for authentication against the server. without knowing the master-key you can't decrypt the vault even if you were able to trick the server into sending you the vault.
The vault is decrypted locally