https://www.theverge.com/2019/9/16/20868111/lastpass-bug-exp...
>In a statement posted on its blog, LastPass downplayed the severity of the bug. The company’s Security Engineering Manager, Ferenc Kun, said that the exploit relied on a user visiting a malicious site and then being tricked into clicking on the page “several times.”
This was what led me to dump them and delete my account.
I thought at the time that A) they're sloppy and B) the next exploit will 100% be sold on the black market for minimum an order of magnitude higher price.
If there were a common exploit among the people on the HN thread like a compromised chrome extension I think they would have discovered it. There were a lot of people on that thread, a bunch of invalidated hypotheses and no clear commonalities.
Edit : i made a mistake - it only exposed the last used password in the vault. Pretty bad but not quite as awful as I first thought.