Review my startup: Automate registration, sign-in and checkout.
Several key points about our security:
- Each Dashlane user has a master password, solely used to encrypt data locally and another key for each device used for authentication against Dashlane’s servers
- The Master password is derived using more than 10,000 PBKDF2 rounds with a 32 bytes random salt to produce the encryption key used to encrypt user’s data locally. Encryption algorithm used is AES-256 (CBC mode).
- Neither the Master Password nor any derivative of it is ever sent to or stored on our servers, nor locally on your computer. When synchronized, personal data are sent encrypted to our servers.
If you are interested in details about our security, here's a white paper that explains in technical words exactly what we do: https://www.dashlane.com/download/Security-Whitepaper-Final-Nov-2011.pdf
Anyway, I would love to have HNers testing our product, so I have 300 invites for those who would be interested: https://www.dashlane.com/hackernews.
Please let me know what you think about it, the Dashlane team and me would be happy to talk with you.