>stored in a proprietary binary format that contains both unencrypted data, *such as* website URLs,
What do you mean such as?? What else is unencrypted? Now is not the time for tip-toeing around this kind of stuff.
>stored in a proprietary binary format that contains both unencrypted data, *such as* website URLs,
What do you mean such as?? What else is unencrypted? Now is not the time for tip-toeing around this kind of stuff.
weird term for std::vector<std::string>
I've never used LastPass, but if the URLs would be encrypted then checking "is there a password for news.ycombinator.com?" would require unlocking the vault, right?
So then you'd at least have to enter your password once on (browser) startup so it can load the list and keep that in memory, and you won't be able to automatically sync things either.
Correct. However this is how it ought to be. If someone acquires my laptop, I dont want logging into my accounts to be as easy as opening the browser
I use pass and this attack vector is why I don't sync even in a private git repo like many suggest. I do sync but only encrypted tar files, and even then some sensitve sites are aliases instead of URLs.
Sure it makes life a little more difficult but for some things convenience should be the last priority.
https://github.com/cfbao/lastpass-vault-parser/wiki/LastPass...
In particular all timestamps (creation, last modification, last access) are unencrypted, as are information about whether you want to auto-logon or auto-fill, whether the password was auto-generated and whether the password has been breached.
Field 10: "genpw": "Is an auto-saved generated password". Good for deciding whether to brute force or not.
Yikes. I can't imagine why anyone would trust Lastpass after this.