I understand why they do this: it's convenient and lets you share/give passwords to others. But this feature is 100% incompatible with the claim that they never see your master password.
I understand why they do this: it's convenient and lets you share/give passwords to others. But this feature is 100% incompatible with the claim that they never see your master password.
1. The encryption key is a local hash of your email address and master password. This never leaves your computer.
2. Ignoring PBKDF2, Your encryption key and your master password are again hashed locally. That is sent with your login email to LastPass.
3. LastPass hashes Step 2 with a salt and that result is then used to authenticate you. After any additional two factor auth verification, LastPass will send your password file, which is decrypted using the result in Step 1, that has never left your computer.
You're more than welcome to inspect the JavaScript code yourself. They have a simple encryption, decryption page so you can see exactly what LastPass does.
So their servers get a hashed version of your password, but not the password itself. Their servers likely also store a hashed version of your password so that they can authenticate you. This style of auth is also used when you use the "show me the password" feature.
Our choice could be to not allow people to utilize the website but it seems like educating people of the risks and letting them decide is the best policy.
So then what would prevent someone from using the Heartbleed attack to obtain your private key that use used to secure the HTTPS connection from me to your servers, then inject malicious JavaScript into the page where I enter my password? This is the attack I am worried about outside of Heartbleed as well, since any CA can issue a valid certificate for lastpass.com and I would not know that I am being MITM'ed.
From a strict security point of view, disabling website access seems like the best policy. From a usability standpoint, I understand the tradeoff you made. Perhaps an option at the account level that disabled website access might be a good idea.
Also, how are the share/give functions handled? I know what "share" is not really keeping my password from being seen by the other person (there are a variety of techniques they can use to get at it), but how is the encryption handled on your end?
Lastly, how do I know that the browser extension I download from you is secure? Is there a way for me to verify it somehow?
Having said all that, I absolutely love your product and recommend it to everyone I know. It's a huge net win in terms of security.