SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Pastimes : Computer Learning -- Ignore unavailable to you. Want to Upgrade?


To: SteveinTX who wrote (90576)9/1/2015 1:38:49 PM
From: lrb  Read Replies (1) | Respond to of 110653
 
What is stored in the cloud is encrypted gobbledygook, but if someone got hold of YOUR gobbledygook and YOUR master password, they could decode the gobbledygook and have access to your password data. Or if they got hold of your gobbledygook alone, they could use whatever means to try to brute force or otherwise discover the password.

It is correct that the encryption/decryption only happens on the device where we are using LastPass, and the LastPass servers receive and store only encrypted data.

This is just my understanding as a customer; as I stated earlier, I do not mean to suggest I am an expert in this area.



To: SteveinTX who wrote (90576)9/1/2015 2:28:42 PM
From: LTBH  Respond to of 110653
 
A discussion of the encrypted goobledegook gets into how secure are the hashes for the encryption, the cloud and the end to end data transfer security ... all of which get quite involved but both have long standing well known weaknesses/holes.

For those that really wish to dig into this detail, it will probably take a number of searches to obtain data. IIRC there was a not too long ago couple of articles on end to end data security (lack of complete point to point) as well as some on hash weaknesses/holes.

A discussion of the difficulty of protecting from keyloggers and the methods/weakness of available software to do such might aid to some understanding and could possibly be a good starting point in the above search.

Luck
LTBH