Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Lastpass stores your password encrypted. If in your threat model you're unwilling to use Lastpass because of the leakability of the master database, you should avoid Lesspass since trying to guess your password on Webstie X given Lastpass database is more/less the same as trying to guess it given you're using Lesspass.


Like I said before, leakability of master database is not that big concern. DDoS on Lastpass, however, is a very likely scenario, especially in the light of recent high-profile DDoS attacks.


DDoS on LastPass is not a big deal as long as you have at least one device logged on. LastPass database is stored locally and can be used off-line.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: