This is the problem I have with Lastpass - someone could hack their servers, replace the javascript encryption file to send the decryption password to their server, and get all of your passwords.
you are talking about web access from a public computer I suppose? if you are connecting from your computer then I suppose the decryption happens in the browser extension and you are safe from the scenario you describe, or am I missing something?
I am talking about either situation. Someone could hack their site (angry employee, outside person, etc), and modify the code to send the decryption password to their server. This would work for either situation since the person could push an update out for the browser extension.
I'm sure they are very careful about the security of their system, but they are still one step away from having all of your passwords (a simple extension update, or site javascript modification). If I use a program like keepassx, I know when it's updated, and can verify that it doesn't attempt to communicate with a remote server.
Comments
This is the problem I have with Lastpass - someone could hack their servers, replace the javascript encryption file to send the decryption password to their server, and get all of your passwords.
you are talking about web access from a public computer I suppose? if you are connecting from your computer then I suppose the decryption happens in the browser extension and you are safe from the scenario you describe, or am I missing something?
I am talking about either situation. Someone could hack their site (angry employee, outside person, etc), and modify the code to send the decryption password to their server. This would work for either situation since the person could push an update out for the browser extension.
I'm sure they are very careful about the security of their system, but they are still one step away from having all of your passwords (a simple extension update, or site javascript modification). If I use a program like keepassx, I know when it's updated, and can verify that it doesn't attempt to communicate with a remote server.