(Note that this is a USENIX paper, which makes the "we let them publish it" comment sort of weird).
The bookmarklet attack isn't subtle; page 8 explains how they were able to set up a malicious site that could obtain Lastpass (say) Dropbox credentials.
Comments
I think this is the research they're referring to:
http://devd.me/papers/pwdmgr-usenix14.pdf
(Note that this is a USENIX paper, which makes the "we let them publish it" comment sort of weird).
The bookmarklet attack isn't subtle; page 8 explains how they were able to set up a malicious site that could obtain Lastpass (say) Dropbox credentials.
It's not a 'we let them publish' it's a we respected their wishes in that we would hold off on talking about it until they published.