Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
phyzome
on Dec 1, 2022
|
parent
|
context
|
favorite
| on:
Lastpass Security Incident
Last I checked, they still didn't have a useful Content-Security-Policy header on their Web Vault (which would prevent XSS), and also didn't have a way to separate "being logged into the extension" from "being logged into the Web Vault".
I... would definitely not recommend them, no.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
I... would definitely not recommend them, no.