Ever wondered how LastPass works and how it gets away with never transmitting your password to their servers? Well here is my understanding of how it works based on
their own documentation. Please note that the iteration number chosen below for the client private key hash (7000) is for illustration purposes only. The server side iteration counter isn't known. And you guessed right: If you already have your password blob cached on your system then technically you don't even need to log on, as you can generate the decryption key locally at any time.
No comments:
Post a Comment