Post
Topic
Board Bitcoin Discussion
Re: Bitcoinica MtGox account compromised
by
dooglus
on 26/07/2012, 04:04:50 UTC
Its possible to login to your account via the website without downloading/installing anything. Therefore the password does get sent to their servers. Not that any of this is entirely relevant to the situation...

I don't think you're correct there.  LastPass doesn't even know my password.  Javascript on the browser is used to authenticate my login.

[...] LastPass employs localized, government-level encryption (256-bit AES implemented in C++ and JavaScript) and local one-way salted hashes to give you complete security with the go-anywhere convenience of syncing through the cloud. All encrypting and decrypting happens on your computer - no one at LastPass can ever access your sensitive data.

[unless you paste the master password into your source code and leak it to the world].