<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2939087088852583826.post6511020056284302409..comments</id><updated>2010-03-01T20:54:26.411-05:00</updated><title type='text'>Comments on LastPass the last password you'll have to remember.: After Yahoo Email Debacle, Sarah Palin Needs Lastp...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.lastpass.com/feeds/6511020056284302409/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default'/><link rel='alternate' type='text/html' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html'/><author><name>lastpasser</name><uri>http://www.blogger.com/profile/04121684558988738880</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2939087088852583826.post-3650777200997537300</id><published>2010-03-01T20:54:26.386-05:00</published><updated>2010-03-01T20:54:26.386-05:00</updated><title type='text'>I wanted to give up RoboForm, but LastPass won't f...</title><content type='html'>I wanted to give up RoboForm, but LastPass won&amp;#39;t fill the username at Amazon.com. That was one of the first sites I tried. If that doesn&amp;#39;t work, well I&amp;#39;ll wait for RoboForm to get their act together for the Chrome add-on.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default/3650777200997537300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default/3650777200997537300'/><link rel='alternate' type='text/html' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html?showComment=1267494866386#c3650777200997537300' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html' ref='tag:blogger.com,1999:blog-2939087088852583826.post-6511020056284302409' source='http://www.blogger.com/feeds/2939087088852583826/posts/default/6511020056284302409' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2939087088852583826.post-150659948285309371</id><published>2008-09-30T11:09:55.464-04:00</published><updated>2008-09-30T11:09:55.464-04:00</updated><title type='text'>Loved LastPass!I'm giving up from Roboform!</title><content type='html'>Loved LastPass!&lt;BR/&gt;I'm giving up from Roboform!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default/150659948285309371'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default/150659948285309371'/><link rel='alternate' type='text/html' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html?showComment=1222787395464#c150659948285309371' title=''/><author><name>Mitcha</name><uri>http://www.blogger.com/profile/11189343173688532919</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html' ref='tag:blogger.com,1999:blog-2939087088852583826.post-6511020056284302409' source='http://www.blogger.com/feeds/2939087088852583826/posts/default/6511020056284302409' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2939087088852583826.post-4073732542151241351</id><published>2008-09-26T07:36:58.893-04:00</published><updated>2008-09-26T07:36:58.893-04:00</updated><title type='text'>I had this same question and asked the Lastpass te...</title><content type='html'>I had this same question and asked the Lastpass team for a non-jargon  explanation and got this from Bob:&lt;BR/&gt;&lt;BR/&gt;Neither your site specific passwords or your Lastpass password ever leaves your computer.  Your site-specific passwords are encrypted locally converted from passwords with value into encoded string of characters with no intrinsic value. &lt;BR/&gt;&lt;BR/&gt;For example if your use Lastpass to store your password for Amazon.com and your password for Amazon is "Amazn1" Lastpass converts "amazn1" into an encrypted string: encrypted string that has been encoded: YpCEhki/Bbs3l1eFsRpWSQ==&lt;BR/&gt;&lt;BR/&gt;Lastpass stores this encrypted string. It is completely meaningless to us or anyone else without the key.  The key is created from your master Lastpass password. and your log-in  Your username+password combination is hashed in 2 ways:&lt;BR/&gt;1) To create your password hash that is sent to us for authentication&lt;BR/&gt;2) To create your encryption key which is never sent to us&lt;BR/&gt;&lt;BR/&gt; For example your the password hash might look like:&lt;BR/&gt;5dff3ab77d45983d9c3005435da0ac&lt;BR/&gt;eb13db373ef5cd829dda196da402160aba&lt;BR/&gt;&lt;BR/&gt;This is a one way hash and there is no way for us to get the original string.  We also create your key that we use for encrypting/decrypting your data locally. This is never sent to us. It looks similar in structure (same length, character set [0-9, a-f] used) to the hash above, but is different.&lt;BR/&gt;&lt;BR/&gt;When you log into Lastpass from a foreign computer, the user enters his/her Lastpass username and passsword into the website. Both the authentication hash and the encryption key are generated from these. Javascript (running locally on the computer) performs the hashing. Then the computer make a request to our servers to authenticate and pull down their encrypted data. Again, locally (in javascript) we perform the decryption of the data with their key.&lt;BR/&gt;&lt;BR/&gt;Once you log off a foreign computer, Lastpass instructs the browser not to cache the page. Most browsers don't save https pages anyway. But even if the browser did cache the page, it is dynamically generated via javascript, so without the username/password combination to decrypt the data, the data is meaningless.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default/4073732542151241351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default/4073732542151241351'/><link rel='alternate' type='text/html' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html?showComment=1222429018893#c4073732542151241351' title=''/><author><name>lastpasser</name><uri>http://www.blogger.com/profile/04121684558988738880</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='09416086557141130868'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html' ref='tag:blogger.com,1999:blog-2939087088852583826.post-6511020056284302409' source='http://www.blogger.com/feeds/2939087088852583826/posts/default/6511020056284302409' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2939087088852583826.post-889336243350400131</id><published>2008-09-26T06:19:58.953-04:00</published><updated>2008-09-26T06:19:58.953-04:00</updated><title type='text'>It sounds like some word play, but overall I think...</title><content type='html'>It sounds like some word play, but overall I think for the most part, it's more true in meaning than not.&lt;BR/&gt;&lt;BR/&gt;I think they mean that your encrypted data is on their servers, but it's gibberish and completely meaningless to them without your password...and you're the only person who has that password.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default/889336243350400131'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default/889336243350400131'/><link rel='alternate' type='text/html' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html?showComment=1222424398953#c889336243350400131' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html' ref='tag:blogger.com,1999:blog-2939087088852583826.post-6511020056284302409' source='http://www.blogger.com/feeds/2939087088852583826/posts/default/6511020056284302409' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2939087088852583826.post-2122667207455533457</id><published>2008-09-26T05:59:52.154-04:00</published><updated>2008-09-26T05:59:52.154-04:00</updated><title type='text'>I don't understand when you say, "Lastpass doesn’t...</title><content type='html'>I don't understand when you say, "Lastpass doesn’t ... have access to any of my information, it doesn’t get saved onto their servers".&lt;BR/&gt; - I get the first part: that you don’t have "access" to any of my information, because it's encrypted and you don't have my Lastpass-login password. That seems to be the real point. However, saying that you don't save my info on your servers seems untrue, since you make my "passwords accessible online, ... from virtually anywhere, anytime" (as your home page says).&lt;BR/&gt; - Can you clarify this?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default/2122667207455533457'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2939087088852583826/6511020056284302409/comments/default/2122667207455533457'/><link rel='alternate' type='text/html' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html?showComment=1222423192154#c2122667207455533457' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.lastpass.com/2008/09/after-yahoo-email-debacle-sarah-palin.html' ref='tag:blogger.com,1999:blog-2939087088852583826.post-6511020056284302409' source='http://www.blogger.com/feeds/2939087088852583826/posts/default/6511020056284302409' type='text/html'/></entry></feed>