DashlaneCaden
DashlaneCaden t1_j8ee111 wrote
Reply to comment by 56kul in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
Ah yes & just to clarify, our extension still has to go through the signing & review process at Mozilla, including submitting source code occasionally for them to reproduce builds & validate + approve our extension. We just opted to distribute it ourselves rather than in the add-on store originally.
DashlaneCaden t1_j8ecrbu wrote
Reply to comment by 56kul in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
Absolutely!
So I cannot speak to why we went the route of hosting the extension ourselves rather than listing via the Firefox add-on store in the first place, but I can say it's on our roadmap to explore listing this year. I'm not on the team that handles our store automation & deployment processes, but from my understanding there is some work needed making the migration still & it's slated this year (with no specific date planned yet).
Our hosted version will still receive automatic updates, we're just missing out on the marketing / discoverability that the add-on store provides.
DashlaneCaden t1_j8eatvh wrote
Reply to comment by 56kul in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
Yep ! I'm an engineer on our web app / extension.
DashlaneCaden t1_j8e1fro wrote
Reply to comment by 56kul in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
Correct - we have never had a security breach (we even confidently state it front & center on our website). I'll never say it's impossible, but we are confident we deploy the highest level of security practices possible to ensure a breach will not happen.
DashlaneCaden t1_j8e18yu wrote
Reply to comment by Breklin76 in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
Dashlane has never had a security breach
DashlaneCaden t1_j8eeenv wrote
Reply to comment by 56kul in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
I believe the biggest hurdle is how to migrate users best from our hosted extension to the add-on store version, so we can avoid having to deploy & maintain the distribution of both versions. Moving from an unlisted extension -> listed is not as seamless as you'd expect, as it would technically be a new / separate extension on the add-on store.