It seems they take info from the site (its name?) plus your master password and hash them - "LessPass uses PBKDF2 with 8192 iterations and a hash function sha-256."
I guess they then produce something of the required length and characters from the hash.
Guess it's ok till someone finds your master password.