> I downloaded the popular rockyou.txt wordlist and put my actual vault master plaintext password inside Note that is NOT a demonstration of being able to crack an encrypted LastPass vault. The author's exercise wouldn't be feasible without prior knowledge of the master password, or choosing a master password that is present in a list of common passwords. That is consist with what we have heard from LastPass so far.
Agreed, it was a bit disappointing to get to the part where the password was added to the word list. The author does point out that a 2,000,000+ hashes per second could be achieved so it might give insight into how quickly all accounts will be checked against popular word lists. If I was a last pass customer I would be thinking about changing passwords on all accounts.
Why is that disappointing? It is a proof of concept, rather than evidence that it has already been done. Sure, it is not novel and perhaps it is overstated, but it does point out that attacks are already possible. It would also be interesting to see the results of a dictionary attack to see if the behaviour of people who use password managers is any better than the population as a whole.