To be clear, I was not describing a hack. LastPass can be forced by the US government to get a LastPass users keys. All they need to do is get a court order and tell LastPass to send some backdoored code to the user, exactly like they do with Hushmail.