A year after the disastrous breach, LastPass has not improved

https://palant.info/2023/09/05/a-year-after-the-disastrous-breach-lastpass-has-not-improved/

84 points · 9 comments · view on lemmy.world

9 Comments

gumdropbunnies@lib.lgbt · 24 pts · 3y (1 reply)

Honestly as soon as they made supporting more than 1 device a "premium" feature I dropped them like a bad habit. Fuck LastPass, Bitwarden does exactly what they do but 1000x better

psivchaz@reddthat.com · 4 pts · 3y

I dropped them for Bitwarden in 2015, after the first hack. I stuck around at first, thinking that they had had a breach but nothing was compromised that we know of so maybe it was a small thing and they learned a valuable lesson and it wouldn't happen twice.

Around May I spotted a bug in how organizations were handled. I legitimately can't remember all of the details. You could basically get access to passwords in your organization that weren't shared with you under a specific circumstance. It wasn't disastrous, it wasn't like every org password was accessible, but it was still fairly serious as my company was using it. I figured given that they had recently had a breach, given that my company was paying for the expensive plan, surely they would take it seriously.

3 months later, they hadn't responded and it hadn't been fixed. Picked an alternative and never looked back.

PotatoesFall@discuss.tchncs.de · 10 pts · 3y (1 reply)

this company just needs to disappear. They have no reason to exist anymore

KingGordon@lemmy.world · 3 pts · 3y

"Its bad enough you exist when nobody wants you"

chemicalprophet@lemm.ee · 7 pts · 3y (2 replies)

Yeah but who's still using it when Bitwarden exists?

PotatoesFall@discuss.tchncs.de · 9 pts · 3y (1 reply)

or anything. LastPass is the Last Password manager you should ever use

Senseless@feddit.de · 3 pts · 3y

Oh, therefor that name

ignotum@lemmy.world · 5 pts · 3y

KeePass + Syncthing all the way!

I was paying for lastpass because i liked it, but the UI got progressively more convoluted, it failed to autofill login prompts and kept trying to autofill random non-login text field, so when they had yet another breach i exported all my data and deleted my account, switching to keepass, which has a better UI and autofill in my experience

Draconic_NEO@pawb.social · 3 pts · 3y

No one should be using LastPass when there are so many better options that exist.