Skip to main content

Using LastPass? You need to switch urgently, says security firm

It’s a good idea to use one of the best password managers to keep your logins safe, but now a security company is warning that one of the most popular password managers in the world is not safe to use.

The extraordinary claim comes from Intego, a firm that specializes in Mac security. Intego made its assertion based on a series of security breaches LastPass has suffered in recent months, the way LastPass has responded to those incidents, and the underlying technology LastPass uses to protect customer accounts.

A dark mystery hand typing on a laptop computer at night.
Andrew Brookes / Getty Images

In its report, Intego outlined the LastPass saga, from its initial disclosure of a breach in August 2022 up to an investigation by rival password manager 1Password in December. That timeline paints a picture of a password manager with questionable practices and technology, Intego states.

In August 2022, LastPass notified users that its development environment had been accessed by an unauthorized third party but that no customer data was taken. Then, LastPass issued a new statement in November stating that hackers had taken “certain elements of … customers’ information.”

Finally, in December, LastPass admitted the data accessed by the hackers was used to trick a company employee into handing over keys to some customer credentials, which were then used to access and decrypt customer data.

Questionable practices

Man using a Macbook Pro at a desk.
Ash Edmonds/Unsplash

However, Intego maintains that third-party analyses of the breach suggest a more troubling scenario. According to security researcher Wladimir Palant, for example, LastPass’s statements were “full of omissions, half-truths, and outright lies.” One of Palant’s allegations is that LastPass’ implementation of a password-strengthening algorithm is not considered strong enough based on industry standards, making users’ vaults far too easy to hack into.

Rival password manager 1Password has added its opinion into the mix, claiming that it would cost a hacker $100 or less to crack the master passwords protecting many LastPass vaults, such is the weakness of LastPass’ hashing methods.

All of that has led Intego to state that, “given what we now know about LastPass — both how the company operates and its technology — we do not recommend using LastPass as a password manager.”

How to keep your passwords safe

password manager lifestyle image
Image used with permission by copyright holder

It’s a remarkable statement to make given LastPass’ popularity. LastPass itself claims it has over 33 million users — if the claims about its lax security are correct, that’s a huge number of people whose accounts, passwords and credit card data are all now potentially vulnerable.

Right now, Intego advises LastPass users to immediately begin migrating their accounts to another password manager. Once that’s complete, the company recommends users update all of the passwords that had been stored in LastPass with fresh replacements.

It goes to show that not even the most popular services are immune to hacking attacks and security breaches. Whether you use a password manager or not, you can protect yourself by using strong, unique passwords that are not used on multiple sites. That way, one breach won’t lead to all your other accounts being compromised.

Editors' Recommendations

Alex Blake
In ancient times, people like Alex would have been shunned for their nerdy ways and strange opinions on cheese. Today, he…
Best LastPass alternatives for 2021
A digital security lock.

Whether you're security-conscious or have a terrible memory, using a free password manager is a great way to free up brain space and secure your most important information. Unfortunately, LastPass -- one of the best password managers -- has taken steps to sharply limit the features of free accounts, including only being able to use the free version on your PC or mobile devices (no longer both), and users will have three chances to determine which version to keep going forward. Understandably, many free account users are now searching for the best LastPass alternatives. Here are our favorites.
Best LastPass alternatives

Best premium alternative: Dashlane
Best iOS alternative: Apple iCloud Keychain
Best freemium alternative: Bitwarden
Best single-device alternative: NordPass
Best Android alternative: Google Password Manager

Read more
LastPass is scaling back its free tier. Find out if you need to pay
LastPass

LastPass currently offers a free tier that lets a single user access its password manager service on all their mobile devices and computers. But that’s about to change.

Starting March 16, the company will limit its free tier to only one device type, either mobile or computer. So if you select to keep the free tier for mobile, you’ll be asked to pay a fee to continue using the service on computers, and vice versa.

Read more
Leaving LastPass? Here’s how to take all your passwords with you
LastPass

If you, like many of us, have been happily using LastPass's excellent free tier for the last few years, you're probably dismayed that LastPass is moving to change the way its free access works. From March 16, you'll only be able to sync your LastPass database between mobile devices or computers -- but not both. So if you want to keep accessing the same passwords on your phone and laptop, you'll have to pay up and join LastPass's premium subscription for $3 a month.

Of course, not everyone is wild to pay a subscription fee -- or has the free cash to do so. If that's you, you're probably looking for a password manager to replace LastPass. But you won't want to leave all your collected passwords and logins behind. Thankfully, you can quickly and easily export your LastPass passwords and login information and import them into your new password manager of choice. So go check out our list of the best password managers, then dive into our guide on how to leave LastPass and take your passwords with you.
Export your LastPass database
Now that you know you're moving from LastPass, the first step is to make sure you take everything with you. Thankfully, exporting your database from LastPass is simple. Unfortunately, there's no way to export your passwords from the mobile app, so you'll have to use a PC or Mac to complete this action.

Read more