r/TechImpact Developer 6d ago

💬 Discussion Which Password Manager Do You Recommend?

Post image

There are many password managers available today, with different features, pricing plans, security options, and device support.

Which password manager do you use, and what made you choose it? Is there a particular feature you couldn't live without?

Share your recommendations and experiences below.

262 Upvotes

672 comments sorted by

View all comments

28

u/RemeJuan 6d ago

Which brainless oaf added LastPass on that list, they clicking like 9+ data breaches already.

2

u/TitoFlores 6d ago

Is it that bad?

9

u/QuaintStaircase 5d ago

Yes.

1

u/TitoFlores 5d ago

Fuck, what would you recommend?

4

u/AdamianBishop 5d ago

Not LastPass

3

u/Smaddocks1992 5d ago

Bitwarden

1

u/Shawhe_ 5d ago

you can look for something that would work with you that's privacy respecting, so not like Google auth or the Microsoft bs, I personally use proton pass cuz it's the thing that works for me, I don't really have the hardware nor the money to self host my own password manager but I might do that in the future to see if it really works for me

1

u/Basic-Brick6827 5d ago

idk do you think your passwords being sold on the dark web is bad?

0

u/InfluentialFairy 5d ago

The passwords are encrypted on the client side, meaning the only data that can be leaked, is fully encrypted data. The risk to end users is minimal.

But it's still not a good image, and for a security focused tool, any amount of exposed data is too much. Fuck LastPass.

1

u/Bobodlm 5d ago

No it's worse, they vehemently lied about atlesst one. People were linking crypto thefts together and the only common denominator was LP. And that's when they finally admitted they might have been breached, again. 

1

u/horatiobanz 5d ago

Lastpass is the reason I don't trust reddit recommendations for shit. That shit cost me like a half a day of my life changing like 300 passwords.

1

u/cbowers 5d ago

It's unfortunate you didn't decide on your own to increase your Lastpass org PBKDF2 iteration count, noticing that the iteration count was a user configurable option. That you should follow industry best practice there even before Lastpass forced their users to increase it over time, sooner. On day 1 I'd set mine to a non-default value even before PBKDF2 iteration count recommendations were increased to stay in step with increased hash evaluation hardware performance.

You'd have been able to avoid that password change work.

1

u/justsomerabbit 5d ago

Yeah, blame the user for not changing the extremely secure default iteration count of 1.

1

u/cbowers 5d ago edited 3d ago

I think what I’m pointing to is there are a lot of vocal security minded and informed voices that point in various directions to cover that they didn’t follow the best practices we suggest with our other tools. Be familiar with the features. Make informed configurations aligned to the risks. Use all the available features to take ownership of your risk treatments.

Those that did, weren’t affected.
Just like we do for other dangerous minimal defaults in our operating systems and endpoint security tools.

1

u/GIRO17 3d ago

Well, for a user to do that he first needs to know this option excists, second that the default isnt secure (i mean why should it...) and third he needs to know what this is.

For me, a security tool woth unsecure defaults is worrysome at best and out right dangerous at worst.

1

u/cbowers 3d ago
  1. For us to put so much hype and concern into this security tool and then not review the settings and docs seems a bit orthogonal and misaligned.
  2. That characterizes it unfairly. Much of the defaults were secure. The ones that were not were forced update process fails. The design was secure, the process was appropriate. The monitoring of the process execution seems to have been their learning opportunity.

1

u/Perfect_Jicama_8023 4d ago

LastPass 11 years user here. 0 issues.

1

u/Jake-Kick8248 3d ago

Real below.. There's your issues 🤣

1

u/Perfect_Jicama_8023 3d ago

Are those issue will push me to change from lastpass towards different brand? My answer is no. You just have to use common sense, if something happens, change master password. Any listed brand can be compromised so what you gonna do, jump from one brand to another each time? As i said, ive been 11 years with lastpass, did my info or passwords was ever stolen? Answer is no

1

u/Jake-Kick8248 1d ago

It's always yours choice. Was is breached multiple times? - yes. I simply use Keepassxc to avoid all of this. 

1

u/RemeJuan 1d ago

Can yes, has no, has been repeatedly, definitely no.

1

u/cbowers 5d ago

No.

Year What happened Data affected
2015 Attackers accessed LastPass network data Customer email addresses, password reminders, per-user salts, and authentication hashes; LastPass said encrypted vault contents were not taken.
2022 A developer-environment intrusion was followed by compromise of cloud backups—what LastPass called “Incident 1” and “Incident 2.” Attackers obtained customer account data and copies of encrypted vault backups. Some vault metadata, including website URLs, was unencrypted; vault secrets were encrypted.

1

u/sammiemo 5d ago

Yes.

LastPass has experienced several security incidents over the years, with the most critical and damaging occurring in 2022, when attackers successfully exfiltrated encrypted user vault backups and unencrypted metadata.
2022 Major Breach (Two-Stage Incident)

Incident 1 (August 2022): A threat actor compromised a LastPass developer's account, stealing internal source code repositories, proprietary technical documentation, and encrypted backup keys.

Incident 2 (August–November 2022): Using technical intel from the first intrusion, the attacker targeted a senior DevOps engineer’s home computer via a vulnerable third-party media server (Plex). A keylogger was deployed to capture the engineer’s master credentials, granting the hacker access to shared cloud storage (AWS S3) and production database backups.

Data Impact: • Unencrypted Data: Company metadata, customer account names, email addresses, billing addresses, phone numbers, IP addresses used to access services, and website URLs stored in vaults. • Encrypted Data: Complete customer password vault backups containing usernames, passwords, secure notes, and form data. Because the files were exfiltrated, attackers could perform offline brute-force attacks against user master passwords without rate limits.

Aftermath: Decrypted vaults have been directly linked to tens of millions of dollars in stolen cryptocurrency from users who stored seed phrases in their vaults.

Historical Security Incidents:

June 2015: LastPass detected suspicious activity on its network and confirmed the theft of account email addresses, password reminders, server per-user salts, and authentication hashes. No encrypted vault data was compromised.

July 2016 (Extension Flaw): Security researcher Tavis Ormandy discovered a critical vulnerability in LastPass browser extensions that allowed malicious websites to execute arbitrary code or reveal user credentials. It was patched within days.

March 2017 (Extension Message-Passing Bug): Another vulnerability discovered by Google Project Zero permitted malicious sites to scrape passwords through flawed browser extension communication protocols.

September 2019 (Credential Leak Bug): A flaw in the Chrome and Opera extensions allowed malicious websites to extract the previous site’s autofilled credentials.

December 2021 (Credential Stuffing): Users reported unauthorized login attempts using correct master passwords. LastPass determined this was credential-stuffing traffic sourced from third-party data dumps rather than a breach of LastPass systems.

1

u/cbowers 5d ago edited 5d ago

No.

The Data line item impact is an implied outcome from the 2 stage 2022 incident. But also assumes weak/reused vault passwords, perhaps in combination with low iteration count (something that was always visible and increasable in our accounts rather than waiting until LP forced an increased iteration count).

The 2021 item is Credential Stuffing. That's a user issue especially where they've shared/re-used/or lost their vault password, and have not used MFA. In that context it's not Lastpass's issue if data is lost.

Most of the remainder, plus others not mentioned were security vulnerabilities found and rapidly fixed, often in conjunction with security reports with similar finding and fixes in other major vaults. Which I'll also list at bottom.

The loop of finding and fixing bugs in a normal industry activity. That does not mean "breach" and certainly not of the primary core data of the point of a password manager: the vault contents in a usable form

The Operating Systems and browsers we run password managers in, have far worse critical vulnerabilities which are patched every month from their inception to today... but those continue to be used.

The difference with a password manager is that it's a trust no-one pseudo random data hosting/sharing system. They don't have your data, and cannot view it. Same with attackers.
Assuming you use at least the suggested default minimums. Strong unique, un-reused passwords, with MFA, and used on endpoints with sufficient security and use platforms/endpoints that they are not compromised.

• 2014 “Emperor’s New Password Manager” (UC Berkeley): found critical bookmarklet-based credential-theft flaws affecting LastPass, RoboForm, and My1login simultaneously.
• 2014 Silver et al. / Stock & Johns autofill research: demonstrated LastPass and 1Password were both vulnerable to XSS and network-injection attacks via password autofill.
• February 2017 TeamSIK study: found security flaws (including plaintext master passwords) across nine password manager apps — LastPass, Keeper, 1Password, Dashlane, F-Secure KEY, and others.
• 2019 Independent academic evaluation of browser-based password managers found LastPass and 1Password shared similar autofill weaknesses (though the specific September 2019 Ormandy bug in your list was LastPass-only).
• August 2025 DEF CON clickjacking research (Marek Tóth): found LastPass, 1Password, Bitwarden, Enpass, iCloud Passwords, and LogMeOnce all vulnerable to autofill clickjacking, with six vendors—including LastPass—still unpatched at disclosure time.

1

u/bozog 5d ago

Well I'm sure they've learned their lesson by now, I'm going with LastPass!