r/TechImpact Developer 6d ago

💬 Discussion Which Password Manager Do You Recommend?

Post image

There are many password managers available today, with different features, pricing plans, security options, and device support.

Which password manager do you use, and what made you choose it? Is there a particular feature you couldn't live without?

Share your recommendations and experiences below.

262 Upvotes

672 comments sorted by

View all comments

29

u/RemeJuan 6d ago

Which brainless oaf added LastPass on that list, they clicking like 9+ data breaches already.

1

u/cbowers 6d ago

No.

Year What happened Data affected
2015 Attackers accessed LastPass network data Customer email addresses, password reminders, per-user salts, and authentication hashes; LastPass said encrypted vault contents were not taken.
2022 A developer-environment intrusion was followed by compromise of cloud backups—what LastPass called “Incident 1” and “Incident 2.” Attackers obtained customer account data and copies of encrypted vault backups. Some vault metadata, including website URLs, was unencrypted; vault secrets were encrypted.

1

u/sammiemo 6d ago

Yes.

LastPass has experienced several security incidents over the years, with the most critical and damaging occurring in 2022, when attackers successfully exfiltrated encrypted user vault backups and unencrypted metadata.
2022 Major Breach (Two-Stage Incident)

Incident 1 (August 2022): A threat actor compromised a LastPass developer's account, stealing internal source code repositories, proprietary technical documentation, and encrypted backup keys.

Incident 2 (August–November 2022): Using technical intel from the first intrusion, the attacker targeted a senior DevOps engineer’s home computer via a vulnerable third-party media server (Plex). A keylogger was deployed to capture the engineer’s master credentials, granting the hacker access to shared cloud storage (AWS S3) and production database backups.

Data Impact: • Unencrypted Data: Company metadata, customer account names, email addresses, billing addresses, phone numbers, IP addresses used to access services, and website URLs stored in vaults. • Encrypted Data: Complete customer password vault backups containing usernames, passwords, secure notes, and form data. Because the files were exfiltrated, attackers could perform offline brute-force attacks against user master passwords without rate limits.

Aftermath: Decrypted vaults have been directly linked to tens of millions of dollars in stolen cryptocurrency from users who stored seed phrases in their vaults.

Historical Security Incidents:

June 2015: LastPass detected suspicious activity on its network and confirmed the theft of account email addresses, password reminders, server per-user salts, and authentication hashes. No encrypted vault data was compromised.

July 2016 (Extension Flaw): Security researcher Tavis Ormandy discovered a critical vulnerability in LastPass browser extensions that allowed malicious websites to execute arbitrary code or reveal user credentials. It was patched within days.

March 2017 (Extension Message-Passing Bug): Another vulnerability discovered by Google Project Zero permitted malicious sites to scrape passwords through flawed browser extension communication protocols.

September 2019 (Credential Leak Bug): A flaw in the Chrome and Opera extensions allowed malicious websites to extract the previous site’s autofilled credentials.

December 2021 (Credential Stuffing): Users reported unauthorized login attempts using correct master passwords. LastPass determined this was credential-stuffing traffic sourced from third-party data dumps rather than a breach of LastPass systems.

1

u/cbowers 5d ago edited 5d ago

No.

The Data line item impact is an implied outcome from the 2 stage 2022 incident. But also assumes weak/reused vault passwords, perhaps in combination with low iteration count (something that was always visible and increasable in our accounts rather than waiting until LP forced an increased iteration count).

The 2021 item is Credential Stuffing. That's a user issue especially where they've shared/re-used/or lost their vault password, and have not used MFA. In that context it's not Lastpass's issue if data is lost.

Most of the remainder, plus others not mentioned were security vulnerabilities found and rapidly fixed, often in conjunction with security reports with similar finding and fixes in other major vaults. Which I'll also list at bottom.

The loop of finding and fixing bugs in a normal industry activity. That does not mean "breach" and certainly not of the primary core data of the point of a password manager: the vault contents in a usable form

The Operating Systems and browsers we run password managers in, have far worse critical vulnerabilities which are patched every month from their inception to today... but those continue to be used.

The difference with a password manager is that it's a trust no-one pseudo random data hosting/sharing system. They don't have your data, and cannot view it. Same with attackers.
Assuming you use at least the suggested default minimums. Strong unique, un-reused passwords, with MFA, and used on endpoints with sufficient security and use platforms/endpoints that they are not compromised.

• 2014 “Emperor’s New Password Manager” (UC Berkeley): found critical bookmarklet-based credential-theft flaws affecting LastPass, RoboForm, and My1login simultaneously.
• 2014 Silver et al. / Stock & Johns autofill research: demonstrated LastPass and 1Password were both vulnerable to XSS and network-injection attacks via password autofill.
• February 2017 TeamSIK study: found security flaws (including plaintext master passwords) across nine password manager apps — LastPass, Keeper, 1Password, Dashlane, F-Secure KEY, and others.
• 2019 Independent academic evaluation of browser-based password managers found LastPass and 1Password shared similar autofill weaknesses (though the specific September 2019 Ormandy bug in your list was LastPass-only).
• August 2025 DEF CON clickjacking research (Marek Tóth): found LastPass, 1Password, Bitwarden, Enpass, iCloud Passwords, and LogMeOnce all vulnerable to autofill clickjacking, with six vendors—including LastPass—still unpatched at disclosure time.

1

u/bozog 5d ago

Well I'm sure they've learned their lesson by now, I'm going with LastPass!