Lastpass security issues

broken image
broken image

I was specifically talking about _online_ password managers in that quote. And I would very much like not to worry about maintaining accounts, updating passwords, etc. I was a LastPass user for many years, many years ago, and trusted them, but have since moved all my passwords offline. There have been some usability improvements in recent years in this area, to the point where it could reach mass adoption, but the change needs to start with developers.

broken image

The way forward is to get rid of passwords altogether and make passwordless authentication the norm. Many non-technical people don't bother or care at all. They're too confusing and a chore to use for the general public, even if users are educated about their importance, and would like to secure their accounts. Password managers are an entire section of software that shouldn't exist. To think that any company could handle this responsibility is naive at best. They're major centralized honeypots given the data they handle, and leaks are probably worth millions on the black market. Sure, but password managers available over the internet are especially vulnerable. I’m sure LastPass tried really hard to protect data.

broken image