It's like choosing a 4 ⭐️ product with 5000 reviews over a 5 ⭐️ product with 3.
Every security expert I've spoken to about password managers recommends against lastpass. Typically they recommend 1password, or passwordstore or sometimes even keepass.
The more apt comparison is a product with 100 2 star reviews vs one with 1000 4 star reviews.
1password has more recommendations by security engineers, and has been reviewed in significant depth.
Lastpass has been reviewed in depth, but is rarely recommended by the same engineers.
(some of it is of course also depends on the threat-model: something with no (or with more caveats, an explicitly activated browser integration) is way less likely to be vulnerable against attacks launched from a website, reviewed or not)
Since moving us to LastPass, compliance is through the roof. Using the browser extension makes it much easier for everyone. Administration is much simpler too. I'm actually considering moving some personal Keepass files to a personal LastPass account, as I now find myself comparatively frustrated when I have to use my Keepass files.
I can't speak to the vulnerabilities in 1Password but the reason we decided against 1Password is that the user experience for LastPass (Teams) is much better. There's no point in having a secure tool without compliance and bad UX is a show-stopper.
Also the vulnerabilities so far have been mostly non-concerning:
1. The vulnerabilities of the browser extensions generally require the user to access malicious URLs, so they still require some degree of interaction.
2. The actual hacks of LastPass didn't result in any passwords or confidential information being leaked, so they're not very interesting.
That 1Password hasn't seen similar disclosures doesn't mean 1Password doesn't have any vulnerabilities, nor that it didn't have them in the past. No software is without faults and so far LastPass has always reacted promptly. That 1Password doesn't have as many recent disclosures may simply mean that Tavis hasn't gotten around to looking at it yet.
I have changed my behavior to just using lastpass-cli and a self-written Go/Qt GUI wrapper over the CLI - https://github.com/alexzorin/lpass-ui - (only builds on Linux sorry) to protect myself from the problems of the browser extension.
While they have issues -- at least this is an issue I know that's been addressed.
"This password manager is bad, so all the others must be just as bad"... yeah.
Other password managers, like 1Password, are more frequently recommended by security engineers.
They're also not built entirely as browser extensions and interfaces, which massively increases attack surface.
Maybe the reason other password managers aren't tire-fires is because they're designed better and are more secure, not because they have more unknown issues.
I use lastpass with a yubikey for 2fa and I feel safe enough. I briefly looked at other password managers when I was evaluating lastpass, but convenience won out for me. I haven't looked at moving out of lastpass, but 3 years ago no other password manager came close to the mobile and platform support that lastpass had.
I considered keeping my passwordDB local, but the inconvenience of needing it and not having it wasn't it worth it to me. Do I know I'm making a tradeoff? Yes.
I also have a nasty habit of setting things up on a local server and then never updating it. Instead I decided that lastpass was worth the $12/year so I wouldn't have to manage anything locally.
So while lastpass may not be perfect security, I'm a lot better off than I was three years ago when I used the same few passwords everywhere.
It also helps me share passwords with my wife, so that's nice.
In light of recent revelations I'm considering going back. And possibly telling friends and family to maintain a separate LastPass for their important stuff, in a separate browser.
These two products are very feature-complete (at least for my usage) and have as much attention as LastPass (with for example Tavis Ormandy working on both). They even publish information about their security model[2][3], which LastPass does not.
LastPass has proven repeatedly that it is not robust enough for storing passwords. Fewer or less important vulnerabilities reported does not equate to less security.
2: https://1password.com/files/1Password%20for%20Teams%20White%...
3: https://www.dashlane.com/download/Dashlane-Security-Whitepap...
Linux support
Their responses in that thread do not inspire confidence in the product for me, to put it mildly.
I've never used LastPass, but 1Password Mini is pretty convenient. It's always ready to go in the menu bar, and once you enter your password it stays unlocked for a good while.
Just b/c they also have a bug doesn't make them any worse than anyone else or diminish their track record in general. And contrary to just about everyone else LastPass doesn't care to notify you of updates or have the auto-update mechanism on.
Before I switched to lastpass, I had maybe 10 different passwords I shared across 100 sites. This was terrible, and now that I use Lastpass, every password is unique. So I use Lastpass because its an incremental improvement.
Is 1Password an incremental improvement over lastpass? I'm not convinced. It might be a tiny bit more secure, but nowhere near the gain in security I had from 10 re-used passwords -> all unique randomly generated 20+ char passwords. The cost of switching is high and so it would have to be enough of an improvement to justify the switchover.
That isn't terrible so long as the email linked to them has a unique, strong password. How many of those sites need the highest level of vigilance?
People keep bringing up KeepPass, but apart from the bad UX, it's developers seem to be even more incompetent concerning basic security design. That leaves 1Password, which also hasn't covered itself in glory security-wise, but appears to be marginally more competent. No linux client though.