Now, the question is “why would I trust this?” to which I answer: I trust them to safeguard my passwords.
Isn't that tautological?
I trust 1Password more than LastPass simply because you _must_ pay for it. Freemium upsells are a dark pattern, and the temptation to monetize data on free users is much greater than paid.
The ultimate problem with this whole logic is that you trust that other individuals and companies are not tempted to "double-dip" by monetizing data on paying users. A comment in the reddit thread referenced in the article summarizes the problem neatly:
> These SaaS cloud services are completely unregulated and answer to no one except their own profits. They can and will hold your data hostage the moment they think they can do so profitably on a large scale. It doesn't matter whether you're paying for the service or not.
https://old.reddit.com/r/software/comments/s053t3/lastpass_i...
I don't think the logic is wholly broken - there will be a lower incentive for paid companies who can generate a profit with subscription fees to "double-dip" than there is for free companies to "single-dip" (who need to dip to survive).
It's all about relative risk between those two models - if company A has a business model that can work without doing shady shit, and company B has a business model that can only work if they do shady shit, then company B will be more likely to do shady shit in reality.
If you told me my options were between LastPass and 1Password, I would rather use a physical pen & paper than LastPass, but I would at least be able to live with 1Password.
CorrectHorseBatteryStaple will fail for a lot of sites. It doesn't have special characters, it's too long, it doesn't have numbers, it contains dictionary words, etc.
And you still have to remember the unique phrase you chose for each site. If you have a couple dozen logins, can you remember 24 different phrases? What about when a site forces you to change your password?
So imagine you use CorrectHorse, and some site stores passwords in plain text or weakly hashed, and then the DB is compromised (if they do badly the storage, chances are the DB is also weak), and boom, a cracker has your email, password, and the name of your first pet.
But if I use KeepPass, I don't care if my password leaks from that site or the other, or if they store in plain text. That password is only used in one site.
Cause most services still require arcane rules like "must have a number, an upper and lowercase letter, and 2 symbol but not on Thursdays"
You get the benefits of people making money off this service and thus keeping up to date clients and plugins. If it becomes bad you dump your data and go somewhere else.
They also store regular copies of your vault in a backup folder. If Satan buys them and they try to lock you out, just decrypt your backups and move somewhere else.
Maybe, if someone acquires 1Password?
Having an open source and self-hsotable alternative (that also has a SaaS equivalent if you so choose) seems to be the more prudent choice.