As somebody that has been using lastpass for many years and continues to do so… I just do not understand how people who pick weak master passwords complain about this.
The lastpass documentation makes clear over and over that your entire DB can be compromised but as long as they don’t have the master password, you are safe. How people do not think one step past this and realize they need a very secure master password is beyond me.
And yes I know there will be a host of comments telling me they are in the password business so they need better something and guides and whatever, fine. But for anybody with the slightest bit of common sense, lastpass was and still is secure and lived up to their promise.