A Note from LastPass
blog.lastpass.com
blog.lastpass.com
I did a purge a few months back and I'm down from 150 sites to about 70. It was depressing how many sites I had to email to ask them to delete my account.
That said, if you ever need something less centralized than lastpass, try KeepassX: https://www.keepassx.org/
https://github.com/keepassx/keepassx/commits/master - Last commit 3 weeks ago.
https://www.keepassx.org/news/2014/04/433 - Last alpha released in April.
http://devd.me/papers/pwdmgr-usenix14.pdf
(Note that this is a USENIX paper, which makes the "we let them publish it" comment sort of weird).
The bookmarklet attack isn't subtle; page 8 explains how they were able to set up a malicious site that could obtain Lastpass (say) Dropbox credentials.
The one caveat I have is that I do wish they open sourced. Overall I prefer that when it comes to security.
But LastPass has always responded well when issues come up.
You also have to have qualified and dedicated people regularly reading and testing the code. I'd rather LastPass hired more security experts who we could be sure were testing the code.