I do not understand LastPass's design; the shared authenticator/decrypting key, the website with HTML form fields for my master password, the public key crypto in Javascript with JSBN. Also, Steve Thomas doesn't like them, and found a vulnerability in their client/server protocol a while back.
I recommend 1Password, if you can use it.
https://discussions.agilebits.com/discussion/38180/vault-1pa...
For my taste that's already too much unencrypted info being synced over Dropbox etc, an attacker can easily see on which sites I have accounts.
I manage a Last Pass Enterprise instance at work. I love/hate it. The interface is terrible and buggy. However, it's the only tool I've found to manage passwords across many users (some medium to non-technical) who need access to shared accounts within an organization. 1Password doesn't really do this, and sharing vaults over Dropbox doesn't really cut it. Despite all the bug pain, it's so much better than what we were doing before, sharing passwords via email and other embarrassing methods.
How can there really only be one company doing what LastPass Enterprise does? There must be other systems that I just can't find in my research. Any recommendations for other managed password stores for organizations?
Some features that are useful: client-side crypto (key is derived from username/password, ALL data is encrypted by default), sharing between accounts via asym encryption, open source client & server means it could be run completely in-house if required (as opposed to using the hosted service).
It doesn't have mobile apps right now, but those are coming pretty quick (either end of June or in July).
One of our slated features is a password note type, and possibly eventual integration with browsers.
Might be worth a look. Like I said, Turtl is new and is missing a lot of features you'd want in a pure-password-manager solution, but it has the potential to grow into this space a lot due to its security, sharing, and hosting features.
1Password seems much more consumer friendly. Annoyed at bugs and crappier interface. 1Password also recently started integrating with some apps which I found particularly useful.
It also has options for using DropBox or iCloud, so if you do sync in the cloud, it's still your own account on a different service. So there's not a single point-of-attack like there apparently is with LastPass.
For company wide use, LastPass Enterprise is a better fit. Centralized management is essential when dealing with larger numbers of not particularly tech savvy and security conscious users.
And despite this incident, I trust a specialized operation like Lastpass more with keeping the data secure 24/7 than myself or company IT.