LastPass
Password manager with a rough history of security breaches
What it does
LastPass is a password manager: encrypted vault, autofill, browser extensions, mobile apps, shared folders for teams, breach monitoring, dark web scans. Once the market leader; still functional in 2026 but reputation permanently damaged by the 2022 breach where encrypted vault data was exfiltrated. Owned by GoTo (formerly LogMeIn).
Free tier
Yes
Starts at
$3/mo
Setup
easy
Key features
Integrates with
Chrome, Firefox, Safari
Who this fits
- Existing LastPass customers who have not migrated yet and want continuity (though migration is Otto's default recommendation)
- Users whose organization mandates LastPass through a contract that has not renewed
- Nobody starting fresh in 2026
Who it does NOT fit
- New customers evaluating password managers in 2026. Recommend Bitwarden (free, open source) or 1Password (paid, refined UX) instead
- Any team where security posture matters (LastPass's 2022 breach exfiltrated encrypted vaults; users with weak master passwords remain at risk)
- Cost-sensitive users (free tier was crippled in 2021, then never recovered credibility)
Pricing
Real gotchas
- August 2022 breach: attackers exfiltrated encrypted customer vault backups. URLs stored in vaults were unencrypted; passwords, notes, and form fills were encrypted but subject to offline brute-force attack. Users with strong master passwords (14+ chars, PBKDF2 iterations at 100k+) are likely safe; users with weak master passwords or older accounts with low iteration counts are at ongoing risk [source: blog.lastpass.com/2022/12/notice-of-recent-security-incident].
- The company was accused of downplaying the breach severity for weeks before full disclosure, further damaging trust.
- LastPass's PBKDF2 iteration count default was upgraded to 600,000 after the breach, but older accounts remained on lower iteration counts unless users manually upgraded. Many did not.
- Free tier restriction to a single device type (2021 change) makes it useless for most people (you cannot use it on your phone AND your laptop on free).
- Migration away is easy: LastPass has a Chrome extension export, and Bitwarden and 1Password have native LastPass importers.
Integrations that matter
Otto’s take on this tool
Do NOT recommend LastPass to new customers. Recommend Bitwarden (free, open source, better free tier, no breach history) or 1Password (paid, refined UI, strong for teams) instead. If a client is currently on LastPass, recommend migration to Bitwarden with the note about master-password strength and iteration counts. Explain the 2022 breach honestly if asked. This brief exists for coverage; it should almost never be a positive recommendation.
Affiliate disclosure: if you sign up through the link above, Ottomately may earn a referral commission at no cost to you. We only feature tools we have actually used or vetted through our recommendation engine.
More in Productivity
Not Sure LastPass is Right?
Otto can pick for you.
30 seconds, one form, get a personalized stack with pricing and integration paths.
Get my recommendations