LastPass
By LastPass
LastPass is a password manager that stores login credentials in an encrypted vault and autofills them across browsers and devices, offered in both consumer and business tiers, and known both for early popularity in the category and for…
Definition
LastPass is a password manager that stores login credentials in an encrypted vault and autofills them across browsers and devices, offered in both consumer and business tiers, and known both for early popularity in the category and for past security incidents affecting user trust. Its basic mechanics mirror other password managers, a browser extension, a master password, and a generator for creating unique credentials per site, but its market position today is shaped as much by its security history as by its feature set.
Overview
LastPass functions similarly to other password managers: a browser extension and mobile app capture and autofill login credentials, a master password unlocks the encrypted vault, and a password generator helps users create stronger, unique passwords for each account rather than reusing one across services. It was among the earliest widely adopted password managers and built a large user base through free browser extension distribution before shifting toward a more subscription-centric model over time. Its early free browser extension helped normalize password managers for a mainstream audience well before many competitors existed, which is part of why it still carries brand recognition among users who may not be aware of, or may have forgotten, its later security incidents. LastPass suffered a series of publicized security incidents, most notably a 2022 breach in which attackers accessed encrypted customer vault backups along with some unencrypted metadata, following an earlier related breach of a developer's credentials. While the vault contents themselves were encrypted and would require cracking a user's master password to be read, the incident drew significant scrutiny of LastPass's security architecture and incident response, and it remains a frequently cited case study in discussions of password manager security postures. The 2022 breach specifically involved attackers using credentials stolen from a compromised employee's system to later access cloud storage containing encrypted customer vault backups, illustrating that even a product built around strong encryption can still be affected by a failure elsewhere in its own operational security. In the years since, LastPass has stated it strengthened its security practices and encryption defaults, and it continues to offer free, premium, and business tiers with features like shared folders, dark web monitoring, and single sign-on integration for organizations. It competes with 1Password, Bitwarden, and Dashlane, all of which gained users partly as a result of the trust impact from LastPass's breaches. Competing vendors' marketing has leaned on this history since, often contrasting their own specific architectural details, such as whether an additional secret key is required beyond the master password, against what became publicly known about LastPass's setup at the time of its incidents. Organizations and individuals evaluating LastPass today weigh its long track record and broad feature set against the reputational impact of its past incidents, and security-conscious buyers often research a vendor's specific architecture, such as whether it enforces zero-knowledge encryption, rather than assuming category membership alone implies equivalent security across providers. In practice, many organizations that stayed with LastPass did so after reviewing the company's subsequent security changes and its explanation of exactly what data was and was not exposed, rather than switching reflexively, since migrating an entire organization's stored credentials to a new vendor is itself a nontrivial undertaking. A prospective buyer evaluating LastPass today is generally advised to look past category membership alone and specifically compare its current encryption architecture, incident history, and transparency practices against alternatives like 1Password or Bitwarden before deciding, rather than assuming all products in the category carry equivalent risk.
Key Features
- Browser extension and mobile app for capturing and autofilling logins
- Master password protecting an encrypted credential vault
- Password generator for creating unique, strong passwords
- Free, premium, and business subscription tiers
- Shared folders for team credential access in business plans
- Dark web monitoring alerts for compromised credentials
- Single sign-on integration for enterprise deployments
- Long operating history as one of the earliest mainstream password managers