LastPass Password Manager—How Secure and Reliable Is It?
Launched in 2008, LastPass has become the world's leading password manager solution. It commands 21.25% of the market[1] and helps 100,000 businesses and millions of consumers manage their passwords[2].
In this review, we'll help you decide whether LastPass Password Manager is right for you. We'll explore the security measures and features LastPass offers to protect users' passwords and personal information.
This guide will also introduce you to virtual cards and how they can help protect your financial information during online transactions.
Disclaimer: Information in this guide is accurate as of September 2024. Visit the official LastPass website or contact support for the most recent information.
An Overview of LastPass' Security and Features
To show you LastPass' capabilities, we'll examine four key areas:
- Security measures
- Password management features
- Device compatibility and customer support
- Plans and pricing
Security Measures
LastPass encrypts passwords and other information users store it it with AES-256 encryption[3]. The password manager derives the encryption key from the user's master password and uses hashing and salting to make it harder for hackers to decrypt[3]. LastPass follows the zero-knowledge principle that prevents it from viewing data stored in the vault—the encryption occurs on the user's device, and LastPass doesn't have access to the encryption key[3].
LastPass enhances password security further with the following measures:
- Passwordless login[4]—LastPass allows users to log in using biometrics, security keys, and its Authenticator app, increasing account access security.
- Two-factor authentication[5]—LastPass requires a second form of user identification, such as one-time passcodes, SMS codes, biometric authentication, or push notifications from the Authenticator app to access the password vault.
- Security audits[6]—LastPass undergoes regular security audits to maintain system integrity and security and address identified vulnerabilities.
- Bug bounty program[6]—To enhance the security of its system, LastPass incentivizes users to submit system bugs and vulnerabilities.
Password Management Features
LastPass simplifies password management by generating unique, complex passwords that combine uppercase and lowercase letters, numbers, and symbols[7]. With the save and autofill functionality, users don't have to remember or enter their passwords manually[5]. This makes using a unique and strong password for every account easier.
Other features LastPass users enjoy include:
- Password sharing[5]—Enables users to share passwords secured by end-to-end encryption
- Secure notes[5]—Allows users to store other sensitive information, like bank accounts, credit card info, WiFi passwords, and passport numbers
- Emergency access[8]—Enables users to authorize a trusted contact to access their vault in an emergency
- Folders and subfolders[9]—Helps users organize their passwords better for easier access and management
- Security Dashboard[10]—Allows users to see weak or reused passwords and get alerts on compromised accounts to take immediate action
- Password import/export[11][12]—Allows users to easily import or export passwords from other password managers or browsers
- Digital wallet[13]—Stores payment information securely, allowing users to transact online with ease and without revealing their actual payment details
- Two-factor authentication (2FA)[14][15]—Allows 2FA on stored credentials via its Authenticator app for individual users and generates time-based one-time password (TOTP) codes for teams and businesses
- Clipboard clearing[16]—Removes copied passwords from the clipboard to protect against clipboard hijacking attacks
Users who want support for passkeys (a modern, more secure replacement for passwords) can consider alternatives like 1Password, NordPass, RoboForm, and Keeper.
Device Compatibility and Customer Support
LastPass is compatible with major browsers, desktops, and mobile operating systems[5], allowing users to access and secure sensitive data consistently across all their devices:
To help users troubleshoot issues and enjoy a smooth experience, LastPass offers web support, as well as[17]:
- Support articles—Offer extensive and detailed instructions on how to use LastPass and troubleshoot common issues
- Phone support—Enables users with Personal and Business subscriptions to contact support for urgent issues
- Community forum—Allows users to post questions, get help, share tips, and discuss LastPass with other users
- Chatbot—Offers real-time assistance and answers to common queries, including login issues and account recovery
Plans and Pricing
LastPass offers five different plans[18] catering to the needs of single users, families, and businesses. Its free plan provides access to valuable features such as a security dashboard, and dark web monitoring. However, it limits users' ability to store notes, share items, and access the password manager on multiple types of devices.
Users who want access to all the features can get the Premium plan at $3/month. The Family plan, billed at $4/month, includes all premium features plus:
- Unlimited password sharing for up to 6 users
- Family manager dashboard
- Item grouping and sharing
For teams and businesses, LastPass offers the Teams plan at $4 per user per month and the Business plan at $7 per user per month, both billed annually.
Password Managers like Proton Pass and Bitwarden offer free plans that don't limit the number of devices you can use them on. Users looking for solutions that allow full access to features free of charge can try Norton Password Manager and Microsoft Authenticator.
Implement Additional Safeguards Against Online Threats
Password managers like LastPass offer convenience by securely storing and autofilling passwords and payment card details when transacting online. However, when it comes to protecting your financial information, LastPass' protection only extends to data stored in it.
Once you provide your payment card information to a merchant during a transaction, you cannot control what happens to it—its safety will depend on the merchant's security measures. If the merchant suffers a data breach, hackers may steal your financial details.
To add an extra layer of protection when shopping online and safeguard yourself against identity theft and payment card fraud, use virtual cards. These cards come with unique numbers that you can use at checkout, shielding your actual card numbers in case of data breaches.
If you want robust security and greater control over who can bill your card and how much, choose a specialized virtual card provider like Privacy.
Privacy Cards—A Reliable Solution for Safer Online Transactions
After linking a bank account or debit card to your Privacy account, you can generate virtual cards for different online payments. Each Privacy Card comes with a unique 16-digit card number, expiration date, and security code, and you can use them like your regular cards to make online payments.
As a BBB-accredited provider with over 250,000 users, Privacy employs strict security measures to protect your information. For example, it uses the AES-256-bit encryption algorithm to encrypt all your data while in transit and at rest, which means that even if a hacker intercepts it, they can't decipher it.
Privacy protects your account access with two-factor authentication and undergoes regular third-party auditing to ensure its security safeguards are current and meet industry standards. You also receive real-time push notifications for every transaction, helping you quickly spot and act on unusual activity.
Privacy Virtual Cards—Types and Features
Privacy offers three types of virtual cards:
- Single-Use Cards—Designed for one-time use, these cards close shortly after the first transaction, making them useless to hackers who might obtain them in a data breach. They're perfect for purchases on unfamiliar websites and stores you don't intend to visit again.
- Merchant-Locked Cards—These cards "lock" to the first merchant you use them with and can't be charged by any other vendor, reducing the risk of fraud. They are ideal for recurring payments like subscriptions and for shopping on your favorite e-commerce platforms.
- Category-Locked Cards—These cards are "tied" to specific spending categories like travel, dining, and health and wellness. They make it easier to track and manage your expenses within a specified category and help protect against unauthorized transactions from merchants outside that category.
You can pause or close your card and set spending limits anytime without impacting your linked funding source. Privacy will block all charge attempts on a paused or closed card and decline transactions that exceed the set limit, which helps protect you against accidental double billing and price hikes you weren't notified about.
Additional Convenience Features
Privacy also makes your online payments more convenient with these features:
- 1Password integration—This integration allows you to manage your passwords and Privacy Cards within 1Password's browser extension.
- Mobile app—Available for iOS and Android, the Privacy App lets you generate and manage virtual cards from your smartphone, giving you total control over your finances wherever you are.
- Browser extension—The Privacy Browser Extension, available for Safari, Firefox, Chrome, Edge, or Safari for iOS, autofills your virtual card information during online transactions.
- Shared Cards—You can securely share virtual cards with family or friends while maintaining control over spending settings.
- Card Notes—Privacy lets you attach notes to your Privacy Cards, helping you remember the next charge date for your subscription.
How To Join Privacy
To join Privacy and obtain your virtual cards, follow these four steps:
- Register on the official website
- Complete the KYC process to verify your identity
- Link your debit card or bank account to fund your Privacy account
- Request your first virtual card
Privacy offers four monthly plans:
References
[1] LastPass. https://www.statista.com/statistics/1331322/password-management-market-share/, sourced September 6, 2024
[2] LastPass. https://www.lastpass.com/company/newsroom/b948ad48-3268-4c9e-8b45-0d6d02d0b4e7#:~:text=LastPass%20is%20a%20leader%20in,accessible%20across%20virtually%20any%20device., sourced September 6, 2024
[3] LastPass. https://www.lastpass.com/security/zero-knowledge-security, sourced September 6, 2024
[4] LastPass. https://www.lastpass.com/features/passwordless-authentication, sourced September 6, 2024
[5] LastPass. https://www.lastpass.com/password-manager, sourced September 6, 2024
[6] LastPass. https://www.lastpass.com/security, sourced September 6, 2024
[7] LastPass. https://www.lastpass.com/features/password-generator, sourced September 6, 2024
[8] LastPass. https://www.lastpass.com/features/emergency-access, sourced September 6, 2024
[9] LastPass. https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/Organize_Your_Vault_with_Folders.html&_LANG=enus, sourced September 6, 2024
[10] LastPass. https://www.lastpass.com/features/security-dashboard, sourced September 6, 2024
[11] LastPass. https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/import-passwords.html&_LANG=enus, sourced September 6, 2024
[12] LastPass. https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/export-vault.html&_LANG=enus, sourced September 6, 2024
[13] LastPass. https://www.lastpass.com/solutions/digital-wallet, sourced September 6, 2024
[14] LastPass. https://www.lastpass.com/solutions/authentication/two-factor-authentication, sourced September 6, 2024
[15] LastPass. https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/create-totp-vault.html&_LANG=enus, sourced September 6, 2024
[16] LastPass. https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/use_the_user_account_menu_in_the_lastpass_for_windows_desktop_application.html&_LANG=enus, sourced September 6, 2024
[17] LastPass. https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/contact-support-offerings.html&_LANG=enus, sourced September 6, 2024
[18] LastPass. https://www.lastpass.com/pricing, sourced September 6, 2024