As technology evolves, it is important to consider the safety and security of our services. LastPass, the popular password manager, is an essential tool for anyone looking to keep their online accounts secure. While LastPass has a long history of providing secure password storage and management, it is still important to ask, is LastPass still safe to use in 2023?
With the rise of cyber threats, especially after the infamous attack that happened a while back on LastPass manager, it is more important than ever to ensure that the services we use are secure and up-to-date. LastPass has made a number of improvements to its security protocols throughout the years, making it one of the most secure password managers available. During the year 2022, it was nominated as the best password manager tool available. With updated encryption and two-factor authentication, LastPass provides a robust security system. But unfortunately, during November 2022, LastPass suffered some significant consequences after an attack that targeted its clients. People wonder if it will continue to be number one as it was a few months ago.
What happened? – a recap
It suffered two connected data breaches that compromised confidential customer information during August and November. The August breach saw a malicious actor steal source code and technical information from LastPass’ development environment that was then used to target an employee. This allowed the hacker to access credentials and keys, which they then used to access LastPass’ third-party cloud storage service in November 2022. Due to these actions, customers’ password vault information, including website usernames, passwords, secure notes, and form-filled data, was exposed. This series of events resulted in many customers backing down from LastPass and turning towards other similar alternatives.
LastPass security features overview
As we mentioned above, LastPass is a password manager that helps users store their passwords and other sensitive information in a secure virtual vault. It allows users to store, manage, and share their data with ease and convenience. It also offers a variety of security features to ensure that users’ data remains safe and secure. One of the most important security features of LastPass is its two-factor authentication. This feature requires users to input two forms of identification to access their accounts. For example, users may be asked to enter a PIN code, or they may be asked to authenticate their identity by providing a fingerprint or face scan. This two-step process helps ensure that the right person is accessing the account.
Another security feature of LastPass is its encryption technology. All data stored in the LastPass vault is encrypted using a 256-bit encryption system. This ensures that only authorized users can access the data. Additionally, it also uses secure socket layer (SSL) technology to protect user data as it is transferred over the internet. LastPass also offers advanced security features such as password sharing and breach alerts. This allows users to share their passwords with others without compromising security. In addition, LastPass also sends out notifications when a breach is detected (given the attack example that happened in November), allowing users to take action to protect their data immediately. But is it still safe to use even after all these security features and enhancements?
Is LastPass still safe to use?
This matter has become a very opinionated topic worldwide, where the answers differ from one to another. A correct answer will be to switch to similar alternatives if it doesn’t make you feel safe. When searching for other options, it is recommended that you always check the history of the tool and if it has any history of cyber attacks and breaches.
Regarding the security features of LastPass itself, it is still an excellent alternative to choose from if we are measuring the cost and benefits ratio against each other. As we said, LastPass utilizes military-grade AES-256-bit encryption to guard its secure vault, and the only way the vault can be unlocked is with the master password.
Per the privacy policy, they get data already encrypted on the local device, and what is sent to their servers is merely encrypted pieces of information. Moreover, their developers cannot decrypt it due to the extra hashing algorithm, which concludes that whatever is stored in LastPass should be secure from outside incursions. Still, some sources suggest that the encryption could be reasonably easy to break. At the end of the day, it all depends on whether it makes you feel comfortable using this password manager or not.