18 ms·
LogMeIn acquires Lastpass
- james-skemp 11y agoFirst comment on the blog so far: 'Oh no.' My first reaction was to chuckle. I wonder how LastPass will change given the new ownership. We switched over to this at work almost a year ago, after trying to determine a password management strategy for years, and it's worked fairly well, although it hasn't sold me on switching from Keepass for personal use. I'll be interested in what the Hacker News community thinks about this.
- tmarman 11y agoAs a former Hamachi user and LastPass user/advocate, I had the exact same reaction when I saw this.
- bluedino 11y agoI cringed when we got this email since we use LogMeIn Pro at work. For everyone else, I hope they don't butcher the free version like they did with LogMeIn.
- gtk40 11y agoAs someone who has never used LogMeIn, could you explain what the problems are? I use LastPass pretty extensively (and was thinking of buying a subscription later this month), but have never used LogMeIn.
- winsome 11y agoLogMeIn used to have a free product that they then took to Premium only. I used to use them extensively until then. Now they also seem to be notorious for price hikes, although I have no first-hand experience. I'm a LastPass Premium subscriber and have enjoyed using it, but I'm worried about what the future holds now.
- bluedino 11y agoMy beef with them was when we quit using the 'Pro' product. We were using a feature that let us do software updates and scripting, which was kind of pointless when we could do those things with Windows server or other solutions. We then went down to the 'Central' version of LogMeIn, as it still provided remote access capabilities (which was all we wanted) and were able to save a bit of money. Well, two months later they billed us the full renewal price of the old product ($2499) and it took us 6 months of back and forth with them to refund that.
- ciaranm 11y agoWonder if now is the time to look at alternatives, before the service potentially changes. I hear a lot of good things about 1Password, which seems to work for my iPhone/MacBook. Anyone know if there's a reasonable option for using it on Windows?
- ghshephard 11y agoI chose 1Password because it works seamlessly across iPhone/MacBook/Windows. https://agilebits.com/onepassword/windows https://agilebits.com/onepassword/windows
- baldfat 11y agoLinux?
- sarahprobono 11y agoUnfortunately not. https://discussions.agilebits.com/discussion/2846/new-product-request-1password-for-linux https://discussions.agilebits.com/discussion/2846/new-produc...
- resurge 11y agoThey have browser extensions, so you can use it through that way on Linux it seems. https://agilebits.com/onepassword/extensions/ https://agilebits.com/onepassword/extensions/
- kieranajp 11y ago
- mpclark 11y agoThese acquisition announcements are always the same, and always get the same sort of comments. They tell of good fortune for the owners of the thing that has been sold, but never tell the users what's in it for them. And that's usually because there is nothing in it for them. What am I supposed to be happy about?
- IgorPartola 11y agoI can't exactly agree with you. First, lots of acquisitions are good for the user because they often mean backing by a larger entity with deeper pockets, ensuring that the service you use will be around for longer. Second, why do they owe you anything? Either you are a free user, at which point you don't really have a whole lot of say in what they do with their own company, or you are paying $12 for a stellar password manager, which I would say is definitely worth it. I am not exactly a fan of LogMeIn, and I do really like LastPass and use it every day, but if they chose to sell their company and cash out, good for them. If the service somehow becomes bad, I will move onto one of many alternatives, though this time probably an open source one.
- aylons 11y ago> Second, why do they owe you anything? Either you are a free user, at which point you don't really have a whole lot of say in what they do with their own company, or you are paying $12 for a stellar password manager, which I would say is definitely worth it. Because I not only paid US$12,00 to them, but I have also invested time and thought in building habits and procedures based on their service. If they their service becomes unworthy or cumbersome, or if I have any reason to distrust them, I'll have to look elsewhere, not only costing me time, but also giving me uncertainty and possibly having to choose a new service. And, if I have chosen Lastpass, is because I believe other services are not worth as much.
- IgorPartola 11y agoOK, but why do they owe you anything for the time you chose to spend with their product? In fact by repeatedly using their product you subtract from their bottom line since you are consuming computing and support resources. As far as I see it, $12 buys you a one year LastPass subscription, not a perpetual right to be consulted on any corporate moves they might make. Practically, you probably have a bit more say than a free user would about the product features, but not nearly as much as one of their team members. In short, while this change to LastPass might not be good for you (or me) in the long run, I don't see why they'd have any responsibility to consult you or me about whether to sell to LogMeIn. We are customers, not shareholders.
- colinplamondon 11y agoThis really rubs me the wrong way. Do not like the idea of my password manager bouncing around owners. Or infrastructure changes that new owners often push on the acquired company. If there's one business I REALLY do not want to be moving about, and I want as little churn as possible for, it's a password manager. The thing I liked about LastPass was that it seemed like the highly geeky, less startupy approach to password managers, more likely to be run for the long-term, less likely to be at risk of an acquisition. Going to look into Dashlane.
- coldpie 11y agoSo, use an open source one.
- baldfat 11y agoWhat Open Source one was a convenient or as feature complete? Serious I love LastPass and I use it for everything BUT my banking. I just install the plugin on any device or open the webpage and I am all set with all my passwords.
- coldpie 11y agoI don't know what features you like or find important. But you have to consider the licensing model as a feature when choosing your software. What happens if the software is sold or no longer maintained? For me, I use a plaintext file in a Truecrypt archive because I'm a massive dweeb.
- yoshamano 11y agoMy first reaction to reading the title was "why?" After reading the article (and then reading it again) I'm not left feeling confident that this is in any way positive for me as a LastPass Premium and Xmarks customer. In particular the vague line about, "As we become part of the LogMeIn family over the next several months, we’ll be releasing updates to LastPass, introducing new features..." To me, LastPass is feature complete. So either I'm going to have a mind blowing, I never knew I needed that, moment, or more likely some sort of bloated crap is going to get shoe horned into LastPass.
- degenerate 11y agoLogMeIn purchased, and absolutely ruined, Hamachi back in 2006. That program was the perfect lightweight virtual LAN client in existence with all the necessary features. Within months of acquisition, Hamachi had several "updates" and became bloated beyond recognition, slow, buggy, and downright unreliable. I have the worst taste in my mouth from what LogMeIn did to a perfectly working product and won't use anything they offer because of it.
- donatj 11y agoI forgot about Hamachi! I used to love that back in college, and you are right, they destroyed it. Salted the earth.
- cryoshon 11y agoYeah, they really ruined Hamachi. There isn't really a suitable replacement even now, to the best of my knowledge. I still resent them for that. I hope they don't ruin LastPass also, but from here on out I'll be intensely skeptical.
- api 11y agoSuitable (and open source) replacement: https://github.com/zerotier/ZeroTierOne https://github.com/zerotier/ZeroTierOne https://www.zerotier.com/ https://www.zerotier.com/ Also does a lot of other things, and is evolving into a full-fledged SDN layer. If you don't want to use the pretty GUI they give you to create/manage networks you can run your own 'network controller' -- see READMEs in GitHub.
- klausjensen 11y agoAre there any real alternatives to Lastpass, that has working browser plugins and also work on Android devices?
- deleted 11y ago[deleted]
- vmuhonen 11y agoOne option I've been meaning to look, but haven't had a reason to because of LastPass is Encryptr [https://encryptr.org/ https://encryptr.org/], but now I might need to. They have Android and Linux support, but not browser plugin I think. Also, it comes from the same people as SpiderOak...
- wscott 11y agoEncryptr is interesting and looks very nice. Includes source: https://github.com/devgeeks/Encryptr https://github.com/devgeeks/Encryptr But it doesn't appear to have anything like Lasspass's autofill on android that supports the fingerprint reader.
- flurpitude 11y agoSo you'll be using the clipboard to copy and paste passwords on Android, which is (I believe) much less secure.
- subliminalzen 11y agoRoboform works everywhere: http://roboform.com http://roboform.com
- nullsocket 11y agoQueue REM: https://youtu.be/Z0GFRcFm-aY https://youtu.be/Z0GFRcFm-aY
- eigenvalue 11y agoThis actually sounds like a smart deal for LogMeIn. Purchase price is $110mm of cash with a $15mm earn-out-- seems reasonable considering LastPass has millions of users and is a pretty sticky service (I've been a premium user for the last couple of years, mostly to be able to use their iPhone app).
- ilogik 11y agohad million of users judging by the announcement comments
- bketelsen 11y agoThere are times when it might be better to disable comments on your corporate blog. This was one of those times.
- krupan 11y agoEncryptr is an alternative that I've had my eye on: https://encryptr.org/ https://encryptr.org/ They don't plan to ever do auto-fill for security reasons, which I'll admit disappoints me.
- m1keil 11y agoI was curious about Encryptr as well. I hope the maintainer will change to less purist approach and understand that for most of us, copy/paste of login details is just no-go.
- Tinyyy 11y agoHonestly if you're a security / privacy company, can you please just not get acquired? You can't 'transfer' your customers' trust to a third party like you transfer cash.
- lewisl9029 11y agoAgreed. Or just open source it so we won't have to trust you.
- gherkin0 11y agoUsing open source and not having to trust someone would be nice, but at a certain point I would rather not be running my own security-critical infrastructure for personal stuff (if I can avoid it). I only have so much time.
- perlgeek 11y agoAs long as it's a hosted service, you still need to trust the one who runs it.
- hu_me 11y agologmein has almost ruined my current favorite password manager Meldium. After they acquired it the service has become gradually to the point it does not work on half the sites stored in it. This week I finally decided to start migrating to LastPass (a few clients use it and it appeared a more dependable alternate). Guess will continue my search for alternates.
- deleted 11y ago[deleted]
- AdmiralAsshat 11y agoAssuming your passwords are in a "stable" state (i.e. you're not constantly adding new logins to your vault), it would probably be a good idea at this point to make a backup of LastPass's database via the Export feature and hold onto that backup. I know I'm on the paranoid end, but I have this sneaking suspicion that the Export feature might "disappear" in the coming months to try to curtail a mass exodus of users.
- secabeen 11y agoI think that's unlikely, given how they handled the expiration of the Free LogMeIn accounts.
- AdmiralAsshat 11y agoHow were they handled? I didn't have one.
- krupan 11y agoEncryptr is an alternative that I've had my eye on: https://encryptr.org/ https://encryptr.org/ They don't plan to ever do auto-fill for security reasons, which I'll admit disappoints me.
- brento 11y agoOne of the reasons I chose 1Password over LastPass is because you can choose where to store your data (iCloud, Folder on your System, Dropbox). I don't think you should trust your passwords to any company.
- AdmiralAsshat 11y agosigh And I literally just migrated all of my stuff from KeePass to LastPass like two weeks ago. Back to the drawing board, I suppose.
- baldfat 11y agoLinux User - I am looking at Keeper https://keepersecurity.com https://keepersecurity.com My devices - Linux Desktop, Laptop, Windows 7, 8 and 10 Machines at work, Android Phone, iPad (Work) Lastpass worked on all of them. The only alternative I could find was Keeper https://keepersecurity.com https://keepersecurity.com that worked with all of my devices. Anyone have experience with Keeper Security?
- buro9 11y agoLikewise, I'm similarly cross-platform and just found http://enpass.io/ http://enpass.io/ Wondered if people have experience with them.
- thehoff 11y agoAm I blind? Where is the pricing for Enpass? It says free download free updates but then in middle it says pay once use forever.
- buro9 11y agoYou're not blind, I can't find it either. And I've already got spider sense tingles about them... lack of SSL cert for a security company? No pricing info? No "About Company"?
- baldfat 11y ago*Free version can store upto 20 items only. Price for Life-time Pro ver is $9.99 per platform with no other server or subscription charges. http://enpass.io/apps/android/ http://enpass.io/apps/android/ So for me that is $20 for iPad and Android BUT my iPad is a company product that is likely to switch on me shorty with an upgrade. So this might not work if it is $20 per platform per personal and business use.
- krupan 11y agoEncryptr is an alternative that I've had my eye on: https://encryptr.org/ https://encryptr.org/ They don't plan to ever do auto-fill for security reasons, which I'll admit disappoints me.
- onwardly 11y agoPrice was $110M + $15M in contingency payments. From the LogMeIn investor release[1] Under the terms of the transaction, LogMeIn will pay $110 million in cash upon close for all outstanding equity interests in LastPass, with up to an additional $15 million in cash payable in contingent payments which are expected to be paid to equity holders and key employees of LastPass upon the achievement of certain milestone and retention targets over the two-year period following the closing of the transaction. 1. (https://investor.logmeininc.com/about-us/investors/news/press-release-details/2015/LogMeIn-to-Acquire-Password-Management-Leader-LastPass/default.aspx_ https://investor.logmeininc.com/about-us/investors/news/pres...
- flipp3r 11y agoYou have some extra characters at the end of your link https://investor.logmeininc.com/about-us/investors/news/press-release-details/2015/LogMeIn-to-Acquire-Password-Management-Leader-LastPass/default.aspx https://investor.logmeininc.com/about-us/investors/news/pres...
- onwardly 11y agoPrice was $110M + $15M in contingency payments. From the LogMeIn investor release[1] Under the terms of the transaction, LogMeIn will pay $110 million in cash upon close for all outstanding equity interests in LastPass, with up to an additional $15 million in cash payable in contingent payments which are expected to be paid to equity holders and key employees of LastPass upon the achievement of certain milestone and retention targets over the two-year period following the closing of the transaction. 1. https://investor.logmeininc.com/about-us/investors/news/press-release-details/2015/LogMeIn-to-Acquire-Password-Management-Leader-LastPass/default.aspx https://investor.logmeininc.com/about-us/investors/news/pres...
- AdmiralAsshat 11y agoThat's funny. The LogMeIn employees have a financial stake in making sure that people DON'T exit en masse after the acquisition. I wonder why? I would caution, then, that any interviews given by any staffer to the effect of "LastPass is not changing, your data is perfectly safe with LogMeIn, the prices will not skyrocket, etc." over the next few months should be taken with a grain of salt, since they quite literally have $15 million riding on you not leaving.
- corin_ 11y agoAs opposed to any other acquisition (excl. acquihires) where the company doesn't have any incentive to keep customers at all and therefore everything they say must be completely true?
- enjo 11y agoThat's a whole lot to infer from that. Holding a significant portion of the sale in escrow pending retention, legal requirements, and other issues is pretty standard practice.
- bargl 11y agoWell looks like I'm going to have to convince, my wife, family, extended family, and friends that they all have to switch password managers now. I'm blown away, I've been a fan since day one because of it's simplicity and availability. I am torn between waiting to see what happens and giving them the benefit of the doubt and just changing all my passwords before Logmein can f--- me.
- Justsignedup 11y agoWell, export your data ASAP. At least if shit happens you won't lose it all. Would be funny if LMI spent 120MM just to have a product everyone leaves. lol.
- DiabloD3 11y agoI don't know why this guy is being downvoted. I, too, am now looking for a new password manager. All I need one is that does local decrypting only, supports Chrome and Firefox, and can do Android as well.
- JoeAltmaier 11y agoUnnecessary negativity; against the HN standards.
- bargl 11y agoBe civil. Don't say things you wouldn't say in a face-to-face conversation. Avoid gratuitous negativity. gratuitous- uncalled for; lacking good reason; unwarranted. I feel that my comment falls into what I consider a fair statement about the severity of the situation. They have my passwords and could easily hike up their rates. This change may add features I didn't know I wanted, but thus far I'm happy with the way LastPass has been operating and I don't want a change.
- JoeAltmaier 11y agoThis comment meets the standard. Negativity without any explanation was the issue. Thanks for clarifying.
- rocky1138 11y agoPlease don't fuck it up.
- pgrote 11y agoI have used LastPass Premium since they started. What gets me down about this is the trust I had for the service LastPass provided. I appreciated their open and pre-emptive communication. They were willing to dive into the details of a possible issue and explain everything about it.
- HackyGeeky 11y agoCongrats to LastPass team for a successful exit :) I understand why the users might have concerns with "LogMeIn", but well one should've expected (at least on this forum) that this is going to happen. I know this isn't the most popular comment. But, what the heck, be happy for the LastPass team, they've worked their ass off. That's what this forum is for, isn't it ? We(hackers) are all in the same boat.
- criddell 11y agoI don't think anybody is unhappy for the LastPass team. Many of us use LastPass though and so we are nervous about the future of something we trust and use. I don't trust LogMeIn like I trusted LastPass and so now I have to contemplate finding a new solution to a problem that I thought was solved. So hooray to the LastPass team and condolences to the LastPass customers.
- jscheel 11y agoI had to find out about this from HN. Never got an email, even being a premium member.
- paulgb 11y agoYeah, I can understand the press release being first because LogMeIn is publically traded, but the delay is weird. I just got an email from LastPass now (as a premium member).
- jlgaddis 11y agoI got two of them, one at 1322 UTC and the other at 1454 UTC (two Premium accounts).
- jecxjo 11y agoI got an email, and then saw this post on HN...and then backed up and deleted my account. Wasn't going to renew anyways, just happened to be perfect timing.
- ejcx 11y agoCongrats to Bob and Joe and LastPass team. I'm a former LastPass employee and will be forever empresses by their work ethicc that I saw. They definitely deserve it.
- ntrepid8 11y agoThis is pretty terrible news. It would have been need to see LastPass get acquired by a company like AWS but LogMeIn doesn't really have the reputation required to ask people to trust them with all their passwords. Also, the valuation also seems low to me. Maybe LastPass was having trouble generating recurring revenue. It seems like going public would be a better route for security companies but maybe the revenue wasn't there for an IPO. I've had a paid subscription for years and used their enterprise service for 2 different startups. Hopefully the service doesn't start to suck. I'm already scouting alternatives.
- gautier 11y agoWe were in a similar situation a few months ago when Mitro announced that they were shutting down their service. Mitro's owner being really nice, they open-sourced the browser extensions, server and mobile applications so we used them to run our own: https://passopolis.com/ https://passopolis.com/ We plan to keep the code open-source and we're working hard at the moment to introduce the organisation feature useful for start-ups. We plan to make the organisation feature a premium service so we can justify running and improving Passopolis for as long as it stays useful.
- jsutton 11y agoLogMeIn has many years of experience securing their remote management software, something that has incredible potential for malicious activity. They seem like a good candidate for keeping LastPass secure, based on their reputation from a technical standpoint.
- fweespeech 11y agoAfter having to deal with LogMeIn for a company I used to consult for.... Yeah, I'm going to be switching password managers.
- wlesieutre 11y agoHopefully they do better with this than when they bought Hamachi. It was a great piece of easy-config VPN software, and they just ruined it. I knew a lot of people who used it regularly. Now I can't think of any.
- Justsignedup 11y ago:( Hamachi quickly went to hell. I bet they use the tech Hamachi provided but the product was scrapped afaik.
- Justsignedup 11y agoAnyone aware of good alternatives? Primarily for enterprise customers who want to share passwords between teams. We have developers, and regular ol' employees who use this of varying levels of computer comfort. We need to be able to share passwords org-wide and team-wide. And on a personal note, I need to be able to manage my own passwords and my partner's and we share from time to time.
- mmaha 11y agoDisclaimer: I work for Okta. Have you considered Okta [http://www.okta.com http://www.okta.com] for your enterprise needs?
- gallamine 11y agoI am constantly impressed and pleased with 1Passsword - both the ease of use and their constant stream of updates. My family has a shared password Vault for common passwords, and private values for non-common ones.
- wj 11y agoI believe Personal has a business plan for sharing passwords and data between teams. I haven't tried it though. https://www.personal.com/ https://www.personal.com/
- switch007 11y agoNo 2FA?
- jronald 11y agoWe're testing Hashicorp's vault - why share system passwords when you can use OTPs provided on demand? Its still early, but looks promising to me.
- fapjacks 11y agoWe started using Vault in our Docker infrastructure for storing sensitive configuration data, and I've since migrated to using Vault for a hell of a lot more. It really is a great piece of software.
- periferral 11y agoLooks like Dashlane ($40) and Sticky Password ($20) are viable alternatives. Both are more expensive than Lastpass. Reading the reviews, these seem like the best so far. Anyone with experience on either of these they can share?
- kfriede 11y agoI'm seeing Dashlane at $40 per year. That's pretty steep.
- pinkano 11y agoYep, I'm switching to Sticky Password too. According to this they offer a discount too: http://heavy.com/tech/2015/10/lastpass-alternatives-logmein-acquired-replacements-password-manager-dashlane-keepass-1password-splikity-shark-tank-encryptr-enpass/ http://heavy.com/tech/2015/10/lastpass-alternatives-logmein-...
- wscott 11y agoLastpass premium customer here. It was $12/yr. (that will probably change after the 2yr/$15M target is over) Right now lastpass encrypts in the browser and the company only saves a binary blob that they can't access. So your data is safe. But they said, "As we become part of the LogMeIn family over the next several months, we’ll be releasing updates to LastPass, introducing new features.." that makes me nervous. The comments here have lots of suggestions like keepass, but none of them really compare with the Lasspass Android support where it will automatically log you into apps.
- WorldMaker 11y agoKeePass apps are usually open source. Presumably some smart devs can contribute such Android support to an Android KeePass app.
- ninjakeyboard 11y agoEveryone seems pretty unhappy about it via the comments on the article.
- tiernano 11y agoNot sure if good or bad...
- johnward 11y agoMe either. I was a big fan of logmein when they had a free version but it wasn't something I was willing to pay for. LastPass is though.
- colinbartlett 11y agoI'd really love for some objective person to weigh in about why all the negative reaction to this. Is LogMeIn a terrible company? I have not used either LogMeIn or LastPass.
- akshatpradhan 11y agoI'm curious as well.
- Splines 11y agoIMO not all that LogMeIn is a good/bad company, it's that LastPass was sold. Their (your) data is being moved from one company to another. It's certainly possible that LogMeIn stays hands-off and LastPass continues all operations exactly as they did before, but then why would LastPass sell? LogMeIn paid $x money for LastPass, and they intend to make $x + $y money for it, by doing things that LastPass was either unable or unwilling to do (otherwise, LastPass wouldn't have sold). Usually this means that LogMeIn is going to try to "extract more value" from the customer.
- draw_down 11y agoI don't really know but I'm surprised people liked using the thing to begin with. Always struck me as junky.
- vacri 11y agoI can't speak for others, but the headline make my guts tighten. I personally experienced bad ethics from LogMeIn when trying to report those "We have detected a windows virus on a computer in your house" scammers.
- m1keil 11y agoPersonally for me, I just can't trust a none security focused enterprise, running a security focused product. I just know that priorities will slowly change from security first to some random not so secure feature. Additionally, LastPass did good job in disclosure of security incidents in the past. I'm pretty sure this won't happen now that they are tied with this big brand name which thinks that publishing security incidents is bad for its PR. Bottom line - It's a matter of trust for me, and I don't trust them.
- jonknee 11y agoSeems like a smart move for selling bulk licenses to large companies.
- xbryanx 11y agoDo LogMeIn users have a feeling as to whether this is a good thing? Will they bring any visual polish, or UX consistency to the jumble that is Last Pass?
- tudborg 11y agoPaying LastPass user here. Not sure how this is going to go down. TBH I'm hoping that nothing will change. Yes, the UX might not be the best in the world, but to me, the important thing is availability and security (probably not in that order). A browser extension and a decent android app is what I need, and I already have that.
- xbryanx 11y agoPaying LastPass (Enterprise) user here too. I hope the extension gets a complete overhaul. I've experienced dataloss multiple times due to inconsistent interface issues. Support just shrugs and points me to 3rd party backup solutions. I see the UX problems as critical, but yes...just below security.
- tekromancr 11y agoPaying LP Enterprise user also. Totally agree. I spent 45 mins today just explaining to new employees how to get everything set up. The UX something that absolutely needs work Then again, it's currently good enough that we are paying them a pretty large yearly sum, so perhaps there is no business case for spending the resources to improve it.
- switch007 11y agoAny suggestions for alternatives? I need yubikey support, Chrome & Firefox plugins (Linux & OS X) and an Android app.
- lectrick 11y agoSo you absolutely must use Yubikey for 2factor auth instead of one of the many alternatives?
- lockes5hadow 11y agoYes, unless you suggest another hardware token with NFC in the same price band (sub $100).
- deleted 11y ago[deleted]
- ejcx 11y agoCongrats to Bob and Joe and LastPass team. I'm a former LastPass employee and will be forever empressed by their work ethic that I saw. They definitely deserve it.
- quaunaut 11y agoHuh. Gotta admit, I'm rather distressed by this, but I'm trying to think through it logically. * They still don't have access to my raw passwords. Everything's already encrypted before it gets to them, and they don't have the key. They just store the encrypted data. * They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I must admit I felt a bit safer when I thought it was a smaller, purpose-built company managing things. * Then again, LastPass hasn't had the greatest user experience lately. A mixture of simply not doing the data entry on some sites, and having a poorly designed UI for mobile that feels like little more than an extension of the desktop experience(which doesn't work very smoothly on mobile- it needs to be rethought from the ground up) means that perhaps the new things LastPass could do with this funding would make it more usable. But at its core, this is a security company to me. Probably the only one I pay for directly. I love change and expansion in so many other industries, but I suppose I'm just not used to it here- perhaps that gut response of "I want my security to be utterly solid because of how bad it could be if it goes wrong". This isn't quite a reason to jump ship for me yet, but I'll certainly be duplicating work to other services(which so far, I've found to be quite inferior).
- danieldk 11y agoThis isn't quite a reason to jump ship for me yet, but I'll certainly be duplicating work to other services(which so far, I've found to be quite inferior). Did you try 1Password (which works with Dropbox, Wifi sync, etc.)? Not affiliated with them, just a happy customer.
- quaunaut 11y agoI tried it for all of a week in the past. It's the top one I'm looking at moving to, but honestly the reviews that have been done by users of both are lacking on information, so I don't know what I'm giving up.
- ge0 11y agoVery happy user of 1password here, features, UX and overall ethos of Agilebits are to be commended
- T3RMINATED 11y agoalright guys its time to switch to www.dashlane.com
- fencepost 11y agoAs a LastPass Premium customer for longer than they've owned XMarks and a combined product customer since, this concerns me. I'm not planning to change my LastPass usage until/unless they change how the product works, but I'm a bit more leery of steering customers to the Enterprise product now and will be investigating alternatives in that space. As for XMarks, I'm torn. It has nice potential, but I feel like the company has basically let it stagnate warts and all. Some seemingly-obvious features like tracking changes to saved bookmarks (diffs, not checking the content of the URL) don't exist, and the ways to get archival data out to do it yourself are clunky and manual. What made me start wanting that was a browser going funky and losing a chunk of bookmarks - I had to kind of ballpark when that was, go back, dump a backup, find them in the HTML dump backup file then recreate and I'm not certain I ended up getting them all.
- zoner 11y agohttps://passopolis.com/ https://passopolis.com/ - I'm using this (formerly known as Mitro) Open source
- forgotpwtomain 11y agoI see a bunch of lame commits like changing logos and names and no actual work on mitro -- not sure how encouraging that is, since you've already jumped at changing the name and making a company around it.
- Karunamon 11y agoPerhaps the original app was feature complete and not a lot of work needed to be done on it? It's based on a third party password management service that open sourced its code before shuttering, so this would naturally be step one in relaunching something based on that code.
- teh 11y agoI'm one of the people running passopolis. We think that Mitro was already pretty good but we've fixed several bugs, packaged it for the Chrome store, made sure the server runs reliably etc. As the FAQ explains we changed the name to avoid confusion when Googling. We're also not building a company around it, we've absorbed the work of keeping it running as our agency (wearewizards.io). If we start charging it's going to be for some actually new feature, not for the current product.
- jayonsoftware 11y agoI love Dashlane
- xbryanx 11y agoIs Dashlane "for Teams" comparable to LastPass Enterprise?
- stuffaandthings 11y agoI switched to LastPass from Dashlane recently. I do like Dashlane better, but unfortunately no linux client was a deal breaker...
- gkop 11y agoNot only do they not have a Linux client, but their web client is super limited - it won't give you the passwords that have been shared with you, for example, and you can't register an account through it (on Linux I literally had to install the iOS app on my iPhone to create an account, have my colleague add my account to the team, and then once I could finally log in to the web app, even though it showed me on my team, it wouldn't give me any team passwords).
- discreditable 11y agoJust one more reason why password management by a company is a bad idea. The company may be good now, but companies can be acquired or evaporate on short notice.
- FabianBeiner 11y agoI upgraded my account yesterday for five more years. ;-) But honestly, if everything will keep working as it is, I really don't care about the name behind it. If LastPass did as they said they do (everything is encrypted, they don't have access), it doesn't matter.
- niels_olson 11y agoXmarks goes with it, I assume?
- electricblue 11y agoI'm thinking about going with KeePass. I don't want to deal with this again with 1Password if/when they get bought.
- danieldk 11y agoI think there is an important difference between LastPass and 1Password: 1Password stores data in a folder you point it to. It is never in any form transferred to their servers.
- npongratz 11y agoAre there open source "clients" that can access the 1Password data I store locally?
- reaperhulk 11y agoThe file formats are extremely well documented https://support.1password.com/opvault-design/ https://support.1password.com/opvault-design/ and many 3rd party tools exist for reading the data.
- mrsaint 11y agoYes, there are. The storage format is "open", and afaik, the current revision is v5. See on GitHub: https://github.com/search?utf8=&q=1password https://github.com/search?utf8=&q=1password
- deleted 11y ago[deleted]
- Adaptive 11y agoFWIW, regarding the ongoing complaints about the LP UI, they just released a beta update to their chrome extension a couple days ago. Still a ways to go, but they are/have been clearly working on the end user experience. https://chrome.google.com/webstore/detail/lastpass-prebuild-free-pa/debgaelkhoipmbjnhpoblmbacnmmgbeg?utm_source=chrome-app-launcher-info-dialog https://chrome.google.com/webstore/detail/lastpass-prebuild-...
- apocalyptic0n3 11y agoThat actually seems to be quite the improvement. The vault actually seems useful now and doesn't look like a poorly built app from 2002. Thanks for sharing
- xbryanx 11y agoOh wow. Thanks for posting this. It's such an improvement.
- therealdrag0 11y agoI haven't had that much complaint about the chrome ext. What do people not like about it?
- discreditable 11y agoJust one more reason why password management by a company is a bad idea. The company may be good now, but companies can be acquired or evaporate on short notice.
- aburan28 11y agoJust wait until the inevitable data breach and there gone
- dtech 11y agoThat already happened: https://blog.lastpass.com/2015/06/lastpass-security-notice.html/ https://blog.lastpass.com/2015/06/lastpass-security-notice.h...
- rwc 11y agoSome of these tools (1Password in particular) seem geared toward individual password management. And LastPass wasn't exactly user-friendly. What are you using for group/team password management?
- gexos 11y agoI use keepassx, it will allow you to keep a local repository of all of your passwords and sensitive information encrypted and accessible to all of your team members. Commonkey is another great program and is free for teams of three.
- song 11y agoI use 1password and export some of the items when I want to share them. But it's not my main use case, so it's not a problem that it's a bit cumbersome. I didn't want to have my passwords stored on any servers from external companies. Instead I use tarsnap to backup my passwords.
- vacri 11y agoI use Passpack. The workflow is a bit janky, but it does the job. I'm not sure what other options would be good for sharing passwords with groups of employees, though.
- iscrewyou 11y agoI've been using an excel workbook that is stored in an encrypted image as my ways to manage passwords. How are these services that people mention in the comments, better at doing the same? Is there a better way someone has come up with to manage passwords where you don't have to rely on these services?
- spathi_fwiffo 11y agoMainly in the user experience, not having to deal with setting up and backing up a personal encrypted store, and the ability to access the same data from multiple machines. The cost, of course, is in the data being remote, and you generally have to trust the company and processes around their handling of your data.
- hagope 11y agoI pay for LastPass because on Android, it will automatically fill in passwords on any screen, saves a ton of time, I wouldn't want to fuss around with a spreadsheet on my phone...
- Splines 11y agoLocal keepass database, synced with $yourpreferredcloudservice. On my Android phone I use a keepass app that includes a keyboard, which integrates typing in username/password. Also supports 2fa totp, which feels to me like poking holes in the whole idea, but if you want to use it it's there.
- sundarurfriend 11y ago> Also supports 2fa totp, which feels to me like poking holes in the whole idea I'm a Keepass user and I didn't know it had support for 2fa. Why do you feel it's poking holes in the idea?
- cuu508 11y ago- they automatically fill login forms in browser. Nicer than copy/pasting things around and more secure: there's malware stealing clipboard contents, and you can also accidentally CTRL+V your password in chat window ;-) - Excel has larger attack surface than purpose-built password managers. Have you checked Excel doesn't leave behind recovery copies of your passwords file in c:\windows\temp ?
- lectrick 11y agoWhew, I was on the fence between this and 1Password after Mitro shut down, just a couple days ago... Glad I went with 1Password LOL
- MrGando 11y agoBeen using 1Password for years now... those guys are super committed to their software, I really like their product.
- saddestcatever 11y agoI've been a serious 1Password user for ~3 years. Love it. Mac OSX app, and Chrome plugin are amazing. It's a little pricey, but I think it's worth it. However - don't think about using 1Password if you're on a windows machine - their windows app is really janky and works just enough to be usable
- lectrick 11y agoJust for the sake of multiplatformability... Is there something remotely as good as 1Password for Linux?
- heinrich5991 11y agoLastPass works really good on Linux.
- gkop 11y agoIt's true. They have a little shell script that you run once and it adds their plugin to all the installed Chromes, Chromiums, and Firefoxes on your machine.
- lectrick 11y agoI've played with Linux and never figured this out- What's the difference between Chrome and Chromium? Nevermind, I remembered how to Google... http://www.howtogeek.com/202825/what’s-the-difference-between-chromium-and-chrome/ http://www.howtogeek.com/202825/what’s-the-difference-betwee...
- azmenak 11y agoFirst off, congrats to the LastPass team! You guys have built an awsrome product and company. My hope now is that LastPass won't go down the same path as Meldium, after they were acquired by logmein; the product went downhill very quickly. In the case of Meldium, it seems they were trying to improve the UI by improving the design at the expense of functionality. It feels like LastPass is in a similar position now.
- borisjabes 11y agoI'm sorry you feel that way and will try to correct it. Can you send me feedback on the functionality that's not working as well now in Meldium? There's definitely some edges we're still working through and I'd love to make sure we make it awesome for you asap. You can drop me an email as well (boris at meldium dot com)
- mderazon 11y agoI have to agree. The new interface is too much bells and whistles not so much functionality. Another weird behavior is the chrome which doesn't open a new tab immediately but hold for couple of seconds. This makes you wonder if you should wait before you can switch to a different tab.
- borisjabes 11y agoWe'll work on fixing that. I think it's safe to say that particular tab experiment hasn't worked out.
- WorldWideWayne 11y agoFor anyone thinking about jumping to KeePass - consider the fact that they're still hosted at SourceForge. That's a major red flag for me and I've been keeping my eye out for an alternative for a while now.
- azmenak 11y agoFirst off, congrats to the LastPass team! You guys have built an awsrome product and company. My hope now is that LastPass won't go down the same path as Meldium, after they were acquired by logmein; the product went downhill very quickly. In the case of Meldium, it seems they were trying to improve the UI by improving the design at the expense of functionality. It feels like LastPass is in a similar position now.
- grayfox 11y agoAs someone who recently jumped from Lastpass to 1Password... I wish them the best, but I feel I'm working with the far superior product. Especially on iOS + OS x.
- ebilgenius 11y agoI've recently done the same, but the lack of support for Linux and their lackluster Windows version kinda bums me out.
- signal11 11y agoWhy's the Windows version "lacklustre" compared to the Mac version? I thought 1Password 4 for Windows is at feature-parity with the Mac version, they even have sync over wifi which was missing in 1Password 3.x for Windows.
- jmuguy 11y agoA lot of folks only have experience with Logmein from the horrible way they handled transitioning users from the free to paid service. My company has used Logmein Central for remote access to hundreds of PCs for years. The core software is great, reliable, and has been ever since we started using it. The problem is that Logmein the company knows they're on top of the heap when it comes to remote management. They have no reason to innovate or improve where they can. They added 2FA but otherwise we haven't seen a single new feature that we've taken advantage of in a very long time. Any features they do add hint at them wanting to be a RMM service but you'd have to be an idiot to trust them with more responsibility of your networks. Also a lot of those features require Logmein Pro which adds an insane amount of cost depending on how many systems you're managing. Meanwhile there are bugs that have been around literally since we started using the software. For instance copy/paste while in a session will randomly break. The Logmein client software is very buggy on OSX, crashes often, search will randomly break. Their support is basically non-existent, although I haven't tried in a while if you opened a ticket it would take days if not longer for a response and they'd usually just direct you to some unrelated KB or tell you post on the forums. We use Lastpass as well so this should be interesting. I've yet to see a merger that actually improved things from our end as a MSP. Cisco bought Meraki, Dell bought SonicWALL, at this point I assume any time we see a merger that its time to find a new vendor.
- nandhp 11y agoI also remember when LogMeIn changed the number of users allowed in the free tier of Hamachi (a P2P VPN) -- it went from 10 to 5 with no notice, just randomly disconnecting half of the peers.
- deleted 11y ago[deleted]
- joebasirico 11y agoMy company uses join.me (a Logmein product) all the time for easy screen sharing. It's one of the few quick screen sharing apps out there that doesn't require a heavy download and is user friendly enough to be used by all of the people in our company and all of our client. I've been using LastPass since 2011 and have been really happy with it (other than the slightly opaque UI and design from the 90's). I'm hopeful about the acquisition, maybe logmein can give some UI/UX guidance to the LastPass team, while the LastPass team can help expand and grow to help more people to use a password manager. If not, there are plenty of other password managers out there, I suppose.
- Goronmon 11y agoWhew, glad this happened sooner rather than later. My subscription was up for renewal in a month. At least it makes the renewal decision easy.
- subliminalzen 11y agoRoboform: http://roboform.com http://roboform.com has been excellent for me. Not sure why I switched to LastPass, but I'm switching back.
- saibalter 11y agoWell shit, time to look for alternatives. What else exists other than 1password?
- saibalter 11y agoWell shit. What oither alternatives besides 1password exist?
- gexos 11y agoWhat about Password Safe "Passwddsafe" I use it om my computer and android and I'm very satisfied. And of course the fact that is designed by Bruce Schneier is a plus for me.
- draw_down 11y agoWhen I started my job I got a laptop with the extension for LastPass installed to Safari. One of the first things I encountered was an error dialog, modal for the entire Safari app, telling me of some nonsense problem with Lastpass, which at that point I hadn't even used yet! So I never started using it after that. I occasionally use 1Password for the iPhone, but still mostly rely on the built-in OS X Keychain app. 1Password is too expensive for the Mac and all the other managers don't seem to place much emphasis on UX. This class of application is quite poor to use overall. Even as nice as 1Password is, its syncing story is not very good.
- bad_user 11y agoAnd this is precisely why I'm not using other people's (proprietary) password managers. And if you really have to pick a proprietary thing, then 1Password has always been better because it doesn't have an online component, syncs with Dropbox only if you want it to and whatever happens with the app, the Dropbox sync includes an HTML/JS interface that can read the dumped passwords, plus the format is documented.
- deleted 11y ago[deleted]
- BjoernKW 11y agoThere's something really odd happening with i18n on that blog. It recognizes my primary browser language as German and hence displays menue items and the right side bar in German. So far so good. However, it also partially translates the actual text into German, i.e. for some sentences the first word is translated while the rest remains English: - Zunächst, we (LogMeIn/LastPass) have no plans ... - Zweitens, this acquisition provides us ... - Seitdem, LastPass has grown by leaps ...
- sagawee 11y agoMy homegrown alternative to password managers like LastPass and 1Password: An encrypted zip file. The zip contains * encrypt.sh * payload, a folder containing subfolders, password text files and other personal information. To "unlock", extract the zip. To "lock", run encrypt.sh. Make sure that the extracted data won't get backed-up at any time. I just came up with this a few days ago. Let me know if you have any concerns about this. Here's the encrypt.sh: http://pastebin.com/DudVinms http://pastebin.com/DudVinms
- andrelaszlo 11y agoMine: passwords.txt.gpg (PGP/RSA encrypted text file) Open/edit works seamlessly in Emacs.
- clusterfoo 11y agoHow do I access this from my phone? Same with other open source solutions... the only way to open it on my phone is to trust an unknown app developer to open it for me. I trust GNU zip, but can I trust MiniKeePass? Can I trust iZip?
- Quiark 11y agoI would avoid using .zip file format encryption, who knows how safe that is. PGP as encryptor would probably be a better choice.
- sagawee 11y agoIt depends on what you use to create the .zip file. The zip command uses the insecure PKZIP algorithm. 7z supports AES-256 encryption.
- niyazpk 11y agoLastPass was good while it lasted. As an FYI to anyone looking for other options, I migrated to 1Password (based on reviews/suggestions in this thread). It just took a few minutes to migrate. 1Password supports importing LastPass export file.
- rhabarba 11y agoAs everyone is suggesting alternatives here, one more vote for KeePass with Dropbox (giving you use 2-factor authentication with Dropbox), KeeFox + KeePass2Android. Lovely, free, relatively secure.
- rwhitman 11y agoThe stark reminder that your password manager can change hands is probably the most bothersome part of this. Overall it's probably a good thing that the product is transferring to a more financially stable company with healthy enterprise sales. I'd rather it head in that direction than struggle for a long period of time and put my data at risk. The worst thing that could have happened with this product would have been a spiral of neglect
- ddoran 11y agoI don't like the announcement and I hate how they've done it. Under the signature on the blog announcement, they've added 13 paragraphs in the HTML source to bury the comments off the page. On OSX Safari and Firefox, I see no way to add new comments. Way to start as a new dawn. I wish I hadn't renewed recently.
- gammaray 11y agoWhat are best self-hosted password managers right now? The only one I know of is KeePass2 Something I can serve from a VPS that works on most platforms.
- pms 11y agoSome time ago LastPass automatically DELETED my five-year old account on Mendeley. The "AutoFill" option of LastPass was turned on. I was browsing my profile settings on Mendeley. Somehow LastPass automatically commenced the account removal action, filled in my password, and confirmed the prompt. My account was gone. I did NOT EVEN NOTICE when it happened. The only reason I know it now is because I managed to reproduce this behavior with a new account. I reproduced it one month later, after exchanging multiple nervous emails with Mendeley Support. The potential for abuse of LastPass is huge. The hope is that LastPass will get better after this acquisition.
- bryang 11y agoSolution: 1)Pen & Paper 2)Protected word doc saved in dropbox under an unassuming title like "Low fat, low calorie, totally un-appetizing vegan meals"
- jroovers 11y agoCall me naive, but I created a change.org petition to try and make the voice of concerned users heard: https://www.change.org/p/lastpass-leadership-lastpass-stay-independent https://www.change.org/p/lastpass-leadership-lastpass-stay-i...
- PeterWhittaker 11y agoEven if this petition accumulates hundreds of thousands of signatures, what should happen? The sale has been announced, which means that, but for regulatory approval (if any), it is done: The owners of LastPass have agreed to terms and have signed contracts indicating this, contracts that are binding. Were they to change their minds LogMeIn could in all likelihood sue both LastPass and the owners of LastPass, personally and severally, for breach of contract and for a number of other things. No government will interfere either, as few if any governments will assert that they know both a business's business and the needs of that business's customers better than the business itself - not to mention because of the precedent it could set and uncertainty it could engender. The best response of concerned customers is one, research, and two, should the research so indicate, voting with their feet and either saying put or moving to another service.
- FatalBaboon 11y agoIf you're looking to change your password manager, I've been using `pass` [0] for years now, and it's one of he best open source project I have ever used. Everything works, it uses git for remote storage and gpg for encryption. There is no fancy browser plugin, but a command line to get the password is enough, since browsers cache the password afterwards and most sites use long lived sessions through cookies. And the android app works well. Pass feels simple but it is actually elegant. [0]: http://www.passwordstore.org/ http://www.passwordstore.org/
- slang800 11y agoI can second this - I've been using it for about a year now, and it's fantastic. I'm able to store password history in git, and automatically sync it between all of my machines, using a private GitHub repo for backup.
- jug5 11y agoBig fan of pass, but there is also a browser plugin! https://github.com/jvenant/passff https://github.com/jvenant/passff How do you sync between devices?
- clinta 11y agoI also love pass. My problem now though is what to recommend to family and friends. I've been evangelizing lastpass to them for a while, but I'm not comfortable telling anyone to trust them anymore.
- FatalBaboon 11y agoPrecisely my problem as well, if only pass had a user-friendly interface under windows..
- uean 11y agoI'm also not pleased by this news, given the track record of Logmein and how they butchered Hamachi (mind you, that was years ago), the price gouging and increases to the Pro and Central customers, etc... I could grumble for awhile, but I do see one positive change I think will be made quite soon - Lastpass Enterprise did struggle to pass passwords through remote sessions (to a client server, for example). We played with using Thycotic Secret Server, but Lastpass Enterprise is better in so many other ways that we dealt with copy/pasting passwords into the remote session. If Logmein can bring Lastpass integration through their remote tools I'll be really happy, and I think it will drive people back to Logmein who left over the past few years price gouging. That all said... Logmein was really really terrible about grabbing the clipboard of any user who had recently connected and hanging onto it. 'Pasting' into a session often splooged some other guys clipboard contents (funny jokes, personal password, embarassing URL)...
- BadassFractal 11y agoI really hope the product continues to exist and get better. Their enterprise offering works well enough and is very useful, even though the UX is a bit ancient and awkward at times.
- homulilly 11y agoI dropped lastpass for dashlane awhile ago, it's much better at actually filling out forms.
- justinholmes 11y agoAnyone want to help keep Mitro up and running. I've got some spare racks.
- mtw 11y agoI saw Passwordbox getting acquired by Intel, now this. I don't think I'm going to switch to 1Password or another. I think they are just going to be acquired one day by unknown big entity... better be safe and keep your passwords to yourself
- afaqurk 11y agoI just created a list this morning to help my family figure out an alternative to LastPass. Here it is: http://afaqurk.github.io/lastpass-alternatives/ http://afaqurk.github.io/lastpass-alternatives/
- oneJob 11y agoI would just like to add my voice to the cacophony of others shouting into this particular echo chamber: Peace out Lastpass
- deleted 11y ago[deleted]
- jordsmi 11y agoTime to switch back to KeePass. Lastpass is much more enjoyable to use but LogMeIn seems to ruin everything they touch
- pinkano 11y agoYes, so I'm switching over to a different one. LogMeIn is always a mess when they acquire another company. So far Sticky Password seems like a decent alternative with some servers saying they offer a great discount. http://heavy.com/tech/2015/10/lastpass-alternatives-logmein-acquired-replacements-password-manager-dashlane-keepass-1password-splikity-shark-tank-encryptr-enpass/ http://heavy.com/tech/2015/10/lastpass-alternatives-logmein-...
- pinkano 11y agoSo it seems that Sticky Password offers a 50% discount in regards to what happened to Lastpass: http://blogen.stickypassword.com/looking-for-an-alternative-to-your-current-password-manager/ http://blogen.stickypassword.com/looking-for-an-alternative-...
- caroline223 11y agoIf you are looking for an alternative password manager, take a look "Intuitive Password" online password mansger (www.intuitivepassword.com). I have more than 200 passwords and they are all different for each site, I use it everyday. It works on all devices including smartphones, tablets, laptops and desktop PCs without installation required. Intuitive Password provides a Data Restore Points feature so you can't lose your data using their service.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- johnwilliams123 11y agoJust in: Zoho Vault offers free migration to LastPass Users. Link: https://www.zoho.com/vault/logmein-lastpass-acquisition.html https://www.zoho.com/vault/logmein-lastpass-acquisition.html