3 ms·
My workplace uses LastPass as the "blessed" password manager that's recommended by the security team. It's a nightmare. I've given up on it entirely and would
by ubertaco 5y ago
My workplace uses LastPass as the "blessed" password manager that's recommended by the security team.
It's a nightmare. I've given up on it entirely and would never trust it again, after encountering this flow several times a month:
1. Log in to LastPass
2. Respond to 2-factor auth prompt
3. LastPass says "you need to change your password"
4. Type in a new password
5. LastPass says "okay, password changed, log in again"
6. Log in to LastPass again, with new password.
7. LastPass says "incorrect username or password."
8. Log in to LastPass again with old password.
9. Respond to 2-factor auth prompt again
10. LastPass says "you need to change your password"
11. Type in the same new password again
12. LastPass says "you cannot reuse the same password"
13. Type in a different new password
14. LastPass says "okay, password changed, log in again"
15. Log in to LastPass again, with new new password.
16. LastPass says "incorrect username or password."
17. Log into LastPass with old password.
18. LastPass says "incorrect username or password."
19. Log in to LastPass with old new password
20. Respond to 2-factor auth prompt.
21. Repeat this loop from step 10 an unspecified number of times, only each time LastPass picks a random one of the possible passwords in play to be the "current" password.
22. Eventually, after an unspecified number of loops, LastPass no longer asks me to change my password again. I now have to keep track of which of the N possible new passwords is the one it kept.
I just use a KeePass vault at this point -- it's free, and it actually works, both of which are more than I can say for LastPass.