LastPass vs. 1Password: Which should you use? [2024] | Zapier (2024)

Everyone agrees: passwords are terrible. They're either too easy for a hacker to crack or impossible for you to remember. I can go on at length about why they're so bad and create such an awful situation—I wrote a thesis on it—but the real takeaway is that password managers are really important if you want to stay secure online. They automate the process of generating long, complex, unique passwords, storing them securely, and, best of all, filling in login forms, so you don't have to remember or type any of those complicated characters.

When it comes to the best password managers, historically, two apps have come up the most often: LastPass and 1Password.

Recently, though, things have changed—dramatically. LastPass suffered a major data breach at the end of 2022 and has been criticized by security researchers for how it handled the fallout. Over a year later, it still hasn't fully addressed the situation.

Still, LastPass is a very popular password manager. So in addition to my previous experience with both apps, I dove back into each one to see how they stack up.

1Password vs. LastPass at a glance

While there are small differences in how 1Password and LastPass operate, the reality is that they're pretty similar when it comes to features. Unlike all-in-one tools that try to be everything to everyone, these apps are really meant to store and manage your passwords, so it makes sense that they do it similarly.

Here's a quick breakdown of how they compare, but keep reading to learn more about my experiences with the apps—and what other security experts think.

1Password

LastPass

Security

⭐⭐⭐⭐⭐ Best in class security and has never had a breach

⭐⭐ Recent data breach and less than ideal security in general

Ease of use

⭐⭐⭐⭐⭐ Easy to import passwords, generate new passwords, and log in to existing accounts

⭐⭐⭐⭐⭐ Easy to import passwords, generate new passwords, and log in to existing accounts

App availability

⭐⭐⭐⭐⭐ Native apps on every device

⭐⭐⭐⭐ It's available on nearly every platform, but you don't always get native apps

1Password offers much better security

A password manager has two main jobs: to keep your passwords safe, and to make filling them in easy. Everything else is kind of secondary. To make things as convenient as possible, both LastPass and 1Password store all your login information on their servers. It's meant to be encrypted and well-protected, so with that in mind, it's worth taking a step back and looking at the ongoing fallout of the LastPass hack from just over a year ago.

In August 2022, LastPass disclosed that a hacker had compromised a developer account and gained access to its development environment. It claimed that it had contained the breach and had taken mitigation measures. In September, it declared that its investigation was complete and all was well, and that there was no evidence any customer data or encrypted vaults had been compromised. Embarrassing for a security company, but it wasn't the first time the company had been hacked—and this was a less compromising breach.

Then, at the end of November, LastPass announced that one of its third-party cloud storage services had been hacked "using information obtained in the August 2022 incident" and that the hackers had gained access to some customer information. What information? Well, it took until December 22, but LastPass came clean: the hackers had a backup of customer vault data.

Some fields in the vault databases—like passwords, thankfully—were encrypted, but others, like email addresses, telephone numbers, the IP addresses customers used when accessing LastPass, and billing addresses weren't. Regardless of whether the hackers could crack the passwords, they still had a lot of personal and identifying data about every affected LastPass user.

And even the encrypted passwords aren't necessarily safe. LastPass has been criticized for years for its inadequate security precautions and failure to update legacy accounts. If someone with a recent LastPass account followed best practices and used a strong, unique master password, their data is probably still private (other than all the unencrypted identifying stuff). But if you had an older LastPass account, reused or used an insecure master password, or were a particularly tempting target? The hackers have direct access to your encrypted vault and can try to crack your master password for as long as they like.

And crack master passwords they did. Throughout 2023, there were a string of crypto heists targeting LastPass users. More than $35 million has been stolen in total from dozens of victims, many of whom were using otherwise solid security protocols. The one commonality was that they all stored an important crypto account identifier called a "seed phrase" in LastPass.

And crypto is just the tip of the iceberg. There's no way to know just how many people were the victims of other kinds of scams because of their LastPass data being compromised. It's only because of the public and very online nature of crypto that security researchers have been able to keep track of the hacks and attribute them to the LastPass breach.

As a result of all this, LastPass has been widely condemned by the security community for allowing hackers to gain access to customer data, failing to contain the initial breach, having inadequate security measures in the first place, downplaying the severity of the breach, trying to blame customers for not having strong enough master passwords, and generally just mishandling the whole situation.

It's facing a class-action lawsuit, and over 18 months later, LastPass's response has been lackluster. In September 2023, more than a year after the initial breach, it finally started forcing old accounts to use 12-character master passwords and automatically updating every account to at least 600,000 rounds of an algorithm called PBKDF2 that slows down attempts to brute force master passwords. (Previously, the minimum for new accounts was 100,100 rounds, and older accounts were secured with just 5,000, 500, or even 1 iteration without being upgraded.)

As one of the affected users, I had to spend a few hours one afternoon over my winter break changing a load of passwords. (I hadn't relied on LastPass for years, so my most important accounts were still safe.)

In short, the last 18 months have demonstrated that LastPass has a pretty cavalier attitude toward protecting the passwords you store with it.

So what about 1Password?

For starters, 1Password has never had a data breach, although it has been targeted. Even then, the company was upfront and honest with customers and published a full security report detailing what happened. More importantly: 1Password uses a significantly more secure setup to encrypt your vault—and encrypts every field. While LastPass now uses 600,000 rounds of PBKDF2 as its default for all accounts, 1Password uses 650,000 iterations—and has always updated old accounts to the latest value.

And even with that, LastPass locks your vault with just your master password, whereas 1Password uses a master password and an additional secret key.

This comes with a downside: to sign in to 1Password on a new device, you need to enter both security factors. It can be pretty inconvenient—your secret key is a long string of numbers that's meant to be kept safe, not carried about on your phone. So while you can log in to LastPass from anywhere, 1Password's improved security makes that harder. But it does mean that even if 1Password were to suffer a similar data breach, user data would be significantly less vulnerable to hackers.

With all that said, despite the embarrassment of the recent breach, most of LastPass's security problems fall into the realm of "less than ideal," not "use LastPass and you'll get hacked yesterday." If you're a regular internet user—not someone prominent who could be specifically targeted, or with a few million in crypto sitting in a wallet—and sign up for a LastPass account today, as long as you use a decent master password, your data should be safe.

Personally, I wouldn't take the risk of using LastPass because I'm neurotic about these things (and I'm regularly a victim of impersonation and identity theft). If you massively prefer LastPass's interface or need its free plan, then feel free to give it a try—just understand the risks.

LastPass and 1Password are both available on almost every platform

LastPass and 1Password operate almost identically on mobile platforms, since Android and iOS both support password management and autofill.

LastPass vs. 1Password: Which should you use? [2024] | Zapier (2)

Both services also have browser extensions for Chrome, Firefox, Safari, and Edge that work similarly. Opera is the only browser that LastPass supports that 1Password doesn't.

On the desktop, however, there's a bigger difference. 1Password offers native desktop apps for Windows, Linux, and Mac users; LastPass more or less relies on browser plugins.

  • 1Password has local apps for Windows, Linux, and Mac that you can use offline to access your passwords or any other information you have stored in your vault. These apps also offer a universal keyboard shortcut for quickly searching your passwords, something LastPass no longer offers on the desktop. 1Password for Chrome OS is a browser-based app, which is common for apps on the platform, and there's also a command-line tool for Windows, Linux, and Mac devices. 1Password also offers browser extensions, which work with or without the desktop app installed. The exception is Safari—you'll need to install the macOS app, but that's just how Safari extensions work.

    LastPass vs. 1Password: Which should you use? [2024] | Zapier (3)
  • LastPass, on the other hand, doesn't really focus on desktop apps. The company offers a "universal installer" for both Windows and Linux that will download browser extensions for every browser, or you can download them all individually. There is a Mac app, but it's more or less just the web version of LastPass running in a dedicated window that comes with a Safari extension. LastPass's own documentation recommends that you use a combination of browser extensions and mobile apps.

    LastPass vs. 1Password: Which should you use? [2024] | Zapier (4)

Overall, the differences between the services exist only on the edge cases. Both apps support most major browsers, which means you can run them both on any operating system. But if you want to use a local desktop app for offline use, 1Password is your only choice.

Both apps are really nice to use

LastPass is really pleasant to use—there's a reason the recent breach affected 33 million registered users and 100,000 business customers. But there isn't a huge amount of difference between how it and 1Password operate in most cases.

Take logging in to your accounts. If LastPass recognizes a login field, you'll see a LastPass logo in it. Click that, and you can choose which account you want to sign in using.

LastPass vs. 1Password: Which should you use? [2024] | Zapier (5)

1Password works the same way using the browser extension.

LastPass vs. 1Password: Which should you use? [2024] | Zapier (6)
See Also
For business

But with 1Password, you also have another option: the Quick Access bar in the desktop app. Use the keyboard shortcut Ctrl/command + shift + space in any app to bring up this bar, which you can use to search all of your passwords and copy any shortcut. This works outside of the browser, meaning it's handy if you're logging in to a desktop app. It's much faster than what LastPass offers on desktop: you can find any password in just a couple of keystrokes, without touching the mouse. If you prefer clicking to keyboard shortcuts, though, you can right-click, select 1Password, and then select your account.

Both apps also make it easy to generate secure passwords for new accounts.

With LastPass, whenever you're creating a new account, you'll see an icon in the password field that you can click to create a random password. Click it, and you will see a password, which you can click right away to use.

LastPass vs. 1Password: Which should you use? [2024] | Zapier (7)

You can choose Customize to change the parameters, like the length of the password or whether or not it includes numbers or special characters, and there's even an option to make the password easy to say if you create it through the full app. These last options are especially helpful for passwords you might still need to actually remember, like your Wi-Fi or Netflix password.

1Password works a little differently. You can click the icon in the password field, but you won't be able to customize—only to accept the given password.

LastPass vs. 1Password: Which should you use? [2024] | Zapier (8)

If you need to generate a password, click the 1Password extension icon in your browser's toolbar, create a new login, then generate the password there. You can customize the parameters to make a long nonsense password, a passphrase made up of random unrelated words, or a PIN. You can tweak things like whether it uses numbers or symbols or which symbol is used to separate words in a passphrase. Once you have a password you like, you can copy and paste it into the password field.

If a site has special requirements for passwords, the generator in LastPass is slightly more convenient to tweak, though 1Password can also get the job done.

LastPass vs. 1Password: Which should you use? [2024] | Zapier (9)

Since long passwords can be hard to remember, we suggest using a passphrase, a collection of seemingly unrelated words that are easy to remember. Something like ZapierWinstonDoggosPlanetCheeseTreats. But…don't actually use that.

1Password and LastPass both have lots of extra features

Both apps have a lot of good secondary features.

  • Both can autofill two-factor authentication codes.

  • Both make it possible to share passwords with other people, though LastPass makes it slightly easier.

  • Both can store credit card numbers, secure notes, important documents, and other things you should keep safe.

  • Both have password breach monitoring and password strength assessment (LastPass calls its Security Dashboard while 1Password calls it Watchtower).

    LastPass vs. 1Password: Which should you use? [2024] | Zapier (10)

Most importantly, both apps are working to support passkeys—a new system that uses public-key cryptography to secure your accounts instead of passwords. They solve a lot of the problems with passwords, though only a small number of services support them at the moment.

Right now, 1Password's passkey implementation is further along, since you can use it to create passkeys for other services that support them, as well as use one to secure your 1Password account.

LastPass vs. 1Password: Which should you use? [2024] | Zapier (11)

LastPass currently only allows you to use one to secure your LastPass account instead of your master password. Still, passkeys aren't yet widespread enough that this really counts as a major ding against LastPass. Both services are beta testing and rolling out their implementations, and by the time passkeys are more widely available, they're both likely to be ready.

Really, there aren't many differences here. For almost everyone, either service will offer an almost identical password management experience.

Neither app offers a good free plan

While there are great free password managers available (see: Bitwarden), neither LastPass nor 1Password falls into that category.

Let's start with 1Password. It's free for journalists and politicians; for everyone else, there's a 14-day free trial. After that, you're looking at $36/year for a Personal account or $60/year for a Families plan with up to five accounts. There are also business plans available from $19.95/month.

In addition to a 30-day trial, LastPass offers a free plan—it's just extremely limited.

LastPass vs. 1Password: Which should you use? [2024] | Zapier (12)

While you can save as many passwords as you want, you can only access your free LastPass account on one device type: either computers or mobile devices. This means you can use LastPass to sync your passwords between your office computer and your personal laptop, but not between your laptop and your smartphone. It's a really awkward caveat, and it undermines the whole "all your passwords everywhere" thing that most people use a password manager for. On paid plans, this isn't an issue. A LastPass Premium plan costs $36/year, while a Families plan for six users is $48/year. For businesses, a Teams plan starts at $4/user/month (billed annually).

So, if you're choosing between 1Password and LastPass, you're really choosing which app you want to spend a few dollars a month on. If you're genuinely considering LastPass's free plan, I'd suggest checking out Zapier's article, where we compare it with Bitwarden, which has a more robust free offering.

1Password vs. LastPass: Which should you choose?

For almost everyone, 1Password is a better password manager than LastPass. There's so little difference between the general user experience, availability, and price of the two apps, that the additional security and transparency of 1Password make it the easy choice.

If you already use LastPass, use a secure master password, and don't want to go through the minimal hassle of switching services, then sticking with LastPass is understandable. But for new users, you'd really have to want one or two of the niche, specific features that LastPass brings to the table (or have a serious discount code) for it to be a better choice.

Related reading:

  • The best password managers

  • Bitwarden vs. LastPass: Which should you use?

  • Make all your passwords strong and unique in 6 steps

  • Two-factor authentication: A security system for your digital life

  • iCloud Keychain vs. 1Password: Which is best?

This article was originally published in February 2019 and has had contributions from Zac Kandell and Justin Pot. The most recent update was in January 2024.

LastPass vs. 1Password: Which should you use? [2024] | Zapier (2024)

FAQs

LastPass vs. 1Password: Which should you use? [2024] | Zapier? ›

LastPass: Which should you choose? For almost everyone, 1Password is a better password manager than LastPass. There's so little difference between the general user experience, availability, and price of the two apps, that the additional security and transparency of 1Password make it the easy choice.

Is LastPass still safe in 2024? ›

No, LastPass is not considered 100% safe due to the security incidents and data breaches that affected the password manager and its users in the past. Hackers successfully threatened the provider on three different occasions – in 2015, 2021, and 2022 – which is why it's impossible to endorse LastPass as a safe password ...

Should I no longer use LastPass? ›

Because of the most recent data breaches, I wouldn't say LastPass is safe to use. In 2022, LastPass experienced two major data breaches that led to both LastPass customer and company data being stolen. The first incident, which occurred in August 2022, involved a software engineer's corporate laptop being compromised.

Should I switch away from LastPass? ›

Get off of LastPass, change *all* of your passwords in order of priority, implement 2FA wherever available, and be especially cautious about any possible phishing attempts from accounts you secured with LastPass. PS - Noting that the 'solution' applies to 'personal' customers raises new questions.

Which password manager has never been breached? ›

There are several password managers with better security, as LastPass has been breached. 1Password is an option as it has never been breached, and NordPass is also known for its strong security features.

Should I use 1Password or LastPass? ›

For almost everyone, 1Password is a better password manager than LastPass. There's so little difference between the general user experience, availability, and price of the two apps, that the additional security and transparency of 1Password make it the easy choice.

Is there any reason to stay with LastPass? ›

With LastPass, you use a master password to encrypt and access your password vault. Even if your device is hacked, your vault remains protected. Go passwordless to access your vault without having to type in your master password.

Is there a better password manager than LastPass? ›

Norton's biometric authentication offers quick, secure access to your vault across all mobile devices, which simplifies usability. Each of these elements contributes to why we believe Norton Password Manager is the best LastPass alternative for integrated cybersecurity solutions.

Is 1Password really safe? ›

To protect your data in and outside the vault, 1Password uses end-to-end encryption and complies with industry-standard security controls. The information is encrypted using AES-256 cipher, and you can also use multi-factor authentication that supports security keys or biometrics.

What is the LastPass controversy? ›

Some sources criticized LastPass's response, and raised additional concerns over the number of rounds of encryption that were required. A class-action lawsuit was initiated in early 2023, with the anonymous plaintiff stating that LastPass failed to keep users' information safe.

Who to switch to from LastPass? ›

Get 1Password for your browser. You'll use the 1Password browser extension to save logins and sign in to websites. Change your passwords. If your LastPass data was part of a breach and you haven't changed your passwords yet, use 1Password to generate and save new passwords for all your accounts.

Is Bitwarden better than LastPass? ›

When it comes to password security, Bitwarden clearly surpasses LastPass in getting the job done. Ultimately, Bitwarden is best for those seeking the most advanced security features and the lowest-cost option for password management.

How many people use 1Password? ›

Trusted by over 15 million users

I've used 1Password for a few years and it has proven time and time again how valuable it is to me. Managing my passwords across my devices is so easy with my subscription.

What password manager do security experts recommend? ›

The best password managers at a glance
Best forStandout feature
1PasswordMost peopleEasy to use across devices
BitwardenA free password managerGenerous free plan with no big caveats
DashlaneA full internet security toolAdditional security features like VPN
iCloud KeychainApple usersSeamless integration with Apple devices
Jan 19, 2024

Has 1Password ever been breached? ›

The password manager came forward after BeyondTrust and Cloudflare disclosed similar Okta environment breaches. All three victims claim no data was compromised.

What is the best password manager right now? ›

Quick List
  • NordPass. Best password manager overall. ...
  • Dashlane. Best password manager for security. ...
  • RoboForm. Best password manager for mobile. ...
  • Bitwarden. Best free password manager. ...
  • Keeper. Best password manager for mid-sized business. ...
  • N-Able Passportal. Best password manager for enterprise. ...
  • 1Password. ...
  • Proton Pass.
Apr 12, 2024

What replaces LastPass? ›

Top LastPass Alternatives
  • Keeper Enterprise Password Management.
  • Specops Software Password Management Tools.
  • ManageEngine Password Manager Pro.
  • 1Password Business.
  • Dell Password Manager.
  • Bitwarden.
  • Bravura Pass.
  • Zoho Vault.

What is more secure than LastPass? ›

With its robust features and affordable pricing, NordPass is our top pick. Compared to LastPass, NordPass offers the convenience of autosaving and autofilling forms while providing extra security measures including multifactor authentication and a scan for data leaks.

Why is LastPass forcing me to change my master password? ›

Cross-Checking New Master Passwords on the Dark Web

If the password is detected in a prior breach, a “Security Warning” pop-up will alert the customer that the password has already been exposed, in which case they will be prompted to choose another password in order to proceed.

What happens when LastPass expires? ›

If you have a LastPass Teams or LastPass Business account and your plan has expired, you can choose from renewing your current plan, upgrading LastPass Business, switching to different plan, or taking no action and using your (now converted) LastPass Free account.

Top Articles
TJX Rewards Platinum Mastercard Review 2023
Payment Checkout Solution for Businesses - Payoneer
159R Bus Schedule Pdf
Jazmen00 Mega
Jeff Bezos Lpsg
Lvc Final Exam Schedule
Chesapeake Wv Topix
Craig Woolard Net Worth
Ups Store Near Publix
Update | Een maand afvallen met NBFM (+ recept & snacktips!) - Mama's Meisje
Giantesssave
Gdp E239 Bts
Magicseaweed Capitola
Restaurant Depot Flyer December 2022
Aaf Seu
Does Publix Have Sephora Gift Cards
KMST ver. 1.2.178 – Tallahart & the Long Awaited Balance Patch!
Jennifer Beals Bikini
Guide:How to make WvW Legendary Armor
Bj지밍
Olecranon Fractures Flower Mound
Buffalo Bills Football Reference
Kaelis Dahlias
Tryst Independent
Wmu Academic Calendar 2022
I-80 New Jersey Traffic and Road Conditions
Resident Evil Netflix Wiki
Trade Chart Dave Richard
Claw Machine Random Name Picker
Craigs List Skagit County
Keci News
Shs Games 1V1 Lol
Hotcopper Ixr
Texas State Final Grades
Taylor Swift: The Eras Tour Showtimes Near Marcus Pickerington Cinema
Texas Longhorns Soccer Schedule
Best Greek Restaurants In Manhattan
Craigslist Tools Las Cruces Nm
Nz Herald Obituary Notices
eCare: Nutzung am PC | BARMER
Mekala - Jatland Wiki
Mathews Vertix Mod Chart
Hyundai Elantra - modele, dane, silniki, testy
How To Use Price Chopper Points At Quiktrip
Ultimate Guide to Los Alamos, CA: A Small Town Big On Flavor
Mazda 6 GG/GG1; GY/GY1 2.3 MPS Test : MPSDriver
Kgtv Tv Listings
Luminous Mysteries - Rosary Meditations
Jenny Babas Nsfw
Craigslist Antelope Valley General For Sale
Voertuigen Geluiden - Pretlettertjes
Opsahl Kostel Funeral Home & Crematory Yankton
Latest Posts
Article information

Author: Maia Crooks Jr

Last Updated:

Views: 5858

Rating: 4.2 / 5 (43 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Maia Crooks Jr

Birthday: 1997-09-21

Address: 93119 Joseph Street, Peggyfurt, NC 11582

Phone: +2983088926881

Job: Principal Design Liaison

Hobby: Web surfing, Skiing, role-playing games, Sketching, Polo, Sewing, Genealogy

Introduction: My name is Maia Crooks Jr, I am a homely, joyous, shiny, successful, hilarious, thoughtful, joyous person who loves writing and wants to share my knowledge and understanding with you.