Earlier quoted context omitted.
For me it was a case of thinking I know better. As in, "no way I'm giving you my passwords" and "who knows how tight their opsec is" ... never even tried anything like LastPass or 1Password until six months ago. Now I cannot imagine going back. My LastPass subscription is among the most vital services I pay for and the sheer freedom of having to remember one diceware-style master password instead of maintaining my ow…
> So if you cracked my LastPass vault - good luck with that, 2FA considered Well, the traditional[1] way to break[2] LastPass is to ignore individual accounts and go after poor coding technique[3]. 2FA won't help you there. [1] https://www.wired.com/2015/06/hack-brief-password-manager-la... [2] https://techcrunch.com/2011/05/05/password-manager-last-pass... [3] https://labs.detectify.com/2016/07/27/how-i-made-lastpas…
I would think the first link doesn't affect me since I use a fairly strong unique master password and haven't set an insecurity question.
As for the second link, much the same. I mean I'm fairly certain I can create an encrypted plaintext file that withstands extensive cracking attempts with standard Linux tools. These kinds of attacks would suck for people using 'lastpassword' as their master, if the stored vaults were unhashed and unsalted. Even then, how would that circumvent 2FA? Without my phone or Yubikey or whatever, you still don't get in.
As for the last one, and generally for most criticism: these tools give you the means to be more secure, they even encourage you by asking things that must annoy the average user. There's no unlimited trust for devices or browsers, the security checker is actually quite helpful in identifying possible problems - like my banking password being capped at five digits by design... sigh - and telling you when you're getting dumb ideas, like permanently storing your master password on your phone. So in the end, it's up to the user isn't it?
It's not using it by itself that makes the concept an increase in security, it's using it thoughtfully that is.