It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…
Good security is hard in practice because people are always going to default to the most convenient/simple way to accomplish their goal, and at this point, most of our security measures require someone to expend extra energy. That means it's going to be very hard to get people to do it.
We have decades of experience with this just with regard to one layer of passwords. Adding an extra layer, like a password vault, is not going to make things better.
While it absolutely true that there is more risk involved in using a third-party extension to manage a password vault than not, the actual net effect is likely better security, because if you make things too hard, people are just going to say "Fuck those annoying nerds, we're going to make every password 123456", or whatever the next-simplest answer that the system will permit is.
As for LastPass making mistakes, that's true, but the benefit you get by using a well-known product like LastPass is that Project Zero has hardened it. That's not the case for most other password vault extensions, especially those made as shims for external vaults like KeePass.