ID: 201157


Date: 2021-02-18

LastPass password management app: A cheat sheet

Not all password managers are created equal, and LastPass is one of the standout options. Available for almost every OS, browser, and mobile platform on the market, LastPass is designed to have you safe, secure, and encrypted wherever you happen to be. TechRepublic's cheat sheet about LastPass is a quick introduction to this password management app, as well as a "living" guide that will be revised periodically as new updates and versions are released. Put simply, LastPass is a digital vault where you can safely store passwords without fear of their being discovered. Plenty of people are in the bad habit of keeping a notebook in their desk drawer or sticky notes on the underside of their keyboard with passwords on them; LastPass is the cure for that incredibly dangerous practice. All of the data you store in LastPass is encrypted using the AES-256 standard. This level of encryption is used by the US government to protect top secret information; a 2013 paper said there is no computationally feasible way to brute force crack it, and as of 2021 nothing has changed. That means your passwords are safe. In addition to AES-256 encryption of your password vault LastPass communicates with its servers using PBKDF2 SHA-256 and salted hashes for an extra layer of security between the app on your phone/computer and LastPass' servers. Additional resourcesThink of the number of websites and applications you have passwords for. If you're like the average American, it's somewhere between 70 and 80, which is a lot of information to remember. We'd all be lying to ourselves, of course, if we said each of our accounts had a unique, secure password. Most of us use the same one--or a slight variation--over and over again. Repeated use of passwords poses a serious security risk that can be eliminated by apps like LastPass. Another common method of password theft is malware that logs keystrokes: All a hacker needs to do is read off the website you typed in along with your username and password to get instant access. Check out all of TechRepublic's cheat she smart person's guidesLastPass circumvents keyloggers in two ways : It can autofill passwords once you're logged in and it also offers a virtual keyboard that you can click on with your mouse. Avoiding keystrokes while typing in passwords or using an onscreen keyboard, along with robust encryption, leaves you protected in a way you can't get with other methods. LastPass can also generate random, complex passwords that you won't have to worry about remembering, provided you have it set up to sync across your devices. Additional resourcesIf you are reading this, LastPass probably affects you. Anyone who uses a computer or smartphone to log into an account can benefit from LastPass: It provides several layers of added security to prevent theft of passwords and important personal data. In 2019, 14.4 million Americans (around 6.67% ) were victims of identity theft--a number that's held roughly steady for the past several years. A paranoid level of identity protection is essential in the internet age, and LastPass can eliminate much of the legwork. Additional resourcesLastPass was originally released in 2008 as a browser plugin. Since then it has grown into a desktop application and mobile app along with its original browser-based form. LastPass is free, but there are also premium options for home users and enterprises. Both offer more features, such as shared accounts for family access and administration consoles for business users. Prior to November 2, 2016, LastPass' free version had a serious restriction: Passwords stored on one device wouldn't transfer to another. If, for example, you stored banking credentials on your desktop, you wouldn't be able to retrieve them on your smartphone. Luckily, that feature is now free, but with a big caveat imposed in February 2021: Free users can only sync passwords on computers or mobile devices, and not between those two platforms. Best practices and security tips (free PDF). (TechRepublic). Anyone using LastPass without paying for a subscription (prices start at $36 USD annually) will, on March 16, 2021, have to choose one of the two platforms, mobile or computer, to sync passwords to. The other platform will simply stop working unless you opt to pay the yearly fee, which LastPass has discounted to $27 USD for new Premium or Family customers paying for their first year. After that the price increases back to $36/year. Additional resourcesIf the lack of synchronization available to free users is enough to make you want to switch to a different password manager, there are a number to choose from, as TechRepublic sister site ZDNet pointed out. Depending on what platform you use, you could opt for a first-party password manager, like Apple's iCloud Keychain, which is integrated with Mac and iOS devices. Likewise, Google has Chrome Password Manager that syncs passwords across Android devices and to Chrome browsers on systems like Windows and MacOS, provided you log in with the same account. In terms of third-party password managers, a number of options are available: Additional free password managers are available, but many place restrictions on multi-device sync or other features. If one of the above-mentioned products doesn't fill your password management needs, be sure to read product descriptions closely before investing time into a product that is less useful than you thought. Additional resources: LastPass is available on a variety of platforms--pretty much anyone using any device can install it. Simply navigate to LastPass' website and click on Get LastPass Free to be instantly taken to the mobile app store or browser plugin install screen applicable to your device. You can also click on Download to see other options for installation, such as the desktop apps available for Windows, macOS, and Linux. Additional resources Strengthen your organization's IT security defenses by keeping abreast of the latest cybersecurity news, solutions, and best practices. Delivered Tuesdays and Thursdays