How the Mighty Have Faceplanted (Premium)

In the 1990s, Microsoft destroyed many once-great companies. But these days, they're just committing suicide.

Case in point: LastPass, a once trusted security company that was acquired by GoTo (formerly LogMeIn, another once trusted company) in 2015 before suffering from several significant security incidents over the next several years, causing GoTo to wipe its hands clean of the tarnished brand by spinning it off earlier this year.

The central mission of LastPass has never changed: Now, as at its inception in 2008, the company offers a password manager via an online service, browser extensions, and apps so that you can store your passwords in a single place and access them anywhere. It's a solid idea, and for many years, LastPass was highly recommended by many for its ubiquity and ease of use. Like many of you, I bet, I was a LastPass user for many years.

By the time I started Thurrott.com in early 2015, LastPass was well understood, but like Evernote in note-taking apps, the competition had improved. And while browser makers had likewise improved their built-in password management capabilities, the dominance of Apple and Google on mobile, and Microsoft on the desktop, further sidelined this company: These companies own the platforms and the default browsers that run on them.

But the biggest issues LastPass faced came from within: The firm had always been a target for hackers because of the data it stores, and in 2015, it suffered from a major security breach in which hackers stole its customers' email addresses, password reminders, server per user salts, and authentication hashes. My response to this is regrettable: Trusting the company, I wrote an article reminded readers to use 2FA authentication with LastPass to eliminate the key complaint about any password manager, that it is a single point of failure. (I had previously—and since—written about the importance of safeguarding your online accounts with 2FA more generally.)

The following year, LastPass came to Windows Phone, so I made it an app pick. And then it came to the then-new Microsoft Edge browser, which had launched in 2015 in Windows 10 without extension support. But with competition increasing, LastPass was feeling the pinch. It freed some capabilities from its paid Premium subscription to drive usage in late 2016. And then it sadly succumbed to a further series of attacks, starting in 2017. Regrettably, again, I was still defending the company at that time.

But with bigger hacks that impacted more meaningful user data, including master passwords and even passwords vaults throughout 2021 and 2022, LastPass was no longer defendable. There was a class action lawsuit and, from what I can see now, an almost-unreported incident in 2023 in which 150 victims of a cryptocurrency scam were all LastPass users. GoTo, as noted, flushed LastPass away earlier this year, understandably.

I quietly gave up on this company years ago, and I've spent the past two years using...

Gain unlimited access to Premium articles.

With technology shaping our everyday lives, how could we not dig deeper?

Thurrott Premium delivers an honest and thorough perspective about the technologies we use and rely on everyday. Discover deeper content as a Premium member.

Tagged with

Share post

Thurrott