By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: LastPass: Excellent Apps and Free Dark Web Monitoring With a Caveat
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > LastPass: Excellent Apps and Free Dark Web Monitoring With a Caveat
News

LastPass: Excellent Apps and Free Dark Web Monitoring With a Caveat

News Room
Last updated: 2025/09/18 at 2:08 PM
News Room Published 18 September 2025
Share
LastPass: Excellent Apps and Free Dark Web Monitoring With a Caveat
SHARE

Before I review and test a password manager, I send a list of questions to the company inquiring about its privacy and security practices. Consumers should have plenty of information about the companies handling their data. For insight into LastPass’s privacy policies, read the company’s answers (edited for length) to my questions below.

Has your company ever had a security breach?

Yes.

If so, when? Please provide dates.

2015 (GoTo was breached), 2022.

What was exposed in the breach?

2015 – Before being acquired by LogMeIn, Inc. (now known as GoTo), GoTo experienced an incident in 2015 where a hard drive was stolen from one of their data centers. This drive did not include users’ vaults but did include unencrypted data related to their accounts.

2022 – LastPass disclosed that a threat actor had gained access to a cloud storage environment used for backups and exfiltrated both encrypted and unencrypted customer data.

Since then, LastPass made a multi-million-dollar investment in security enhancements across its people, processes, and technology including completing its separation from GoTo, operating as an independent company with a newly refreshed management team, entirely new modernized cloud-based infrastructure, systems, and tools, as well as a fully dedicated Trust and Security team. This includes a new Threat Intelligence team focused entirely on protecting its customers and their data. In connection with this separation, LastPass completed a number of steps to further modernize and harden its infrastructure.

What unencrypted information does the password manager store in customer vaults?

Encryption and decryption are ONLY performed on the end-user’s device. LastPass does not have access to or store the master password, which derives the encryption key used to encrypt/decrypt customer data. This is aligned with our Zero Knowledge principles.

LastPass customer vault data is encrypted using AES-256 on a per-user basis (meaning every user’s encryption keys are unique.) Encrypted fields within the vault include usernames, passwords, website names, notes, payment cards, addresses, bank accounts, item and folder names, secure notes, etc.

Up until June 2024, URL-related fields within the vault were not encrypted. As of June 2024, all newly created and any customer-modified URLs stored within the primary URL field have been encrypted in all customer vaults.

There are 6 remaining URL-related fields, which are either pre-populated by LastPass or empty upon initial use and potentially added by customers. The remaining fields have architectural dependencies that will take longer to remediate, and encrypting these fields will require additional product refactoring and/or sunsetting of certain older features/functionality, and will continue throughout 2025, given required end-of-life (EoL) notification practices.

What is the company’s policy regarding selling or sharing customer data with third parties?

At LastPass, we always strive to limit the types and categories of data that is collected from, and processed on behalf of, our users to include only data which is necessary to achieve the purpose(s) for which it was collected – in other words, we have measures and policies in place designed to ensure that we only collect and process data that we believe is necessary to provide our users with a world-class service. 

LastPass does not sell end-user data to third parties, including any vault data. Under some US state data protection laws, our use of third-party cookies for advertising purposes may constitute a “sale”. We specifically inform visitors of the use of those technologies and the specific cookies that may be deployed within our cookie banner, and, depending on the visitor’s location, cookies are only deployed after a visitor opts in to their use. Furthermore, we afford individuals to manage their privacy rights by changing opting-out of the sale or sharing of their personal data through the cookie banner, the Cookie Preferences link present at the bottom of our web page, or submitting a requestion through our Individual Rights Management Portal.

How does your company respond to requests for customer information from governments and law enforcement?

LastPass will not disclose customer information to governments and/or law enforcement unless presented with a valid warrant, subpoena, court order, or equivalent legal process. Each request is considered on a case-by-case basis, and LastPass is committed to responsibly balancing our legal and regulatory obligations with the commitments to promote public safety and user privacy, which may include  attempting to narrow requests that it deems excessively broad, request further clarification if the nature of the investigation is ambiguous, or contest the request for other reasons.

Further, due to our zero-knowledge security model, we do not possess, and cannot obtain, the master password needed to be able to decrypt any encrypted customer vault data. Therefore, we cannot provide such information in response to a government request.

Newsletter Icon

Get Our Best Stories!

Stay Safe With the Latest Security News and Updates


SecurityWatch Newsletter Image

Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.

Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.

By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.

Thanks for signing up!

Your subscription has been confirmed. Keep an eye on your inbox!

LastPass told me that the 6 remaining unencrypted URL-related vault fields will be 100% encrypted by October 2025. These are presumably the same fields that were unencrypted during the 2024 review period. Storing unencrypted vault data on a server in the cloud is a security flaw, so the score remains lowered by a half point.

LastPass’s other answers are in line with the company’s privacy policy. Always browse privacy policies for all apps to learn more about how companies collect, sell, or store your data.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article I dropped my planning app after finding this built-in Obsidian plugin I dropped my planning app after finding this built-in Obsidian plugin
Next Article 4 Ways to Sell or Trade In Your Old iPhone 4 Ways to Sell or Trade In Your Old iPhone
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

How to Get on the Instagram Explore Page in 2025
How to Get on the Instagram Explore Page in 2025
Computing
Bret Taylor’s Sierra reaches 0M ARR in under two years |  News
Bret Taylor’s Sierra reaches $100M ARR in under two years | News
News
Apple May Launch Low-Cost iPhone, iPad, And MacBook In Early 2026, Says Analyst – BGR
Apple May Launch Low-Cost iPhone, iPad, And MacBook In Early 2026, Says Analyst – BGR
News
Former OpenAI executive Zack Kass on rediscovering what it means to be human in the age of AI · TechNode
Former OpenAI executive Zack Kass on rediscovering what it means to be human in the age of AI · TechNode
Computing

You Might also Like

Bret Taylor’s Sierra reaches 0M ARR in under two years |  News
News

Bret Taylor’s Sierra reaches $100M ARR in under two years | News

3 Min Read
Apple May Launch Low-Cost iPhone, iPad, And MacBook In Early 2026, Says Analyst – BGR
News

Apple May Launch Low-Cost iPhone, iPad, And MacBook In Early 2026, Says Analyst – BGR

3 Min Read
Upgrade your movie nights: XGIMI MoGo 4 on sale for the first time
News

Upgrade your movie nights: XGIMI MoGo 4 on sale for the first time

2 Min Read
Exact date two much-loved channels disappear from Sky & Virgin revealed
News

Exact date two much-loved channels disappear from Sky & Virgin revealed

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?