News: 1613518065

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

LastPass to limit fans of free password manager to one device type only – computer or mobile – from next month

(2021/02/17)


Password manager LastPass has changed its terms and conditions to limit the free version of its code work on a single device type only per user, seemingly in an effort to force free folks into paying for its service.

In a [1]blog post , the developer's vice president of product management, Dan DeMichele, said the biz needed to “adapt our offerings to keep up with the constantly evolving digital world,” and so from next month will require users of its free service to decide whether to use it on their mobile device, or their computer, but not both.

[2]

The free version of LastPass – which people use to store passwords, notes, credit card details and so on – currently works across devices; a single login will give you access to all the associated data. The same is true for almost all password managers from Bitwarden to 1Password to Dashlane.

Log us out: Private equity snaffles Lastpass owner LogMeIn [3]READ MORE

[4]

But from March 16, users will be required to choose which “active device type” they want to use for the free service. Whichever type of device they log into the service first will be set as the default and users will be able to change their decision three times before it’s locked down. The device types are really two categories: computers, and mobile. So if you go with the computer type, you can continue to use the free version of LastPass with macOS, Windows, Linux, etc, machines, and if you opt for mobile you can use it on iOS, Android, etc.

Thankfully, LastPass hasn’t tried to argue that this split is necessary for technical reasons. It has clearly calculated that free users who access their passwords on both a laptop and their mobile phone are the ones most invested in the service, and so most likely to be willing to pay $3 a month (or $4 a month for the six-user family option).

Market differentiation

The security biz will also be pulling email support from its free service, giving access only to a self-help library, as a way to prod users onto its “premium” service. While the decision is likely to frustrate LastPass users, it makes good business sense: the service is the best on the market for free users and there aren’t a lot of good reasons to shift to the paid-for product. Competitors tend to limit free accounts either by time or number of passwords that can be saved.

The hope, presumably, is that existing users with a large amount of data already stored with LastPass will pay the $36 a year rather than shift it all to a competitor that charges slightly less – BitWarden, for example, is just $10 a year though it has fewer features. The $36 fee matches the current market leader, 1Password, although LastPass is offering a discounted price as part of the transition “for a limited time.” The device-split approach will also allow the company to prod customers in future to “upgrade” their account to have their data accessible across all devices.

[5]

But that is likely to be of little consolation to LastPass users who will have to decide whether to work exclusively off one device type, cough up for a password service, and rebuild their password database with a different service. ®

Get our [6]Tech Resources



[1] https://blog.lastpass.com/2021/02/changes-to-lastpass-free/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCyi6SJben3CLsDwU8sqfAAAAM0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2019/12/18/log_me_in_acquired/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCyi6SJben3CLsDwU8sqfAAAAM0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCyi6SJben3CLsDwU8sqfAAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://whitepapers.theregister.com/

Rebulid?

759b954e-617b-408b-a2b1-f5a42c3688d4

"rebuild their password database with a different service"

Export... import... done. It's really not that hard.

Bitwarden FTW. I switched from Lastpass 2 years ago.

Re: Rebulid?

Snake

Secret:

Any password-saving service that you need to "log on" to is not a security solution. All you're doing is passing your idea of "security management" off to someone else, someone who actually presents a larger footprint as a target for hacking than just doing it yourself. One hack, boom, you plus millions of other users have *all* their passwords comprised.

Just say no. Your passwords should NEVER go beyond your device unless and until YOU ask for it, for local-only backup or import.

moving on

bryces666

I use to pay for their service, but then they doubled the price one year (maybe 6 odd years ago) so I changed to their free service. Now I guess I move to another company. I'm open to hear your recommendations and why.

Classic ploy

steamnut

I think that this is a classic bait and switch ploy. They already know that most users will be using more than one device. The most likely result will be customers moving to another product. How long before they change their mind to allow two devices at least? Did they really think that all of their users would simply cough up?

Re: Classic ploy

Sampler

Probably not all, but a percentage and that's all they care about, it doesn't affect the current paying base, so no revenue lost, so the percentage growth from the free base plus cost saved on the free base that pivot.

I mean, it's a shot in the foot for future customer acquisition in trade off for the gamble of turning some free customers now as people will no longer be recommending the product or trying it before they buy unlike the competitors.

But I suppose the market is small to start with, given it does what Google already does, so you have to be IT literate enough to not trust Google to store your passwords in chrome and CC details in pay, but not literate enough to know password managers are a bad idea (this last bit will probably not win me any friends).

Re: Classic ploy

doublelayer

"so you have to be [...] not literate enough to know password managers are a bad idea (this last bit will probably not win me any friends)."

Care to elaborate? Password managers are juicy targets, and thus they pose a risk to an attacker. Therefore, if you had said something like "Monolithic hosted password managers are a bad idea", I'd be behind you. However, you weren't that clear and if you meant that all password managers are a bad idea, I must disagree. A local password manager means people stop using the same password or multiple weak ones. That's so frequently an avenue for attack that it's probably worth doing something about it. If you have a reason they're a bad idea, you could lay out the details about why so we could debate them or agree and find a solution.

The password version of Evernote

GraXXoR

Evernote has likewise been tightening the noose around its free service for years.

This kind of thing only really works when your software has a niche monopoly, though… since otherwise there are alternatives that offer similar feature sets including, in some cases, open source alternatives.

chris_79

Interestingly enough, as of 2pm AEDST, their online renewal portal is down. Whether it is due to the number of people renewing or otherwise. This instills so much confidence in me to continue my service, it really does...

hoopsa

Well I suppose they have to make money somehow, although I must admit I was a bit startled to read about the way they're doing it this morning.

I've been using Lastpass for a good number of years now. I'm sure that I used to pay for the ability to use it on more than one computer back in the old days.

Having said that, it feels like a matter of principle to move when they break existing functionality and force you to pay to get it back, even though it's not a huge amount of money.

Maybe I'll check out Bitwarden, unless anyone has other suggestions.

Alternatives

sansva

Install f-droid and search for "password manager". The top two entries (according to most recently updated) are NC Password which interfaces with Nextcloud Passwords "Passwords is the most advanced password manager for Nextcloud and allows you to manage and store your passwords safely in your own cloud."

The other is KeePassDX which works with KeePass-format password entries, so you could use it with KeePass on your desktop. "KeePass is a free open source password manager, which helps you to manage your passwords in a secure way."

Life is like a sewer. What you get out of it depends on what you put into it.
-- Tom Lehrer