Popular password manager LastPass to be spun out from LogMeIn
- Reference: 1639501866
- News link: https://www.theregister.co.uk/2021/12/14/lastpass_spinout/
- Source link:
"The success we've seen across the entire LogMeIn portfolio over the last 18 months proves there is a vast growth opportunity ahead for both LastPass and LogMeIn," said Andrew Kowal, a partner at Francisco Partners.
Francisco Partners, a private equity business, [1]bought the bundle of remote access, collab and password manager tools – which also includes [2]Citrix's GoTo business – in 2019 for $4.3bn.
[3]
"The substantial scale of LastPass, its tremendous growth, and its market leading position and brand makes it a perfect candidate to seize new opportunities as its own standalone company," said Bill Wagner, CEO and prez of LogMeIn, in a canned statement.
[4]
[5]
LogMeIn itself [6]bought lastPass in 2015 .
The "global shift to remote working has also fueled the adoption of new accounts and applications," said LogMeIn. It added that "50 per cent of people in the 2021 Psychology of Passwords research reported twice the number of accounts today, compared to pre-pandemic levels," raising the question of why it wouldn't expose any of its own customer growth numbers in the release.
[7]
In 2018, the then-public LogMeIn made revenues of $1.2bn and profits of $446m. The private firm [8]said today it made "over $1.3bn in annual revenue" in 2021 and that LastPass had managed a "50 per cent compound annual growth rate" over the last three years.
LogMeIn's competition includes Bitwarden, 1Password, Dashlane, Keeper, NordPass and open-source password manager [9]KeePass .
According to the [10]press statement , LogMeIn has 2 million "customers" and 30 million users, many of whom will be on its freemium tier.
[11]1Password unsheathes Rusty key, hopes to unlock Linux Desktop world
[12]1Password has none, KeePass has none... So why are there seven embedded trackers in the LastPass Android app?
[13]Log right in, the water's fine, whispers Microsoft as it adds autofill to Authenticator app
[14]Log4j RCE latest: In case you hadn't noticed, this is Really Very Bad, exploited in the wild, needs urgent patching
LogMeIn said today it planned to "increase investment in the customer experience" for the new standalone business and said customers would see "planned enhancements on an accelerated timeline in 2022, with the benefit of additional dedicated LastPass resources."
In [15]February this year LogMeIn tried to heave some of those freemium fans onto paid plans by limiting them to one device type only: computer or mobile. How did that go? According to today's announcement, "the significant majority" of its business is corporate customers.
[16]
Also in February, LastPass came in for criticism after a security researcher recommended against the password manager's Android app after noting [17]seven embedded trackers in the software. LogMeIn said at the time that users can opt out if they want.
El Reg today spotted Apache's Log4j 2.x – vulnerable to a remote code execution hole [18]CVE-2021-44228 among [19]Lastpass's list of third party software licences . LastPass told The Reg it had released a patch for the [20]vulnerability for "impacted customers."
Version 2.15 of Log4j was released with part of the exploitable functionality disabled by default last week; version 2.16 is also out that completely kills off the insecure feature by default. ®
Get our [21]Tech Resources
[1] https://www.theregister.com/2019/12/18/log_me_in_acquired/
[2] https://www.theregister.com/2016/07/26/citrix_logmein_goto/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YbkiH@UA72V-Uozqdy9CdgAAAJM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbkiH@UA72V-Uozqdy9CdgAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbkiH@UA72V-Uozqdy9CdgAAAJM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2015/10/09/logmein_gobbles_lastpass/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbkiH@UA72V-Uozqdy9CdgAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.sec.gov/Archives/edgar/data/1420302/000156459019003676/logm-10k_20181231.htm
[9] https://sourceforge.net/projects/keepass/
[10] https://www.logmein.com/newsroom/press-release/2021/logmein-set-to-establish-lastpass-as-an-independent-cloud-security-company-amid-strong-market-demand
[11] https://www.theregister.com/2021/05/18/1password/
[12] https://www.theregister.com/2021/02/25/lastpass_android_trackers_found/
[13] https://www.theregister.com/2020/12/16/authenticator_autofill/
[14] https://www.theregister.com/2021/12/13/log4j_rce_latest/
[15] https://www.theregister.com/2021/02/16/lastpass_pricing_changes/
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbkiH@UA72V-Uozqdy9CdgAAAJM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://www.theregister.com/2021/02/25/lastpass_android_trackers_found/
[18] https://logging.apache.org/log4j/2.x/security.html
[19] https://lastpass.com/docs/licenses.php
[20] https://www.theregister.com/2021/12/10/log4j_remote_code_execution_vuln_patch_issued/
[21] https://whitepapers.theregister.com/
There is a lot to be said for keeping your passwords locally.
Also in February, LastPass came in for criticism after a security researcher recommended against the password manager's Android app after noting seven embedded trackers in the software. LogMeIn said at the time that users can opt out if they want.
My personal choice is to use Passwordsafe (the pwsafe.org version) because:
a) it is open source so no security by obscurity
b) passwords are still encrypted even while in memory and only decoded individually for display/copy-paste
c) support for all OSes, not just Win & iOS
d) you can choose where to store your data - Mine is on a pair of USB sticks (one on my keyring, the other in a locked drawer for backup.)
e) no ongoing costs, or any costs for that matter.
People still use Lastpass?
I use both 1Password and Dashlane (personal and company stuff) and tried out Lastpass - it was truly awful. Though I (and the company) were willing to pay so is Lastpass the best you can hope for for cheapskates?
Re: People still use Lastpass?
The user experience is only one consideration.
Some others are:
- the encryption / decryption are done locally
- the ability and ease to hook into the company's authentication system, e.g. LDAP or some other SSO
- where the passwords are stored if the company is not based in the U.S.
- the ability to set and enforce rules on managed office laptops / desktops to prevent the user from storing company passwords in their private password manager or vice-versa
Lastpass ticks a few boxes that not all the others do, which is why a company might select it.
Re: People still use Lastpass?
I stopped using it when they started charging for more than one device - I use Bitwarden now.
Embedded trackers
Work has a subscription to LastPass, so I'm sort of stuck with it (although I use Bitwarden in my own life). One thing that is noticeable from the LastPass Firefox add-on (possibly the same for other browsers) is that it looks like whenever the add-on gets updated or signed out, you have to make sure to go into a hidden by default section of the login panel to disable the tracking spyware yet again (which, for obscure evil reasons is enabled by default, rather than disabled by default, as it should be «sigh»).
Re: Embedded trackers
LastPass is far from the only ones to remember some config and conveniently forget some other config. I view this as a handy "Replace Me!" alert, albeit I do have to manually initiate some sort of audit to trigger the alert. Thanks to the helpful manglement decisions, I don't have to audit the source code, the config dialog usually shows me what I need to know. No privacy settings? Extra hurdles for privacy settings? Placebo privacy settings? Forgotten privacy settings? Bye bye.
XMarks
My first negative experience with LastPass was when they killed XMarks, the only usable cross-platform, cross-browser bookmark sync tool at the time – not long after I had let myself being lured into LastPass only because I already used and liked XMarks. When the other negatives mentioned in the article came up, I moved to a self-hosted Bitwarden setup and have never looked back. I wonder how well the LastPass business actually has been doing.
LogMeIn said today it planned to "increase investment in the customer experience" for the new standalone business and said customers would see "planned enhancements on an accelerated timeline in 2022
Oh dear. My experience is just fine as it is, thanks. And does this mean we should expect more useless chuff and unwanted intrusions?
KeePassXC FTW!
keepassxc all the way
keepassxc all the way!
Log4j version 2.15 vulnerable to CVE-2021-45046
"Version 2.15 of Log4j was released with the exploitable functionality disabled by default last week."
Unfortunately version 2.15 is not enough. Last night version 2.16 was released as 2.15 opens you up to CVE-2021-45046. Albeit a score of 3.7, it still is something people should know about
Re: Log4j version 2.15 vulnerable to CVE-2021-45046
Yeah, we're just about to run an update on it.
C.
Ah bon‽
The marketing drivel is real, a cynical mind might think there are unmentioned reasons why they would want to get rid of it, perhaps related to earnings and future potential - considering all the competition.
Like many I'm enjoying the free tier of Bitwarden, which is open source and 3rd party audited, as I'm sure everybody here knows already. However, I discovered the paid personal plan is $10/yr, that's not much for supporting them.