Good Better Best Reviews

LastPass vs. 1Password

GoodBetterBest Reviews··5 min read

LastPass vs. 1Password: What the 2022 Breach Actually Means for You

Comparing LastPass and 1Password today means reckoning honestly with the real 2022 LastPass security incident — not dismissing it, and not overstating it beyond what actually happened.

What Actually Happened to LastPass in 2022

In 2022, attackers compromised LastPass's systems and, in a follow-on incident, gained access to a cloud storage service containing customer encrypted vault backups, along with some unencrypted account and technical data. This is a real, serious incident worth taking seriously. The accurate, complete picture matters: LastPass's zero-knowledge architecture meant the stolen vault data was encrypted, and whether an individual user's actual passwords were practically at risk depended heavily on their master password strength — a strong, unique master password meant the stolen encrypted data remained very difficult to crack even with the attackers in possession of it; a weak or reused master password left that user meaningfully more exposed to offline cracking attempts. This is a more nuanced and more useful takeaway than either "nothing was actually compromised" or "everyone's passwords were instantly exposed" — both oversimplify what happened.

Since the incident, LastPass has stated it strengthened its security practices, including password hashing requirements for accounts. 1Password has not had a comparable publicly disclosed breach of this scale, which is a real, legitimate point in its favor for security-conscious buyers — though "no major breach so far" is a track record, not a permanent guarantee for either company.

Security Architecture

1Password's Secret Key is a genuinely distinctive feature: it's a long, randomly generated string created on your device during setup that combines with your master password to derive your vault's encryption key — meaning an attacker would need both your master password AND your device-specific Secret Key to decrypt your data, even if 1Password's servers were compromised. This is a real, meaningful additional layer beyond a master-password-only model like LastPass's traditional zero-knowledge architecture. The trade-off: losing your Secret Key without a backup (1Password provides an "Emergency Kit" for this) means permanent loss of vault access, since there's no company-side recovery.

Pricing

Both companies price their individual and family/team plans competitively with each other and with the broader market — check both companies' current pricing pages directly for accurate, up-to-date numbers, since specific prices for both change over time and a fixed comparison here would likely be stale. LastPass has historically offered a free tier with device-type restrictions (syncing across device types requiring a paid plan); 1Password does not currently offer an equivalent free tier, generally offering only a free trial period instead. Compare current plan details for both, including team/business features like SSO and provisioning if relevant to your organization.

Features: Passkeys, Travel Mode, and Security Monitoring

Both services support passkeys (FIDO2/WebAuthn) to varying degrees — check each provider's current documentation for platform-specific implementation quality, since this is an actively evolving area across the whole password manager industry. 1Password's Travel Mode (temporarily removing sensitive vaults from your devices, useful when crossing borders) and Watchtower (a security-health dashboard flagging weak, reused, or breached passwords) are both real, genuine 1Password features without an exact equivalent in LastPass's current feature set — worth checking current documentation for both, since feature parity between password managers shifts over time as companies add capabilities.

Migrating Between the Two

Most password managers, including both LastPass and 1Password, support exporting and importing vault data, generally via a CSV or provider-specific format. Shared folders/vaults typically don't map perfectly between different providers' sharing models, so expect to manually recreate shared access for family or team members after a migration — budget real time for this if you have significant shared vault structures, rather than assuming an automatic one-to-one transfer.

Frequently Asked Questions

Is LastPass still safe to use after the 2022 breach? LastPass's zero-knowledge encryption meant the stolen vault backups needed to be cracked to be useful to attackers, and a strong, unique master password provided real protection even in the incident — but the breach is a legitimate, serious mark against LastPass's track record worth weighing, and switching to a service with a cleaner history (like 1Password) is a reasonable response if it matters a lot to you. What makes 1Password's Secret Key different from a standard master password? It's a second, device-generated key that never touches 1Password's servers — an attacker would need both it and your master password to decrypt your vault, a real additional layer beyond password-only protection. Which has better cross-platform support? Both support the major platforms (Windows, macOS, iOS, Android); check each provider's current documentation for the specific quality of Linux support, which has historically varied more between password managers than other platforms.

The Bottom Line

1Password's clean breach history and its genuinely distinctive Secret Key architecture are real, legitimate reasons to prefer it if security track record is your top priority. LastPass's 2022 incident is serious and worth taking into account, though its practical impact on any individual user depended heavily on their master password strength — not a reason to panic, but a real, fair factor in choosing a different provider if you want the strongest track record available. Compare both providers' current pricing and features directly for your specific needs.