LastPass vs 1Password
- Authentication
- 3.5
- 4.0
- SSO & Federation
- 4.0
- 4.0
- Authorization
- 3.0
- 3.0
- Lifecycle & Provisioning
- 3.0
- 3.5
- MFA & Passwordless
- 3.5
- 4.0
- Governance & Audit
- 3.5
- 4.0
- Developer Experience
- 3.0
- 4.5
- Deployment Flexibility
- 3.5
- 3.0
- Pricing Transparency
- 4.0
- 4.0
- Support & Ecosystem
- 3.5
- 4.5
Scored 0–5 against a published rubric. Bold marks the higher score. Independent analysis, no vendor sponsorship.
The honest comparison
Most people reading this page are already on LastPass and deciding whether to move. So this is a migration guide, and it starts with what LastPass published itself rather than with adjectives.
In August 2022, LastPass disclosed that a threat actor had accessed its development environment and taken source code and technical information. In November and December 2022 it disclosed a second, linked incident: using information from the first, the actor reached a third-party cloud storage service and took basic customer account data along with a backup of customer vaults. In LastPass's own notice of the security incident, that backup contained unencrypted fields such as website URLs alongside encrypted fields including usernames, passwords, secure notes, and form-fill data, each protected by a key derived from the user's master password. LastPass cited 100,100 rounds of PBKDF2 at the time; researcher Wladimir Palant documented in December 2022 that many older accounts had been left on far lower counts, commonly 5,000 and in some cases 500 or 1, because the 2018 increase in the default was not applied retroactively. Its published security model now states 600,000 rounds.
What changed since is also on the record. LastPass rebuilt the development environment, rotated credentials and certificates, added logging, alerting, and endpoint detection, separated development from production, and completed its separation from GoTo on 1 May 2024 to run as an independent company.
Our scores are not close: LastPass 3.4 overall against 1Password at 4.5, with 1Password ahead on six of the ten dimensions we grade. LastPass is not beaten everywhere, though. It edges 1Password on deployment flexibility, reflecting client coverage across every major operating system and browser, and the two tie on three dimensions: federation, authorization, and pricing transparency.
When LastPass wins
- You are an existing tenant, the credential rotation is already done, and the migration cost is real work you would rather not repeat
- Admin policies, directory integration, and SSO are configured and running across a mid-market estate
- Client and browser coverage is the binding requirement, which is the one dimension where it out-scores 1Password
- Your risk assessment has been done deliberately and signed off, rather than assumed by inertia
When 1Password wins
- You are making a fresh decision and have no switching cost to defend
- Your security team wants a vendor with no customer-vault exfiltration in its history, and that is a hard filter
- Developer secrets, a command line tool, an SSH agent, and device trust at sign-in are on the requirement list
- You want the higher score on authentication, governance, support, and developer experience, which is most of the matrix
Pricing
Both publish prices and both score 4.0 on pricing transparency, so the decision is not made here. LastPass sells per-user business subscriptions and consumer tiers; 1Password sells per-user tiers with no permanent free option. The cost that actually matters in a migration is not the subscription. Exporting a vault takes an afternoon; re-issuing the credentials that were in it does not. Budget that rotation work explicitly, and model seats in the TCO calculator.
Verdict
If you are choosing from scratch, 1Password is the stronger product on nearly every axis we grade, and the recommendation is not close. If you are an existing LastPass customer, the honest answer is more measured: the tooling is mature, the company has published what it changed, and a planned migration with credential rotation beats a panicked one. What is not defensible is staying without rotating, because the 2022 vault copy is outside everyone's control permanently. For the open-source and self-hosted alternative see 1Password vs Bitwarden, and for how stolen credentials get used afterwards see our teardown on infostealers and session hijacking.
Frequently asked questions
- What happened in the LastPass breach?
- LastPass disclosed two linked incidents in 2022. In August, a threat actor accessed its development environment and took source code and technical information. In November and December, using information obtained in the first incident, the actor reached a third-party cloud storage service and took basic customer account information along with a backup of customer vault data. LastPass stated that the vault backup held unencrypted fields such as website URLs alongside encrypted fields including usernames, passwords, secure notes, and form-filled data, each protected by a key derived from the user's master password. Its own notice of the incident is linked in the body of this comparison.
- Is LastPass safe to use now?
- That is a risk decision rather than a fact anyone can assert for you. LastPass says it decommissioned and rebuilt its development environment, rotated credentials and certificates, added logging, alerting, and endpoint detection, and separated development from production. Its published security model now states 600,000 rounds of PBKDF2-SHA-256, above the 100,100 it cited in 2022, and it completed its separation from GoTo on 1 May 2024 to operate as an independent company. Whether that is sufficient depends on your own risk posture, and many security teams have concluded it is not.
- If I move off LastPass, do I still need to change my passwords?
- Yes. Treat every credential stored before the breach as potentially exposed and rotate the ones that matter, starting with email, banking, cloud consoles, and anything holding recovery codes or cryptocurrency seed phrases. Importing a vault into a new manager does not reduce the exposure, because the copy taken in 2022 is permanently outside anyone's control. Rotation is the only remedy, and because website URLs were in the unencrypted portion of that backup, an attacker knows which sites to try even without breaking the encryption.
Last updated 2026-07-24
Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to [email protected].