💡
23
c/cybersecurity-tips•emmaclarkemmaclark•1mo ago

Switched from a password manager to a hardware token after my LastPass account got flagged

I used LastPass for about 4 years. Felt fine. Then last month I got an email saying someone tried logging in from Russia. Changed my master password but the whole thing just felt off after that. Picked up a YubiKey 5 for $55. Setup took maybe 20 minutes to get it working with my Google and GitHub accounts. A week in and I actually like having to tap the key to get in. Has anyone else moved away from cloud password managers after a close call?
2 comments

Log in to join the discussion

Log In
2 Comments
dakota415
dakota4151mo ago
Bought a YubiKey myself after LastPass left a bad taste in my mouth. Way less paranoid now that I'm not relying on some cloud server to keep my stuff safe.
7
sage_green
sage_green1mo ago
Get the backup key too @dakota415, learned that one the hard way when my first one just stopped working out of nowhere. Now I keep one on my keychain and one hidden at home. Also make sure you have a secondary way to get into your accounts if the key breaks or you lose it. Had to deal with account recovery for a week last time and it was a nightmare.
4