LastPass Android app has some sneaky tracking software hidden away

LastPass
(Image credit: Future)

Keeping track of all the passwords we use daily to access our online accounts and services can be difficult which is why password managers such as LastPass are becoming increasingly popular among both businesses and consumers.

However, a German security researcher named Mike Kuketz is now advising users to avoid using LastPass' Android app due to the fact that it contains seven embedded trackers. While the company says that users can opt out of these trackers, their very existence could induce risks to such a security-critical application.

According to a new report from the non-profit organization Exodus, of the trackers found in the LastPass Android app, four are from Google for analytics and crash reporting while the others are from AppsFlyer, MixPanel and Segment. Segment is particularly concerning because the company gathers data for marketing teams to profile users and connect their activity across different platforms to serve targeted ads.

In his investigation, Kuketz also looked into what data is transmitted by LastPass' Android app by inspecting the network traffic to discover that it sends details about the device being used, the mobile operator, the type of LastPass account and the Google Advertising ID which is able to connect data about a user across different apps.

Tracking in password managers

LastPass wasn't the only password manager examined in Exodus' report and the firm found that 1Password and KeePass contain no trackers while the open source Bitwarden has one for Google Firebase analytical and one for Microsoft Visual Studio crash reporting and Dashlane has four trackers.

Password managers are the simplest and most efficient way for people to avoid reusing the same password across multiple sites and services since many contain password generators which can create strong, complex and unique passwords with the tap of a button.

In a statement to The Register, a spokesperson from LastPass explained that the company uses trackers to improve its own service and that no identifiable user data could be passed on through them, saying:

"No sensitive personally identifiable user data or vault activity could be passed through these trackers. These trackers collect limited aggregated statistical data about how you use LastPass which is used to help us improve and optimize the product. All LastPass users, regardless of browser or device, are given the option to opt-out of these analytics in their LastPass Privacy Settings, located in their account here: Account Settings > Show Advanced Settings > Privacy. We are continuously reviewing our existing processes and working to make them better to comply, and exceed, the requirements of current applicable data protection standards."

Regardless of whether you choose LastPass or a different password manager, investing in such a service can be an excellent way to improve your security posture and avoid falling victim to identity theft.

Via The Register

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Young woman working at a coffee shop with a laptop
Too many passwords, not enough brain space? Here’s how password managers can improve your life
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
LastPass 2022 hack fallout continues with millions of dollars more reportedly stolen
A hand laying out a password
Security attacks on password managers have soared
Man screaming at computer with TechRadar data privacy week logo next to it.
I almost lost my entire online identity – until one tool made all the difference
Young woman holds a smartphone with a beam of light obscuring her eyes
Privacy powerhouses: 5 apps to take your online security to the next level
An abstract image of a lock against a digital background, denoting cybersecurity.
Best password manager of 2025
Latest in Security
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
Latest in News
Nintendo Switch 2
A Nintendo Switch 2 FCC filing confirms Wi-Fi 6 and NFC support for the upcoming console
Google Pixel 8 review Pixel 8 Pro cameras
Is your Google Pixel 9 screen flickering or are the haptics a lot more intense? You aren't alone, and thankfully there's a fix
Motorola Edge 50 Pro lavender
Your next Android bargain? Major Motorola leak teases details of multiple 2025 phones – including the Edge 60 series
Matt Murdock holding a phone to his right ear in a prison in Daredevil: Born Again episode 2
What time is Daredevil: Born Again episode 3 going to be released on Disney+?
A close-up of the PS5 Pro
PS5 Pro games will soon get something 'very similar' to FSR 4 for what Sony is calling 'the next evolution of PSSR'
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI