I am becoming increasingly paranoid about the applications I use - LastPass is a big part of my daily workflow and I really enjoy it.
However after noticing (https://news.ycombinator.com/item?id=6621560) that LastPass' vault is easily broken into when open, even with strict reprompt settings, I'm starting to trust their security model less and less. I opened a support ticket about the obvious password breach detailed above, and they say it's an inevitable consequence of Chrome's broken security model in extensions.
Well, if that model is broken, I don't want to use it. I find it misleading that LastPass even offers a reprompt option, since it is so easy to retrieve passwords from the application when it is logged in, even if a reprompt is required. Sure, it would slow down unsophisticated attackers, but you don't need to be that sophisticated to change the type of an input.
I have been trying to use it with very fast autologout policies but it very annoyingly asks for a password twice (once to login, once as a reprompt) as well as the Yubikey for every single site. The usability is garbage.
I've been looking at 1Password but I was turned off by their lack of meaningful 2FA support (Yubikey), and their exposure of data if used in any sort of convenient fashion (I would like access from my phone, which is part of the reason I want Yubikey support).
What do you use and what do you like/dislike about it?
[1] http://keepass.info/help/base/keys.html