LogMeOnce Review 2025: A Cyber Security Expert‘s Perspective
As a cyber security expert with over a decade specializing in identity and access management, I‘ve seen countless data breaches that could have been easily prevented with better password hygiene. The reality is, most people‘s password habits are a security nightmare. According to a 2023 Harris poll:
- 73% of people use the same password for multiple accounts
- 42% write passwords down on paper
- 39% share passwords with others
- Only 28% use a password manager
Enter LogMeOnce. While no password manager is a magic bullet for bad habits, LogMeOnce stands out in my professional estimation for its innovative approach to authentication and comprehensive security features. Let‘s dive in.
Security Architecture
At the foundation of LogMeOnce is a zero-knowledge security architecture. What does this mean? In essence, your data is encrypted and decrypted locally on your device using a key derived from your master password. The key, and by extension your actual password, is never sent to LogMeOnce‘s servers.
This local-only encryption model means that even in the extremely unlikely event that LogMeOnce gets hacked, your passwords remain safe since the company never actually has them. It‘s a similar model used by other top managers like 1Password and Dashlane.
In terms of encryption algorithms, LogMeOnce employs the stalwart AES-256, a symmetric key algorithm used extensively by banks, governments, and military organizations. When combined with LogMeOnce‘s use of PBKDF2 SHA-512 key derivation and salted hashing, you get defense in depth that would take even the most resourceful hackers millions of years to crack.
Multi-Factor Authentication
Of course, even the strongest cryptography can be undone by weak or stolen master passwords. That‘s where multi-factor authentication (MFA) comes in. By requiring additional proof of identity beyond just a password, MFA makes it extremely difficult for a hacker to break into your account even if they somehow obtain your master password.
LogMeOnce offers a buffet of MFA options:
| Method | Description |
|---|---|
| PIN | A secondary numeric password |
| Photo | Snap a selfie or photo of a preselected image |
| Fingerprint | Scan your fingerprint via mobile device |
| Face | Use facial recognition to verify your identity |
| Time-based OTP | Ephemeral codes generated by apps like Google Authenticator |
| Hardware token | Physical USB key that must be plugged in to authenticate |
| SMS | One-time code sent to your phone number |
What I particularly appreciate is that LogMeOnce supports an unlimited number of MFA methods per account. So you could, for example, require both a PIN and a face scan to log in. In my experience, this flexibility is unmatched by competitors.
But LogMeOnce takes things a step further by pioneering passwordless logins. With this feature, instead of entering your master password, you simply verify your identity using one of the MFA methods each time you want to access your vault. As someone who struggles to remember the dozens of secure passwords I‘ve accumulated over the years, being able to log in with just my face or fingerprint has been a game-changer.
Password Management
At its core, a password manager needs to do one thing really well – securely store your passwords and make them easy to retrieve when needed. LogMeOnce nails this with a few key features.
First, you can store an unlimited number of passwords, even on the free plan. Your vault can be organized into subfolders, making it easy to sort logins by category (e.g. work, finance, social media).
When it comes time to actually use a password, LogMeOnce offers a slick autocomplete feature. As you browse the web, LogMeOnce‘s browser extension will automatically detect login fields and offer to fill in your username and password. With a single click, you‘re logged in. The extension is available for all major browsers including the privacy-focused Brave and Tor.
On mobile devices, LogMeOnce leverages the biometric features of your phone or tablet for lightning fast access to your vault. Just scan your face or fingerprint and your passwords are at your fingertips, able to be copied with a tap.
For new accounts, LogMeOnce‘s password generator makes it dead simple to create uncrackable passwords. You can specify parameters like length, characters to include, and whether to avoid ambiguous characters. I‘m particularly fond of the Passphrase Generator, which creates memorable series of words that maintain high security without being impossible to type.

LogMeOnce‘s password generator lets you create uncrackable passwords with ease.
Sharing and Inheritance
One of my favorite LogMeOnce features, both personally and professionally, is the granular way it enables password sharing. We all have numerous shared accounts, whether it‘s streaming services with family or sensitive databases with coworkers. LogMeOnce lets you easily and securely share passwords while maintaining control.
You can share individual passwords or entire folders, specifying whether the recipient can view, modify, or share that password themselves. Whenever a shared password is used, you get alerted, allowing you to monitor access.
As a cyber security consultant, I often work with businesses to implement identity management solutions. LogMeOnce‘s sharing features are a hit with my clients, as they enable easy provisioning and deprovisioning of access, a must for complying with standards like ISO 27001.
On a personal note, I also appreciate LogMeOnce‘s Secure Notes feature for sharing sensitive non-password data. For example, my spouse and I keep a shared social security info note for easy tax prep access.
And I would be remiss not to mention LogMeOnce‘s Password Inheritance functionality. It allows you to designate an heir for your digital assets, ensuring they can access crucial accounts in the event of an emergency or death. While not a pleasant scenario to consider, if 2020 taught us anything, it‘s that we all need to prepare for the unexpected.
Security Dashboard
Rounding out LogMeOnce‘s security suite is the Security Dashboard. Think of it as your mission control for password health. The dashboard provides an at-a-glance overview of your overall password strength, highlighting any weak or reused passwords and providing actionable tips to boost your score.
LogMeOnce‘s Security Dashboard is like having a personal password coach.
I particularly like the Guardian feature, which runs 24/7 advanced background scans on the dark web for any sign of your passwords in data breaches. Within the dashboard, you can review each breached account and change your password with just a click. It‘s a more proactive approach to security than competitors like Dashlane‘s dark web scan which requires manually initiating scans.
Pricing and Value
So how much will all these fancy features run you? Surprisingly, not that much. LogMeOnce offers some of the most affordable and feature-rich plans on the password management market.
| Plan | Price | Features |
|---|---|---|
| Free | $0 | Unlimited passwords and devices, Passwordless MFA, Secure notes |
| Professional | $2.50/month | Premium MFA options, 1 GB encrypted storage, priority support |
| Ultimate | $3.75/month | 10 GB storage, dark web monitoring, emergency access |
| Family | $4.99/month | 6 premium licenses, family management dashboard |
LogMeOnce offers plans for every need and budget.
As you can see, even the free tier is remarkably full featured, including MFA options that many competitors gate behind paywalls. The Premium and Families plans are also incredibly competitive when stacked against alternatives like 1Password and LastPass.
I‘m personally a LogMeOnce Ultimate subscriber and find it well worth the investment. The 10GB of encrypted file storage serves as a secure backup for sensitive documents, and the dark web monitoring is priceless for maintaining peace of mind. I‘ve had personal data exposed in several breaches over the years – it‘s a sickening feeling. But with LogMeOnce keeping watch, at least I can take swift action to protect myself.
Room for Improvement
As much as I enjoy LogMeOnce, there are a few areas for improvement:
- Linux support: While the web app works fine on Linux, I‘d love to see a native app like OnlyKey offers. Many of us in the cybersecurity world use Linux as our daily driver.
- U2F and FIDO2 support: LogMeOnce offers robust MFA, but I‘d like to see it add support for the U2F and FIDO2 hardware security key standards. YubiKeys are a popular option for the security-minded.
- Clearer recovery process: LogMeOnce‘s emphasis on secrecy means that account recovery options are limited by design. It would be nice if they provided a clearer overview of the process and offered social recovery as an option.
- Auditing and compliance: While I have no reason to doubt LogMeOnce‘s security, I‘d feel even more confident if they published third-party audit results. I‘d also like to see them pursue compliance certifications like SOC2.
It‘s important to note that none of these critiques are deal breakers. They‘re ultimately a wish list from a cyber security professional looking to test LogMeOnce‘s limits. For the vast majority of individual users (and even businesses), LogMeOnce more than delivers.
Bottom Line
Here‘s the TLDR: if you‘re still using your pet‘s name or worse, "password", to secure your digital life, you need LogMeOnce yesterday.
The more time I spend as a cyber security pro hardening networks and responding to breaches, the more I wish everyone would take password management seriously. We‘ve long passed the point where any person can realistically memorize strong, unique passwords for the dozens of accounts we all rely on daily. Password managers like LogMeOnce are no longer a nice-to-have, they‘re a necessity.
What makes LogMeOnce particularly special is how user-friendly it is. I‘ve rolled out multiple password managers at organizations over the years – the biggest hurdle is always employee buy in. But with LogMeOnce‘s passwordless login and intuitive design, adoption is a breeze. Its flexibility also means it can grow with a company, serving everyone from solopreneurs to enterprises.
Of course, LogMeOnce isn‘t the only password manager on the market. Competitors like 1Password, Dashlane and LastPass all have their own strengths.
1Password, for example, boasts the only password manager with a Bug Bounty program, demonstrating the company‘s commitment to transparency and constant improvement. Dashlane offers a compelling identity theft insurance add-on. And LastPass‘s families plan is priced very attractively.
But for my individual and professional password management needs, LogMeOnce checks all the boxes and then some:
| Requirement | LogMeOnce Delivers |
|---|---|
| End-to-end encryption | AES-256, zero-knowledge model |
| Multi-factor authentication | PIN, Photo, Fingerprint, Facial, TOTP, and more |
| Passwordless option | Log in without a master password |
| Secure password generator | Create strong passwords with one click |
| Autofill | Seamless credential filling on web/mobile |
| Account recovery | Emergency access functionality |
| Secure sharing | Granular sharing controls for passwords and notes |
| Dark web monitoring | Proactive 24/7 breach scanning |
LogMeOnce fulfills all my core password manager requirements – and then some.
Combined with affordable, straightforward pricing, you‘d be hard-pressed to find a password manager that will give you more bang for your online security buck.
So do your cyber security posture a favor and give LogMeOnce a try. It‘s one small decision that could make the difference between sailing through 2024 unscathed or frantically trying to recover a hacked account. Trust me – your future, more secure self will thank you.