- No https on site
- Update file hosted via http (not https)
- Downloads via sourceforge which has injected adware in downloads before
- FAQ downplays lack of constant time comparison instead of using constant time comparisons and being extra safe
- You have to cobble together multiple apps from multiple developers to get a full working solution; means you have to trust lots of individual entities
That being said I can hardly defend staying on Lastpass anymore.
I just wish 1Pass was crossplatform so there was a clear universal winner!