Password managers' promise that they can't see your vaults isn't always true

February 18, 2026
Password managers' promise that they can't see your vaults isn't always true

Here’s something that might surprise you — many password managers claim they can't see your vaults, but that’s not always true. Over the past decade and a half, as Dan Goodin from Ars Technica notes, these tools have gone from niche to essential, with millions relying on them for everything from passwords to crypto keys. Now, here’s where it gets interesting — many of these services advertise a ‘zero knowledge’ system, meaning even they can’t access your data. Companies like Bitwarden, Dashlane, and LastPass make bold promises: they can't read your vaults, even if they wanted to. But according to Goodin, this isn’t entirely accurate. He points out that there’s a difference between encryption and total invisibility. Some technical loopholes or vulnerabilities could, in certain circumstances, give insiders or hackers a way in. So what does this actually mean for you? Be aware that trusting these promises might be riskier than it seems — nothing’s foolproof, even when it’s sold as ‘zero knowledge.’

Over the past 15 years, password managers have grown from a niche security tool used by the technology savvy into an indispensable security tool for the masses, with an estimated 94 million US adults—or roughly 36 percent of them—having adopted them. They store not only passwords for pension, financial, and email accounts, but also cryptocurrency credentials, payment card numbers, and other sensitive data.

All eight of the top password managers have adopted the term “zero knowledge” to describe the complex encryption system they use to protect the data vaults that users store on their servers. The definitions vary slightly from vendor to vendor, but they generally boil down to one bold assurance: that there is no way for malicious insiders or hackers who manage to compromise the cloud infrastructure to steal vaults or data stored in them. These promises make sense, given previous breaches of LastPass and the reasonable expectation that state-level hackers have both the motive and capability to obtain password vaults belonging to high-value targets.

A bold assurance debunked

Typical of these claims are those made by Bitwarden, Dashlane, and LastPass, which together are used by roughly 60 million people. Bitwarden, for example, says that “not even the team at Bitwarden can read your data (even if we wanted to).” Dashlane, meanwhile, says that without a user’s master password, “malicious actors can’t steal the information, even if Dashlane’s servers are compromised.” LastPass says that no one can access the “data stored in your LastPass vault, except you (not even LastPass).”

Read full article

Comments

Audio Transcript

Over the past 15 years, password managers have grown from a niche security tool used by the technology savvy into an indispensable security tool for the masses, with an estimated 94 million US adults—or roughly 36 percent of them—having adopted them. They store not only passwords for pension, financial, and email accounts, but also cryptocurrency credentials, payment card numbers, and other sensitive data.

All eight of the top password managers have adopted the term “zero knowledge” to describe the complex encryption system they use to protect the data vaults that users store on their servers. The definitions vary slightly from vendor to vendor, but they generally boil down to one bold assurance: that there is no way for malicious insiders or hackers who manage to compromise the cloud infrastructure to steal vaults or data stored in them. These promises make sense, given previous breaches of LastPass and the reasonable expectation that state-level hackers have both the motive and capability to obtain password vaults belonging to high-value targets.

A bold assurance debunked

Typical of these claims are those made by Bitwarden, Dashlane, and LastPass, which together are used by roughly 60 million people. Bitwarden, for example, says that “not even the team at Bitwarden can read your data (even if we wanted to).” Dashlane, meanwhile, says that without a user’s master password, “malicious actors can’t steal the information, even if Dashlane’s servers are compromised.” LastPass says that no one can access the “data stored in your LastPass vault, except you (not even LastPass).”

Read full article

Comments

0:00/0:00
Password managers' promise that they can't see your vaults isn't always true | Speasy