What “Zero-Knowledge” Password Managers Mean

Explained

What "Zero-Knowledge" Password Manager Claims Actually Mean

Nearly every password manager markets itself as “zero-knowledge,” a term meant to reassure you that not even the provider can read your stored passwords. A 2026 academic study from ETH Zurich’s Applied Cryptography Group, examining Bitwarden, LastPass, and Dashlane, found that this promise doesn’t hold up as completely as the marketing suggests. This isn’t a takedown of password managers, you should still use one, but the gap between the marketing claim and the technical reality is worth understanding before you decide which one to trust.

Key Takeaways

Key takeaways

  • "Zero-knowledge" is a real cryptographic property, not just a marketing word It specifically means the provider’s servers never receive your data in a form they could decrypt, because encryption and decryption happen only on your device.
  • A 2026 ETH Zurich study found real implementation gaps Researchers examined Bitwarden, LastPass and Dashlane and found the servers’ actual security guarantees against a fully malicious server didn’t fully match the zero-knowledge claim in practice.
  • The cryptography itself is sound; the gap is in implementation details AES-256 encryption is table stakes across the industry now, where products actually differ is in server-side architecture, audit transparency, and how consistently zero-knowledge principles are followed end to end.

What "Zero-Knowledge" Is Actually Supposed to Mean

In a genuinely zero-knowledge system, your master password never leaves your device, and it's used locally to derive an encryption key that encrypts your vault before anything is sent to the provider's servers. The provider stores only encrypted data it cannot read, so even if their servers were fully compromised by an attacker, or subject to a legal data request, what an attacker or requester would get is encrypted data, not usable passwords. That's the promise, and it's a meaningful one: it means your security doesn't depend on trusting the provider's staff or their server security in the same way it would for a service that can see your plaintext data.

The practical trade-off users accept for this is real: if you lose your master password, most true zero-knowledge password managers cannot recover your vault for you, because recovering it would require them to be able to decrypt it, which is precisely what zero-knowledge is designed to prevent. That's not a bug; it's the direct consequence of the security model actually working as designed.

An unrecoverable master password is a feature, not a flaw

If a password manager offers to reset your master password and restore your existing vault without you providing any secondary key, that’s worth investigating, it may mean the provider retains more decryption capability than a strict zero-knowledge design would allow.

What the 2026 ETH Zurich Study Actually Found

Researchers Matilda Backendal, Matteo Scarlata, Giovanni Torrisi and Kenneth Paterson, publishing through the Cryptology ePrint Archive and presenting at USENIX Security 2026, examined the actual server-side security architecture of Bitwarden, LastPass and Dashlane against a specifically defined threat model: a fully malicious server. Their finding, in plain terms, is that the zero-knowledge promise, that server compromise poses no risk to customer data because everything is encrypted and unreadable, didn't hold up as completely as the marketing framing implies once you examine the actual cryptographic protocol in detail, not just the high-level claim.

This matters because it's a difference between marketing language and a verified technical claim. It doesn't mean these three products are unsafe for normal use against realistic, non-nation-state threats, the practical risk to an individual user from this specific gap is different from, and generally lower than, the risk of not using a password manager at all, or reusing weak passwords across sites. But it does mean the specific phrase "zero-knowledge" on a pricing page shouldn't be taken as an independently verified, audited guarantee on its own, it's a claim, and claims in security specifically deserve verification, not automatic trust.

How to Actually Verify a Zero-Knowledge Claim

What to look for

What to actually check before trusting a provider's zero-knowledge claim

01
Public, third-party security audits with published results

A provider that publishes full audit reports, not just a badge, is giving you something to actually evaluate.

Look for
The severity breakdown in the audit, zero critical findings is meaningfully different from a report noting a medium-risk cryptographic issue
Avoid
Trusting an unspecified 'independently audited' claim with no published report
02
How recent the audit is

Security architecture and the threat landscape both change; a three-year-old audit tells you less than a current one.

Look for
Audit dates within the last 12-18 months for an actively developed product
Avoid
Treating an old audit as equivalent to ongoing verification
03
Breach history and how it was handled

Whether a provider has been breached, and how transparently they communicated about it, tells you about real-world resilience, not just design intent.

Look for
Clear, timely public disclosure and a documented remediation response
Avoid
A pattern of downplaying or delaying disclosure of past incidents
04
Whether the master password is genuinely unrecoverable by the provider

This is the practical, checkable consequence of true zero-knowledge architecture.

Look for
Explicit confirmation that losing your master password means losing vault access, absent a separate recovery key you control
Avoid
A provider that can simply reset your master password without you controlling a secondary recovery mechanism
05
Open-source code where available

Open-source password managers like Bitwarden allow independent community review of the actual implementation, not just the marketing description.

Look for
A public code repository alongside the audit reports
Avoid
Assuming closed-source products are less secure by default, they simply require more trust in the vendor's own audits

None of this is a reason to stop using a password manager, every credible source on this topic, including the researchers studying these gaps, agrees that a password manager with imperfect zero-knowledge guarantees is still dramatically safer than reusing weak passwords across sites or storing them in a browser without true zero-knowledge architecture at all. The point of understanding this research is to know what to actually check, rather than accepting the phrase "zero-knowledge" as a fully verified guarantee on its own.

Three Providers and Their Current Security Posture

Side-by-side comparison
Security posture snapshot
Open source, community-reviewable
Bitwarden
Long-standing audit track record
1Password
Enterprise/compliance-focused architecture
Keeper
Codebase Open source Closed source Closed source
Published security audits Yes Yes Yes
Included in the 2026 ETH Zurich study scope Not directly studied in this specific paper (Bitwarden, LastPass, Dashlane were) Not in this specific paper's scope Not in this specific paper's scope
Enterprise compliance focus (FedRAMP-track etc.) – – Yes
Best for Users wanting community-reviewable code General users wanting a long audit track record Regulated industries needing compliance-specific controls
Check Price Check Price Check Price

Correction of scope: the specific 2026 ETH Zurich study examined Bitwarden, LastPass and Dashlane, not 1Password or Keeper directly, we've included those two here as commonly recommended alternatives with their own separate audit histories, not because they were part of this specific paper's findings. Always check a provider's own current, dated audit reports rather than relying on any single study covering a subset of the market.

Who Should Weight This Research Most Heavily

Best for
Security-conscious individuals and businesses choosing a password manager Anyone currently relying on browser-saved passwords without true zero-knowledge protection
Not for
Readers looking for a reason to avoid password managers entirely, that's not what this research supports
Pros
  • Using any reputable password manager remains far safer than not using one
  • Published audits and open-source code give real, checkable signals beyond marketing
  • This research pushes the whole industry toward more precise, verifiable claims
Cons
  • “Zero-knowledge” as marketed isn’t always a fully independently verified guarantee
  • Master password recovery limitations are a genuine usability trade-off, not just a security win
  • Audit quality and recency vary meaningfully between providers

Comparing password managers directly

See our full password manager comparison for teams, alongside our wider security software guide.

Our Sources

Methodology

Where this comes from

The core finding in this article is drawn from a real, citable academic source: Backendal, Scarlata, Torrisi and Paterson, “Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers,” Cryptology ePrint Archive, 2026/058, presented at USENIX Security 2026, alongside ETH Zurich’s own public summary of the research. Provider-specific audit and compliance claims were cross-checked against each vendor’s own published security documentation.

  • Primary academic source

    ETH Zurich Applied Cryptography Group study, Cryptology ePrint Archive 2026/058, USENIX Security 2026.

  • Vendor documentation cross-checked

    Audit and compliance claims checked against each provider’s own published security pages, not summarized secondhand.

  • Scope stated explicitly

    We’ve been explicit above about which providers were and weren’t part of the specific 2026 study’s findings, to avoid overstating its scope.

Frequently Asked Questions

Frequently Asked Questions

Frequently asked questions

Should I stop using Bitwarden, LastPass or Dashlane because of this research?

No. The study identifies a gap between marketing claims and a fully verified guarantee under a specific threat model, not a practical vulnerability making these products unsafe for normal use. Any reputable password manager remains far safer than not using one.

What does it mean that a password manager can't recover my master password?

It’s the direct, intended consequence of genuine zero-knowledge architecture, if the provider could recover or reset your master password and restore your existing vault without a separate key you control, they would need decryption capability that contradicts the zero-knowledge design.

How can I check if a password manager's security claims are actually verified?

Look for published, dated third-party audit reports (not just a badge), check the severity of any findings, and check the provider’s history of handling past security incidents transparently.

Is open-source Bitwarden more secure than closed-source options like 1Password or Keeper?

Open-source code allows independent community review, which is a genuine advantage, but it doesn’t automatically mean stronger security, closed-source providers can and do commission independent audits too. Check each provider’s specific, current audit history rather than assuming based on open- versus closed-source alone.

What was LastPass's 2022 breach, and does it relate to this research?

LastPass experienced a 2022 security incident involving compromised employee credentials, which the company argued was a credential-compromise issue rather than an architectural flaw in their zero-knowledge design, a separate matter from this 2026 academic study’s specific findings, though both relate to how thoroughly zero-knowledge claims hold up in practice.

Conclusion

Final take

  • Zero-knowledge means encryption/decryption happens only on your device, in principle
  • 2026 ETH Zurich research found real implementation gaps in three major providers
  • Published, recent, third-party audits are the actual way to verify a provider's claims

“Zero-knowledge” describes a real, meaningful cryptographic property, but 2026 academic research shows the marketing claim doesn’t always match a fully independently verified guarantee once you examine the actual protocol. That’s not a reason to avoid password managers, it’s a reason to check published audit reports, breach history, and recovery-key design yourself rather than accepting the phrase at face value. The cryptography the industry relies on is sound; where providers differ is in implementation rigor and how transparently they let you verify their claims.

Urivio
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart