← All categories
Password Managers
You gave them every password you own. LastPass proved what happens when that trust is broken.
8 devices analyzed. Set your privacy comfort level to filter.
What we found
LastPass Password Manager: FClaimed 'zero-knowledge' encryption. Hackers stole 25.6 million vaults. URLs, email addresses, and company names were stored unencrypted. $438 million stolen from cracked vaults.
UK ICO fined LastPass GBP 1,228,283 for UK GDPR violations. The breach affected over 1 million UK data subjects. LastPass's own MFA database was also compromised, including authenticator seeds and phone numbers used for two-factor authentication.
Dashlane Password Manager: FDashlane knows your email, IP address, which devices you use, when you log in, and how you use the app.
Dashlane collects: email address, IP address, billing information, device identifiers, usage analytics, and support message records. Their privacy policy states they can 'disclose personal data if it believes it is necessary to protect its rights.' Zero-knowledge applies only to vault contents, not the substantial metadata collected around it.
Apple Passwords (iCloud Keychain): FWithout Advanced Data Protection enabled (which most people haven't), Apple holds the keys to your passwords.
iCloud Keychain syncs passwords via iCloud. Without Advanced Data Protection (ADP) enabled, iCloud backups — which contain Keychain data — are encrypted with keys Apple holds. Apple can and does provide this data to law enforcement. In H1 2024, Apple received 12,812 US account data requests and complied with the majority.
1Password: F1Password records every time you unlock your vault, create an item, or complete onboarding.
1Password added telemetry in 2023 that collects usage data including unlock events, item creation, onboarding completion, device type, and account metadata. For business accounts, telemetry is ON by default and individual employees cannot opt out — only account owners can disable it.
Google Password Manager: DGoogle can read your passwords.
By default, Google Password Manager uses server-side encryption where Google holds the encryption keys. This means Google can technically read your passwords. 'On-device encryption' is available but opt-in and buried in settings. Most of the 3+ billion Chrome users are on the default setting where Google has access.
Bitwarden Password Manager: DMost users never change defaults.
Argon2id is available but not the default — users must manually switch in settings. PBKDF2 is GPU-friendly and significantly weaker against hardware-accelerated attacks compared to Argon2id which is memory-hard. Most users will never change the default.
NordPass Password Manager: DNordVPN has been caught making exaggerated security claims in marketing.
NordPass is owned by Nord Security, which also operates NordVPN — a company with a history of aggressive affiliate marketing and occasionally misleading security claims. While the crypto is strong and Panama jurisdiction is favorable, the parent company's marketing-driven culture raises trust questions for a security product.
How audits work in this category
Common standard: SOC 2 Type II
What it covers: Verifies security controls existed and operated during the audit period. May include availability, confidentiality, privacy criteria if the company opts in.
What it misses: Only security is mandatory — privacy and confidentiality are optional. Can be scoped to specific products. Does not test whether attackers can bypass controls. LastPass held SOC 2 when breached.
Product Auditor Standard Trust signals
1Password FCure53, ISEpen test, pen testSpecialist audit
Bitwarden Password Manager DCure53, Insight Risk Consultingsource code review, SOC 2 Type IISpecialist audit
Dashlane Password Manager FUnknownSOC 2 Type II
LastPass Password Manager FUnknownSOC 2 Type II
Gold standard for this category:
  • Open-source code
  • Zero-knowledge architecture
  • Published security audits (Cure53)
  • Bug bounty programme
Open source, Cure53 audited, SOC 2, bug bounty.
For the auditors' own track record, see Who Audits the Auditors?

Your privacy tolerance