USENIX Security2026Top-tier venue
Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers
Matteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. Paterson
Abstract
Zero Knowledge Encryption is a term widely used by vendors of cloud-based password managers. Although it has no strict technical meaning, the term conveys the idea that the server, who stores encrypted password vaults on behalf of users, is unable to learn anything about the contents of those vaults. The security claims made by vendors imply that this should hold even if the server is fully malicious. This threat model is justified in practice by the high sensitivity of vault data, which makes password manager servers an attractive target for breaches (as evidenced by a history of attacks). We examine the extent to which security against a fully malicious server holds true for three leading vendors who make the Zero Knowledge Encryption claim: Bitwarden, LastPass and Dashlane. Collectively, they have more than 60 million users and 23% market share. We present 12 distinct attacks against Bitwarden, 7 against LastPass and 6 against Dashlane. The attacks range in severity, from integrity violations of targeted user vaults to the complete compromise of all the vaults associated with an organisation. The majority of the attacks allow recovery of passwords. We have disclosed our findings to the vendors and remediation is underway. Our attacks showcase the importance of considering the malicious server threat model for cloud-based password managers. Despite vendors' attempts to achieve security in this setting, we uncover several common design anti-patterns and cryptographic misconceptions that resulted in vulnerabilities. We discuss possible mitigations and also reflect more broadly on what can be learned from our analysis by developers of end-to-end encrypted systems. Class Ref Name Cause Impact Interaction Mitigations BW01 Malicious Auto-Enrolment Lack of Key Auth,
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 244ba1c6-2c02-41fc-8649-cb1ac21f142cBuilds on14
- On the Practical (In-)Security of 64-bit Block Ciphers: Collision Attacks on HTTP over TLS and OpenVPNKarthikeyan Bhargavan, Gaëtan LeurentCCS 2016 · 180 citations
- Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSHKarthikeyan Bhargavan, Gaëtan LeurentNDSS 2016 · 128 citations
- A Systematic Analysis of the Juniper Dual EC IncidentStephen Checkoway, Jacob Maskiewicz, Christina Garman, Joshua Fried et al.CCS 2016 · 91 citations
- Security Analysis of the WhatsApp End-to-End Encrypted Backup ProtocolGareth T. Davies, Sebastian H. Faller, Kai Gellert, Tobias Handirk et al.CRYPTO 2023 · 29 citations
- Secret Key Recovery in a Global-Scale End-to-End Encryption SystemGraeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman et al.OSDI 2024 · 19 citations
Related papers
- Exploiting Leakage in Password Managers via Injection AttacksAndrés Fábrega, Armin Namavari, Rachit Agarwal, Ben Nassi et al.USENIX Security 2024 · 1 citation
- Vault Raider: Stealthy UI-based Attacks Against Password Managers in Desktop EnvironmentsAndrea Infantino, Mir Masood Ali, Kostas Solomos, Jason PolakisNDSS 2026 · 1 citation
- End-to-End Encrypted Cloud Storage in the Wild: A Broken EcosystemJonas Hofmann, Kien Tuong TruongCCS 2024 · 5 citations
- Security Analysis of Master-Password-Protected Password Management ProtocolsYihe Duan, Ding Wang, Yanduo FuS&P 2025
- Credential Extraction Attacks Against Compromised Credential Checking Services of Password ManagersYihe Duan, Ding Wang, Yutong LiS&P 2026 · 1 citation
