Password managers typically encrypt your vault on your device before syncing it. Your master password is used as input to derive key material that can unlock the vault; the provider may store the encrypted data without holding the key needed to read it. The exact design, sign-in process and recovery options vary by service.
How does a password manager encrypt your vault?
- It derives key material from your master password. A password-based key derivation function (KDF) processes the password with a salt and a work factor. The salt helps prevent identical passwords from producing identical derived values; the work factor makes each password guess more expensive to test.
- It encrypts vault data on the client. In an end-to-end design, the app encrypts vault contents on your device before sending them to the provider. The provider syncs the encrypted data, and an authorized client uses the required key material to decrypt it.
- It syncs ciphertext, not necessarily every account detail. Encrypted vault contents are different from account metadata. For example, 1Password notes that information such as an email address may be shared with a service provider.
Services implement these steps differently. Bitwarden says it encrypts and/or hashes data on the local device before sending it to cloud servers, and documents AES-CBC with 256-bit keys and HMAC-SHA-256 for integrity and authentication. 1Password describes end-to-end AES-GCM-256 encryption. These are vendor-specific designs, not a universal recipe for all password managers. Bitwarden: What encryption is used? 1Password security model
What does the master password do?
Your master password supplies secret, memorable input for deriving or unlocking the material that protects the vault. It is not simply copied and used as the entire encryption system. NIST SP 800-132 describes techniques for deriving master keys from passwords or passphrases to protect stored data or data-protection keys. NIST published the guidance in December 2010 and says a revision is planned, so it is foundational guidance rather than a description of current product defaults. NIST SP 800-132
A longer, unique master password makes guessing harder; a KDF adds computational cost to each guess. Neither replaces the other: a high KDF work factor does not make a weak password strong. Raising the work factor can also slow unlocking on older or less powerful devices, so Bitwarden advises testing settings across your devices before increasing them. Bitwarden KDF documentation
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
Can the password manager company see my passwords?
In a correctly implemented end-to-end design, the provider stores encrypted vault data but does not possess the key needed to decrypt the vault contents. That does not mean the provider has no account information, or that every service uses the same architecture. Bitwarden states, “We never store and cannot access your Master Password.” This is Bitwarden’s description of its own system, not an independent guarantee about every provider. Bitwarden encryption documentation
Is signing in the same as decrypting the vault?
No. Login authentication and vault decryption are related in the architecture, but they need not be the same cryptographic operation. Bitwarden documents a master-password hash for account authentication, distinct from its derived encryption key. 1Password documents Secure Remote Password (SRP) authentication and says the account password and Secret Key are not sent over the network. Bitwarden encryption and KDF documentation 1Password security model
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How do Bitwarden and 1Password describe their designs?
| Service | Documented key and encryption details | Authentication or recovery detail |
|---|---|---|
| Bitwarden | Its KDF documentation lists a default client setting of 600,000 PBKDF2-SHA-256 iterations and offers Argon2id as an alternative. Its security white paper describes a 256-bit master key, HKDF stretching, and a generated symmetric key encrypted with AES-256. The paper also describes a separate master-password hash and server-side PBKDF2-SHA-256 with a random salt and 600,000 iterations. These are Bitwarden specifications, not an industry-wide standard. | Its documentation distinguishes the authentication hash from the derived encryption key. |
| 1Password | Its support documentation describes a 128-bit Secret Key generated on the user’s device and combined with the account password to protect data. Its security model describes AES-GCM-256 and PBKDF2-HMAC-SHA256. | It documents SRP authentication and recovery paths for some family and team accounts; the Secret Key itself is not available to the company for recovery. |
The iteration count and Secret Key size above are product-specific details in documentation accessed in 2026. They are not direct comparative security scores, and neither figure alone proves that a service is secure. Bitwarden KDF documentation 1Password security model 1Password Secret Key security
What happens if you forget your master password?
Recovery depends on the provider and account configuration. A design that keeps decryption keys with the user can limit the provider’s ability to restore access simply by resetting a password. Before relying on a manager, read its current recovery instructions and securely store any required recovery materials.
Recommended Free Tools
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
1Password says it cannot recover a user’s Secret Key, which is created on the user’s device. It also documents recovery-code and family or team recovery paths. Its support documentation describes a recovery code as a 256-bit key paired with identity verification; authorized family or team recovery may restore account access and issue new credentials. Availability depends on the account and its setup. About your Secret Key 1Password recovery codes 1Password account recovery
What encryption does not protect against
Encryption protects vault contents while stored and transmitted, but it cannot make an already compromised device safe. Someone who controls your device while the vault is unlocked may be able to view displayed secrets or use the unlocked app. Encryption alone also does not prevent phishing, malware, a weak account password, or unauthorized access to your device.
Rank #4
What should you compare when choosing a password manager?
Do not compare services by a single algorithm name or iteration count. Check their documented design and whether it fits how you use your devices:
- Key design: Does the vault rely on password-derived key material alone, or use an additional secret such as a Secret Key?
- Encryption and integrity: Which algorithms protect vault contents, and how does the service detect tampering?
- KDF and settings: Which KDF is used, can its work factor be adjusted, and do your devices unlock it comfortably?
- Sign-in method: How does account authentication work, and is it distinct from vault decryption?
- Recovery: What happens if you forget the master password or lose a recovery key, and who can authorize recovery?
- Transparency and usability: What technical documentation or audit information is available, and can you reliably unlock the vault on all the devices you use?
These questions help compare documented designs and practical trade-offs; they do not establish a security ranking or predict breach rates.
Quick Recap
Best Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

