1. Threat Profile
CONFIG
2. Master Passphrase Analyzer
LOCAL CRYPTO
Shannon Entropy:
94.8 bits
Charset Pool: 94 chars
Est. Combinations: 10^28
1x RTX 4090
14,200 Years
8x GPU Cluster
1,775 Years
Cloud Botnet (10k)
1.42 Years
ALGORITHM
Argon2id
ITERATIONS
3
MEMORY
64 MiB
PARALLEL
4
Audited Manager Rankings
HIGH PRIVACY INDIVIDUAL
Cryptographic & Operational Spec Matrix
18 METRICS
| Manager | Encryption Scheme | KDF Default | Audit Recency | Passkey/FIDO2 | Open Source | Self-Hostable |
|---|---|---|---|---|---|---|
| Bitwarden | AES-CBC-256 / AES-GCM | Argon2id (3 it, 64MB) | Audited 2025/2026 | Full Support | Yes (GPLv3) | Yes (Vaultwarden) |
| 1Password | AES-256-GCM + 128b Secret Key | PBKDF2 (650k it) / Argon2id | Audited 2025 | Full Support | Proprietary | Cloud Only |
| Proton Pass | OpenPGP (ECC Curve25519) / AES-GCM | Argon2id | Audited 2025 | Full Support | Yes (GPLv3) | Cloud Only |
| KeePassXC | ChaCha20 / AES-256 | Argon2id / Argon2d | Audited 2024/2025 | Hardware Key | Yes (GPLv2/v3) | Local / Offline |
| Dashlane | AES-256-GCM | Argon2id | Audited 2025 | Full Support | Proprietary | Cloud Only |
Vault Migration & Hardening Planner
5 STEPS
Deterministic step-by-step hardened transition workflow to prevent plaintext leaks and lost MFA tokens:
-
1. Encrypted Export & Sanitization: Export current vault in JSON/CSV to a RAM-disk or encrypted volume; wipe plaintext artifacts immediately after import.
-
2. KDF Work-Factor Upgrades: Configure master password key derivation to Argon2id with 3 iterations, 64 MB memory, and 4 threads in vault settings.
-
3. Passkey & FIDO2 Hardware Re-enrollment: Transfer passkeys and register primary/backup YubiKeys or WebAuthn hardware tokens.
-
4. Emergency Access & Trusted Contact Setup: Designate encrypted recovery contacts with time-delayed access verification (e.g. 48h delay).
-
5. Reused Password & Breach Audit: Run the built-in cipher health check to rotate duplicate, weak, and pwned credentials.
Report downloaded successfully. Check your browser downloads.