2026 AUDIT

Password Manager Security Matrix & Threat Evaluator

1. Threat Profile CONFIG
2. Master Passphrase Analyzer LOCAL CRYPTO
Shannon Entropy: 94.8 bits
Charset Pool: 94 chars Est. Combinations: 10^28
1x RTX 4090
14,200 Years
8x GPU Cluster
1,775 Years
Cloud Botnet (10k)
1.42 Years
ALGORITHM
Argon2id
ITERATIONS
3
MEMORY
64 MiB
PARALLEL
4
Audited Manager Rankings HIGH PRIVACY INDIVIDUAL
Cryptographic & Operational Spec Matrix 18 METRICS
Manager Encryption Scheme KDF Default Audit Recency Passkey/FIDO2 Open Source Self-Hostable
Bitwarden AES-CBC-256 / AES-GCM Argon2id (3 it, 64MB) Audited 2025/2026 Full Support Yes (GPLv3) Yes (Vaultwarden)
1Password AES-256-GCM + 128b Secret Key PBKDF2 (650k it) / Argon2id Audited 2025 Full Support Proprietary Cloud Only
Proton Pass OpenPGP (ECC Curve25519) / AES-GCM Argon2id Audited 2025 Full Support Yes (GPLv3) Cloud Only
KeePassXC ChaCha20 / AES-256 Argon2id / Argon2d Audited 2024/2025 Hardware Key Yes (GPLv2/v3) Local / Offline
Dashlane AES-256-GCM Argon2id Audited 2025 Full Support Proprietary Cloud Only
Vault Migration & Hardening Planner 5 STEPS

Deterministic step-by-step hardened transition workflow to prevent plaintext leaks and lost MFA tokens:

  • 1. Encrypted Export & Sanitization: Export current vault in JSON/CSV to a RAM-disk or encrypted volume; wipe plaintext artifacts immediately after import.
  • 2. KDF Work-Factor Upgrades: Configure master password key derivation to Argon2id with 3 iterations, 64 MB memory, and 4 threads in vault settings.
  • 3. Passkey & FIDO2 Hardware Re-enrollment: Transfer passkeys and register primary/backup YubiKeys or WebAuthn hardware tokens.
  • 4. Emergency Access & Trusted Contact Setup: Designate encrypted recovery contacts with time-delayed access verification (e.g. 48h delay).
  • 5. Reused Password & Breach Audit: Run the built-in cipher health check to rotate duplicate, weak, and pwned credentials.
Enjoy this tool? Build your own with Super