Compared

How BlindLock compares to cloud password managers.

LastPass, 1Password, Bitwarden and Proton Pass are established products built around provider-hosted encrypted vaults. KeePass takes a local-file approach, but does not use BlindLock's built-in steganographic carrier and device binding. BlindLock takes a different approach to both models. Here is what that changes.

Criterion BlindLock LastPass 1Password Bitwarden Proton Pass KeePass
Vault storageWhere your encrypted vault physically lives PNG carrier; separate file-vault containers Cloud Cloud Cloud (self-host possible) Cloud Local only (KDBX file)
Account & loginWhat unlocks the account and vault No vault cloud account — carrier + password + device Email + master password Email + password + Secret Key Email + master password (passkey login available) Proton account (email + password) No account — password/key file
Steganographic vaultVault concealed in an ordinary-looking file (deniability depends on threat model) ✓ — PNG carrier; optional decoy region
Long-term ciphertext riskHarvest-now / decrypt-later exposure if vault ciphertext is bulk-stolen No central vault DB to harvest; at rest: 256-bit authenticated encryption (AES-256-GCM + XChaCha20-Poly1305) Central encrypted vaults can be bulk-stolen offline Central vaults; PQ hybrid TLS on web transport (not vault-at-rest) Central encrypted vaults (self-host possible) Central encrypted vaults Local file only — no provider vault server
Hardware-bound keysKey material anchored in platform security hardware TPM 2.0 / Secure Enclave / Android StrongBox or TEE where available Device-linked (cloud-backed) Device-linked No hardware sealing (KeePassXC: quick unlock only)
Hardware-bound unlockVault key material is sealed to platform security hardware on the authorised device ✓ — sealed to TPM 2.0 / Secure Enclave / mobile hardware root; PIN gates unlock in the app
Central customer-vault databaseWhether the provider stores encrypted customer vaults None — vault contents are never sent to BlindLock Server-side vault Server-side vault Server-side (self-host possible) Server-side vault Local file; no provider vault server
Key derivationWhat a single brute-force guess costs the attacker (time × memory) Argon2id, memory-hard (512 MiB–4 GB by device class) PBKDF2 — not memory-hard, GPU-friendly PBKDF2 + SRP — not memory-hard PBKDF2 (600k) default for many accounts; Argon2id available (~32–64 MiB) bcrypt + SRP — low memory cost per guess KeePassXC: Argon2 (~64 MB default) / KeePass 2.x: AES-KDF by default
Open cryptographic layerWhether crypto primitives or the full app are publicly inspectable libcrux-backed AEAD primitives (verified cores where available); app not open source Closed Closed Open source Partially open Open source
TOTP 2FA built inNo second authenticator app needed Built in — codes stay inside the vault Free plan includes TOTP; advanced/hardware MFA on paid tiers Paid tier (Premium) Paid tier (Plus) KeePass 2.x: third-party plugin required / KeePassXC: built in
Pricing modelOne-time vs. recurring revenue Lifetime desktop licence (pay once; one active desktop; moves to a new PC; iOS & Android always free, for everyone) Subscription Subscription Subscription (free tier) Subscription (free tier) Free (open source)
Public breach historyMajor disclosed vault exposure No central vault service to breach 2022 — encrypted vault backups stolen (~30M reported); cracking linked through 2025 No vault exfiltration No vault exfiltration No vault exfiltration No central provider vault
Available or local advantage Partial or conditional Not available / not applicable

What does a stolen vault file cost to crack?

If someone steals an encrypted vault file, they can try passwords offline on graphics cards. Low-memory methods let them try many passwords at once. High-memory methods force them to go much slower. A strong password still matters either way.

Product Key derivation (typical default) Memory per guess Offline guessing on a GPU
LastPass / 1Password PBKDF2 Very low Many parallel guesses
Bitwarden PBKDF2 or Argon2id (account-dependent) Very low to medium Many parallel guesses on PBKDF2; fewer if Argon2id is enabled
Proton Pass bcrypt Very low Many parallel guesses
KeePass 2.x AES-KDF (default) Very low Many parallel guesses
KeePassXC Argon2 (~64 MB default) Medium Hundreds of parallel guesses on a 24 GB GPU
BlindLock Argon2id (512 MiB–4 GB by device class) High Far fewer parallel guesses; normal unlock also requires the authorised device (recovery is a separate path)

You pay the memory-hard cost once when unlocking. An attacker pays it for every guess. Values above are typical shipping defaults; some products let users raise them. BlindLock’s vault password KDF scales with the device class that created the vault; separate file-vault envelopes stay at the 512 MiB floor.

Three structural differences worth understanding

The matrix above is specific. These are the patterns behind it.

No cloud is not the same as "encrypted cloud"

A zero-knowledge cloud manager still transmits an encrypted vault to provider infrastructure. BlindLock never transmits vault contents to our servers and operates no central customer-vault database or vault cloud account. Licence and version checks remain strictly separate from your secrets.

Long-term ciphertext risk starts today

Encrypted vaults stolen today can be stored and attacked later. BlindLock reduces that exposure by design: there is no central vault database to harvest, and resting vault files use 256-bit authenticated encryption, generally regarded as beyond practical quantum attack for confidentiality under current estimates. That reduces risk; it is not a promise that every future attack is impossible.

Hardware binding keeps a copied file locked

An attacker who obtains a cloud vault can often attack it offline on any machine. With BlindLock, normal unlock needs the carrier file, the password, and the authorised device. Optionally, a security key (YubiKey, Google Titan, or SoloKey) adds a fourth factor. Recovery is a separate, deliberate path.

Context: the LastPass 2022 breach In December 2022 LastPass disclosed theft of encrypted customer vault backups (on the order of ~30 million accounts in later reporting; figures vary by source). In subsequent years, more than $35 million in cryptocurrency theft has been publicly traced to cracking of weak master passwords on those backups; in 2025 U.S. investigators linked a ~$150 million heist to that same class of stolen vault material. The issue was not a break of AES itself, but bulk possession of offline-attackable ciphertext. BlindLock is designed so there is no central customer-vault database of that kind. June 2026: LastPass reported that customer CRM/support data (names, addresses, phones, support cases) — not vaults — was accessed via a supply-chain incident involving Klue (TechCrunch, 23 June 2026). Vaults remained encrypted; personal customer data did not. See also the blog for longer security writing as it is published.

If "local-first, disguised, hardware-bound" sounds like what you actually want…

Lifetime pricing opens soon — phases from €59.

Comparison based on publicly available information and vendor documentation as of 19 July 2026. Competitor features and breach histories change over time — we update this page as we verify changes. This is not legal advice and is not intended as a statement about competitors beyond documented facts.