What "zero-knowledge" actually means

Every password manager says zero-knowledge. Here is what the phrase means, how to tell when it is true, and how tigerpassword's design earns it — in plain words.

“Zero-knowledge” is on every password manager’s home page, including ours. It is a real idea from cryptography that has been stretched into a marketing phrase, so here is the plain meaning, a way to check whether a product earns it, and what it looks like inside tigerpassword.

The plain meaning

A zero-knowledge password manager is one where the company cannot read your passwords even if it wanted to — not because of a policy, but because it never has the key. Your vault is scrambled on your device with a key made from a secret only you know. What leaves your device (if anything does) is the scrambled version.

That is the whole idea. If the company can reset your master password for you, it is not zero-knowledge. If a support person can “look into your vault”, it is not zero-knowledge. If the company holds the key anywhere, even briefly, it is not zero-knowledge.

Three questions that separate the real thing from the phrase

  1. What happens if I forget my master password? The honest answer for a zero-knowledge product is “your vault is gone unless you kept the recovery material we told you to print.” Any answer that involves the company recovering it for you means they can open it.
  2. Where does the encryption happen? On your device, before anything is sent anywhere. If encryption happens “on our secure servers”, the server saw the plaintext.
  3. Can I read the design? Real zero-knowledge products publish how the key is derived and how the vault is sealed, because the design is the security. Marketing pages are not the design.

How tigerpassword does it

  • Your vault is one encrypted file on your devices. There is no tigerpassword server, so the first question — “what can the company see?” — has the shortest possible answer: nothing, because nothing is sent to us.
  • Two secrets seal it. A key is derived from your master password and a 128-bit Secret Key that is generated on your device and printed on your Recovery Kit. Someone who steals the file, a sync blob or a backup, and even guesses a weak password, still faces the Secret Key.
  • The Secret Key never travels. It is never written into the vault file, never included in a sync payload or backup, never logged, and never placed in a keychain item that syncs. A test in the code base fails the build if any of that changes.
  • Sync sees ciphertext. When you sync through Google Drive, OneDrive, iCloud Drive or a folder, what lands there is encrypted records and a signed manifest. Not a title, not a username, not a key.
  • The design is public. The byte-level specification, the threat model, and the audit scope with each promise mapped to the test that enforces it are in the repository. We wrote them before we wrote this post.

What zero-knowledge does not protect you from

Honesty cuts both ways. Zero-knowledge means the company cannot read your vault. It does not mean:

  • A weak master password is fine. The Secret Key helps enormously against a stolen file, but on your own unlocked computer the password is the door. Use a long one.
  • Your device is safe. Malware on an unlocked device can read what you can read. Keep the operating system updated and lock the app when you step away (tigerpassword does this for you on phones).
  • The software has no bugs. It is why we publish the design, run seventeen fuzz targets against every parser that reads untrusted input, and why the first thing our Kickstarter funds is an independent audit. Until that audit lands, we say plainly: do not store real credentials yet.

The one sentence to remember

If the company could help you recover your vault without your secrets, it could also open it without you. Zero-knowledge means it cannot do either — and the price of that is a piece of paper you keep safe.