LastPass breach and implications for BitWarden

Your post has a lot of speculation that is not accurate. What you have written above is not true about Bitwarden, and it is not true about LastPass. Also, neither service claim “100% encryption”, they only claim “zero-knowledge”, which essentially means that the encrypted data cannot be decrypted by the company.

This GitHub Gist shows an example of what the user vault data would look like when stored on Bitwarden’s servers — please take a look. There is no server-side encryption of the vault data:

1 Like