# Threat Modeling Password Managers

DevFeed: [Threat Modeling Password Managers](<https://devfeed.tech/articles/threat-modeling-password-managers-37047.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-modeling-password-managers/>)

Author: Adam

Published: 2017-07-17T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [data](<https://devfeed.tech/tags/data.md>), [dropbox](<https://devfeed.tech/tags/dropbox.md>), [local](<https://devfeed.tech/tags/local.md>), [password](<https://devfeed.tech/tags/password.md>), [password-manager](<https://devfeed.tech/tags/password-manager.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-knowledge](<https://devfeed.tech/tags/zero-knowledge.md>)

## AI overview

This opinion article applies threat modeling to the debate over 1Password's membership and password-storage approach. It compares the risks of local storage with cloud-based storage and discusses trust boundaries, breach assumptions, operational complexity, and zero-knowledge encryption.

## Source excerpt

[no description provided]