CYBER WELFARE

Protect your Digital Privacy

A compromised password vault: what actually happens

The most common objection to password vaults is a reasonable one: “isn’t it dangerous to put everything in one place?”

The honest answer is that yes, a vault concentrates value — and that is exactly why it has to be protected in proportion. But the correct comparison is not between “vault” and “no risk at all”: it is between an encrypted store with a strong key, and dozens of reused passwords scattered across browsers, notes and memory.

This post looks at what would actually be touched in each scenario, using the three aspects by which the security of any information is measured: confidentiality, integrity, availability.

It expands on the recommendation storing passwords safely.

First of all: what “compromised” means

The word covers very different situations, with very different impacts. Telling them apart is the most useful part of this post.

ScenarioWhat happensHow likely
Master password discoveredWhoever knows it can open the vault, if there is no second factorThe most common case
Device compromisedUnwanted software can read the vault while it is unlockedPossible, depends on device hygiene
Provider breachUsers’ encrypted vaults end up in someone else’s handsRare, but it has happened
Vault lost with no recoveryNobody reads anything — but neither do youMore common than people think

The first two depend on you, and they are the ones you can act on. The third depends on the provider — and the crucial point is that, if the master password is strong, a stolen encrypted vault remains very hard to open. The fourth is not an attack at all, but it still produces an impact: we treat it alongside the others because it is the one people run into most often.

1. Confidentiality: who can read what

Confidentiality is the guarantee that information stays readable only to those entitled to it.

A practical example

Your vault is left unlocked on a computer you walk away from in a shared office. Anyone who sits down can see the list of services you use, and copy the credentials.

What the incident looks like

The impact is not limited to the passwords: a vault also contains the list of your accounts. Knowing where you hold an account, which professional tools you use and which platforms you have signed up to is valuable information in itself, even without the passwords.

Some vaults also hold secure notes, documents and recovery keys: everything inside has to be considered exposed at the same moment.

What to watch for

  • the vault turns out to be unlocked when you do not recall opening it;
  • sign-ins to the vault from devices you do not recognise;
  • sync notifications from unusual locations;
  • provider alerts about suspicious access.

What to do

Set the vault to lock automatically after a few minutes of inactivity, not hours. Turn on multi-factor authentication. And treat the master password as the one credential that must not appear anywhere else.

2. Integrity: what can be changed

Integrity is the guarantee that data stays correct and is not altered by anyone without the right to do so.

A practical example

With access to the vault, someone changes the password on one of your accounts and updates it in the vault too. From where you sit everything looks normal — until you try to sign in from a different device.

What the incident looks like

The most insidious alterations are the silent ones: an entry edited, an associated web address changed so that autofill happens on a different site, a secure note replaced. Unlike a deletion, they are not noticed.

This has to be said plainly: these are scenarios that require access to the vault to have been obtained already. They are not the everyday risk of using a vault — they are the reason that access deserves a second factor.

What to watch for

  • vault entries edited when you have not touched them;
  • autofill offering credentials on the wrong sites;
  • a change history containing events you do not recognise;
  • passwords that stop working even though the vault shows them as updated.

What to do

If your vault keeps a change history, look at it now and then. Check periodically that the addresses associated with your entries are the right ones.

3. Availability: being able to get in when you need to

Availability is the guarantee of being able to use your own data at the moment you need it. This is by far the most frequent impact, and it almost never comes from an attack.

A practical example

You change phone. The authenticator app was not transferred, the recovery codes were never saved, and the master password — rarely typed thanks to biometric unlock — is not something you can recall exactly.

Nobody attacked anything. But the vault is out of reach.

What the incident looks like

The effect is immediate and wide: without the vault you have the password to nothing. Recovery goes account by account, starting from your email — which is also in the vault.

For anyone who works with online tools, that means stopping.

What to watch for

  • you cannot recall the master password with certainty, because you only ever use your fingerprint;
  • you do not know where the recovery codes are;
  • the vault exists on one device only, with no sync and no copy;
  • the vault’s authenticator app is installed on a single phone.

What to do

Three measures, all one-off: check that you really do remember the master password by typing it in full every so often; keep the recovery codes outside your phone; make sure the vault is reachable from at least two devices.

AspectMain impactWhat it depends on
ConfidentialityPasswords and account list exposedMaster password, second factor, auto-lock
IntegrityEntries altered without you noticingPeriodic checks, change history
AvailabilityLoss of access to the whole vaultRecovery codes, a copy, remembering the master password

The impacts depend on what you put in there

A credential store does not hold only passwords. And the impact changes a great deal depending on what you have added.

ContentMain impact if exposedNote
Account passwordsConfidentiality, then everything elseThe expected content, and the best protected
The list of services you useConfidentialityValuable even without passwords: it says where to look
Secure notes (codes, PINs, security answers)ConfidentialityOften forgotten: worth reviewing what they contain
Attached documentsConfidentialityCopies of ID documents, if uploaded, are sensitive data
Recovery codes for other servicesConfidentiality and availabilityIf they live only there, they are lost with the vault
Digital wallet keysFinancial, irreversibleThere is no recovery procedure: consider separate custody
Credentials shared with other peopleConfidentiality for third partiesThe impact falls on people who chose nothing

From which a useful rule of thumb: the vault is the right place for passwords, and not necessarily for everything else. Recovery codes and keys that have no restore procedure are worth keeping elsewhere as well — precisely so that two protections do not depend on the same key.

The impacts that fall on other people

A personal vault almost always contains something that concerns someone else.

  • Shared credentials in a family or a work group: if the vault is reached, the access applies to everyone who uses them.
  • Work accounts holding client data: the confidentiality impact extends to people who took no part in choosing the tool.
  • Access to shared services — subscriptions, family cloud storage, an association’s tools: availability disappears for everyone at once.

This is why, when a vault is used by a group, the configuration rules are not an individual choice: the shared folder and the revocation of access have to be handled as a joint decision.

The comparison that actually matters

The “all your eggs in one basket” objection deserves an answer with the right qualitative figures.

Without a vaultWith a well-protected vault
Number of unique passwordsFew, limited by memoryOne per account
Points to protectDozens, scattered and uncountedOne, known and protected
Visibility of weak passwordsNoneAutomatic analysis
Effect of an external breachSpreads to every account sharing that passwordConfined to one service
Effect of the central point being compromised—Serious, but requires beating master password and second factor

A vault does not remove risk: it moves it from many weak, unwatched points to one strong, watched point. That is a trade worth making, on condition that the point really is protected.

The factor that changes everything: the second factor

It is worth isolating, because it is the difference between the two worst scenarios.

With the master password alone, whoever discovers it gets in. With multi-factor authentication enabled on the vault, the password by itself is not enough: the device or the key is needed too.

It is the same logic as recommendation R4, applied to the tool that deserves this protection more than any other.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessWeighing a risk against the real alternatives, not the ideal one
SkillsTelling the four compromise scenarios apart, and knowing which you can act on
Secure BehaviourProtecting the central point with the care its contents deserve

Reference level: FL3 — Autonomous. This is the level at which a tool is adopted not because it is recommended, but because its limits and conditions of use are understood.

Summary

  • Confidentiality covers passwords and the account list: protected by a strong master password, a second factor and auto-lock.
  • Integrity covers silent edits to the vault: checked through the change history and periodic reviews.
  • Availability is the most common impact, and almost never comes from an attack: prevented with recovery codes, a copy, and actually remembering the master password.

One thing to do today. Open your vault’s settings and check two things: that multi-factor authentication is on, and that you know exactly where the recovery codes are. If either is missing, that is your next step.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.