Dashlane
AES-256-CBC + HMAC, Argon2d
Published September 7, 2026· By Juan Martinez
In This Article
Dashlane is a fixture of “best password manager” roundups and sells itself as the polished, premium option. The engineering underneath is genuinely modern in places — Argon2 key derivation, every vault field encrypted, a device-binding key that is separate from the encryption key. But the last year has been rough: Dashlane closed its free plan entirely, patched a cryptography-downgrade flaw found by academic researchers, and disclosed a brute-force attack in which a small number of customers had their encrypted vaults downloaded. This review weighs the product as it stands after all of that.
Security
Dashlane encrypts your vault on your device before it syncs. The cipher is AES-256 in CBC mode paired with HMAC-SHA256 — an encrypt-then-MAC construction, so tampering with the stored ciphertext is detectable rather than silent. The key comes from your master password via Argon2d (3 iterations, 32 MB of memory, 2 threads), a memory-hard function that is meaningfully harder to attack with GPUs than the PBKDF2 that some competitors still use by default. PBKDF2 lingers only as a fallback for old clients, which Dashlane says it will drop in 2026. Your master password is never sent to the server; a protocol called OPAQUE lets the client prove it knows the password without revealing it.
Two things set the architecture apart. Every field in a vault entry is encrypted — usernames, item URLs, notes — not just the password, so the server cannot see which services you hold accounts with. And authentication is decoupled from encryption: each device gets a server-issued 40-byte Device Key that is stored locally, so stealing a master password is not enough to pull a vault without also controlling an authorized device. Turning on login 2FA adds a server-held User Secondary Key that is XOR-ed into the key material and released only after the second factor checks out.
The weak spots are real, though. CBC-with-HMAC is a sound construction but it is not a native authenticated mode like AES-GCM or XChaCha20-Poly1305, which is where most of this category has moved. In November 2025 Dashlane removed support for a legacy “CBC-only” path after ETH Zurich researchers showed that, against a fully compromised server, an attacker could inject a forged settings item and downgrade a vault’s cryptography — a slow attack (the researchers estimated a minimum of ~126 days) that required server compromise, but a flaw in shipped code nonetheless. Dashlane credited the researchers and says it has hardened further.
Vault unlock 2FA is the other gap: it is a TOTP authenticator app only. Dashlane does not accept a hardware security key as a login second factor — a FIDO2 key can only stand in for the master password as a passwordless unlock method. Several competitors let you bolt a YubiKey onto the login as an extra factor; Dashlane does not.
The 2026 brute-force incident
Starting 31 May 2026, an attacker ran a high-volume brute-force campaign against Dashlane’s device-registration endpoint. To add a new device, Dashlane sends a 6-digit one-time token — to your email, or from your authenticator app if 2FA is on — and registering the device then downloads a copy of the encrypted vault. The attacker automated guesses against that 6-digit token fast enough to hit valid values for fewer than 20 personal-plan accounts before Dashlane’s automated lockouts and network filtering shut the campaign down. Those accounts had a new device registered and their encrypted vaults downloaded.
What was not exposed: master passwords, which Dashlane never stores, and therefore the plaintext contents of those vaults — decrypting them still requires brute-forcing each user’s master password against the Argon2 + AES-256 stack. Dashlane found no evidence its internal systems were touched, notified every affected user directly, and published an advisory the next day, 1 June, with a detailed technical follow-up on 4 June and a hardening update on 3 September (extra verification layers on device registration, anti-enumeration protections on active endpoints, and upgraded cryptographic flows).
This belongs in the record because user vault data left Dashlane’s control. It is also, in scale and in disclosure, the opposite of the worst-case: a handful of accounts, no metadata dump, encryption intact, and a same-day public account. The honest read is that a security control — a guessable 6-digit token with insufficient rate limiting on that endpoint — failed and was exploited, and Dashlane fixed it in the open.
Privacy & Trust
Dashlane publishes the source for three of its clients — iOS, Android and the web extension — on GitHub. That is more than a fully closed manager offers, but it comes with caveats: the licence is Creative Commons Attribution-NonCommercial (a content licence, not an open-source software licence), the repositories are not buildable projects, updates land as occasional code drops rather than a live mirror, and the server and desktop apps are closed. It is source-available for inspection, not open source.
There is no published independent security audit. Dashlane says accredited third parties run annual penetration tests, but only a summary is available, and only to enterprise customers under NDA through its Trust Center — no auditor is named publicly and no report, gated or open, can be read. It holds SOC 2 Type II and ISO 27001 certifications and runs a long-standing bug-bounty program (now on Intigriti). Certifications and bounties are worth something; they are not a substitute for a named cryptographer publishing a review. The most substantive external scrutiny on the public record is the ETH Zurich paper, which Dashlane engaged with constructively.
On ownership, Dashlane is straightforward: an independent, venture-backed company (Dashlane, Inc., with the trademarks held by Dashlane SAS in France), last funded by a Sequoia-led round in 2019, never acquired, headquartered in New York and Paris. Vault data is hosted in AWS’s EU-West region by default. Dashlane collects adjustable diagnostic telemetry but does not publish a breakdown of exactly what the clients send, so the reading here is that data is gathered and can be turned off rather than absent by default.
Features
The paid product is broad. You get Dark Web Monitoring, a Password Health dashboard that flags weak and reused credentials, one-to-many secure sharing, a built-in TOTP generator with autofill, 1 GB of encrypted file storage, real-time phishing and AI “scam” alerts, and a bundled VPN (built on Hotspot Shield technology). Passkeys are stored and autofilled alongside passwords — Dashlane was early to in-browser passkey support — and there is a passwordless login option for the client itself. The Friends & Family plan organizes up to 10 members under one subscription.
The gap worth calling out is email aliasing: there is no built-in alias generator and no integration with an alias service, a privacy feature that several competitors now ship. Dashlane also retired its automatic password-changer feature, so bulk rotation is manual.
None of this is available for free — the trial aside, there is no free tier to sample it on.
Usability & Platforms
Onboarding is easy, import options are broad, and autofill is generally dependable — this is the part of Dashlane that earns the “polished” label. But the platform coverage has a hole: since the 2022 move to a “web-first” model, there is no native desktop app for Windows or Linux. On those systems, and on ChromeOS, Dashlane is the browser extension plus a web app, with a native app only on macOS (plus iOS and Android). Offline access works, but if you want a standalone desktop client on Windows, Dashlane no longer has one.
Reputation is mixed. Dashlane’s Trustpilot score sits at 2.8 across several thousand reviews, with recurring complaints about auto-renewal billing, cancellation friction and support responsiveness — themes that also run through Reddit discussion. The product works well day to day; the friction users describe is mostly around the subscription, not the vault.
Price & Value
Premium is $4.99 a month billed annually ($59.88/year) at the standard rate; Friends & Family is $7.49 a month ($89.88/year) for 10 members. Dashlane’s own page often shows a lower promotional figure, but the annual rate above is the steady-state number to plan on. That makes Premium one of the most expensive individual plans in this category — well above the open-source options and the mid-market incumbents — and with the free plan gone as of September 2025, there is no longer a no-cost tier to fall back to. The bundled VPN and the family per-seat price add some value back, but for a single user paying for a password manager, Dashlane is at the top end of the range.
Pros
- Argon2d key derivation and full-record encryption — usernames, URLs and notes are all encrypted, not just passwords
- Encryption is decoupled from device authentication, so a stolen master password alone cannot pull a vault
- Source for the iOS, Android and web-extension clients is published for inspection
- Independent, venture-backed company with a clear ownership history and no acquisition
- Broad paid feature set: Dark Web Monitoring, Password Health, secure sharing, built-in TOTP, passkey storage, bundled VPN
- Responded to the 2026 incident and the ETH Zurich findings quickly and in public
Cons
- In 2026 an attacker brute-forced device-registration tokens and downloaded the encrypted vaults of fewer than 20 users; master passwords were not exposed, but user vault data left Dashlane’s control
- No published independent security audit — only NDA-gated pentest summaries and compliance certificates
- Source-available under a non-commercial licence, not open source; server and desktop apps are closed
- AES-CBC-with-HMAC rather than a native authenticated mode, and a legacy CBC-only downgrade path had to be removed in late 2025
- Vault 2FA is TOTP-only — no hardware security key as a login second factor
- No free tier since September 2025; Premium is among the priciest individual plans in the category
- No native desktop app for Windows or Linux; no built-in email aliasing
Our Rating
| Category | Score | Notes |
|---|---|---|
| Security | 7.5/10 | Argon2d key derivation, encrypt-then-MAC AES-256, every vault field encrypted, and encryption separated from device authentication. Held back by CBC-with-HMAC rather than a native AEAD mode, a legacy downgrade path removed only in late 2025, TOTP-only vault 2FA with no hardware-key option, and a device-registration token that proved brute-forceable — and was exploited — in 2026 |
| Privacy & Trust | 6.5/10 | Three clients are source-available and the company is independent with a clean ownership history, but the licence is non-commercial rather than open source, the server is closed, and there is no published independent audit — only NDA-gated pentest summaries and compliance certificates. The 2026 incident was small and disclosed within a day |
| Features | 8.5/10 | Dark Web Monitoring, Password Health, secure sharing, built-in TOTP, passkey storage, bundled VPN and a 10-member family plan — a complete paid set, minus email aliasing and an automatic password changer |
| Usability & Platforms | 7.0/10 | Easy onboarding and dependable autofill, native apps on macOS, iOS and Android — but there is no native desktop app on either Windows or Linux (both are extension-and-web-app only), and Trustpilot reviews flag persistent billing and support friction |
| Price & Value | 5.5/10 | Standard Premium is $4.99/mo billed annually — one of the priciest individual plans in the category — and there has been no free tier since September 2025. The family per-seat price and bundled VPN claw back some value |
| Overall | 7.2/10 | Security 30% · Privacy & Trust 25% · Features 20% · Usability 15% · Price 10% |
Dashlane is a capable, feature-rich manager with a modern cryptographic core and a company that has handled bad news openly. What keeps it out of the top tier is a combination of things a security-focused buyer will weigh: no independent audit anyone outside the company can read, a source-available-but-not-open licence, a recent incident in which encrypted vaults were exfiltrated, and a price at the top of the market with no free plan to test on. If you are already invested in Dashlane and using a strong master password, none of this is a reason to leave in a hurry. If you are choosing now, the open and audited alternatives cost less and ask you to take less on trust.
Rating: 7.2/10