What Zero-Knowledge Encryption Means for Your Privacy
When you store passwords with an online service, you trust that service to keep your passwords safe, right?But, how much should you trust the online service? Well, the best answer is probably just to trust them as little as possible. That's the thing why zero-knowledge encryption works, which is something that keeps your data private even from the company that you're putting the data in. Below, learn what zero-knowledge encryption is and how it works.
The trust problem
Normally, when you give a company your data, that means you're trusting them to protect your data and you're trusting them to not misuse your data.The problem is that companies can get breached, maybe could make mistakes and sometimes, they might get pressured to handover data and other information. The more information that the company can read, the more things there are to lose if something goes wrong.
Zero-knowledge encryption literally just turns this around. Instead of just asking you to trust the company, zero-knowledge encryption gets rid of the need for any trust at all. The company stores your data, but has no idea what's inside it.
How it works in simple terms
Here’s how it works in basic words: when you use a company with zero- knowledge encryption, your data is encrypted and scrambled so nobody can read it, before it’s even sent to the company you’re using. The only thing that can unscramble your password is your master password, which never leaves your device.
So, the company only receives and only stores the scrambled version of your password. They don’t have your master password, so they can’t see any of your passwords at all. Without your master password, your scrambled passwords mean nothing to the company . Basically, it’s like the company has a box that is locked, which they can’t open.
And, when you want your data and passwords back, your device downloads the scramble version of your password and unscrambles your password with your master password. The unscrambling of your password only happens on your device, and it never happens on the company’s servers. The company can never see your data and passwords unscrambled.
Why this matters for you
Zero-knowledge encryption protects you in a bunch of important ways:
- If the company is breached, hackers can only see scrambled data, which they can’t read at all, because it’s scrambled. Your passwords stay safe, even if the company servers are hacked by hackers.
- The company cannot misuse your data, because they can’t even read your data and passwords.
- The company cannot be forced to hand over readable data, because they can’t even unscramble your data. The company can only give hackers the scrambled version of your passwords, never the unscrambled version of your passwords.
Zero-knowledge encryption is a much better thing than companies just saying " we protect your data.” Zero-knowledge encryption is like saying, " we can’t read your data anyways, so it doesn’t matter whether you trust us or not.”
The one tradeoff
But, there is one bad thing about zero-knowledge encryption, and honesty about it is really importnt. In a real zero-knowledge encryption company, your master password is the only thing that can get your other passwords. if you forget your master password, the company can’t get your data back for you because they never had your master password at all. So, if you lose your master password, you can’t get your passwords back at all.
This is not a bad thing. It’s just a result of the security from zero- knowledge encryption, the same thing that stops hackers and the company from reading your data and passwords also means that nobody can help you if you lose your master password. So, you need to protect and remember your master password really carefully.
How HatePassword uses this
HatePassword is built on zero-knowledge encryption . Your vault is encrypted on your device before it reaches our servers. We never get your master password, and we can’t read your stored passwords. We can’t even open your vault.
That means if our company got hacked, the hackers would only see scrambled data. It means we can’t sell or misuse your passwords and data because we can’t even read it. And, it also means that your passwords and data can be safe with us, even if you don’t trust us, because your data is scrambled to everyone(including us) except for you.
Zero-knowledge encryption is one of the most important things in privacy now. When you want to store something like a password or some of your data online, you should ask yourself: can the companyread my data or passwords? If you use a company with zero-knowledge encryption, no, the company can’t read your data and passwords. This is exactly the thing that keeps your data safe and protected.