Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Dropbox Passwords: a password manager from a company that holds your file keys

June 2020

LowStatus: HistoricalProduct: Dropbox PasswordsYear: 2020

Dropbox launched a zero-knowledge password manager in 2020, but reviewers and privacy advocates questioned trusting a vault to a company that — for its core product — holds the encryption keys and has a documented history of breaches.

What happened

In June 2020 Dropbox introduced Dropbox Passwords, built on technology from its acquisition of Valt, and marketed it as using zero-knowledge encryption: the master password is used to derive a key stored only on the user's device, so Dropbox says it cannot read stored credentials. Passwords are protected with 256-bit AES, and the server verifies the user without learning the master password.

The scrutiny is one of trust and track record rather than a specific flaw. Reviewers noted the tension that the same company asking users to entrust their entire password vault is the one that, for standard Dropbox storage, holds the keys and decrypts files server-side — and that has suffered the 2012 credential theft (~68 million accounts) and the 2024 Dropbox Sign breach. Analysts also flagged that, as a U.S. provider subject to laws like the CLOUD Act, Dropbox is a less obvious home for highly sensitive secrets than dedicated, independently audited password managers, and questioned the depth of public security auditing of the Passwords product.

The custodial question this entry raised no longer applies to current users: Dropbox fully discontinued Dropbox Passwords on 28 October 2025, after which all stored credentials and payment data were permanently deleted from Dropbox's servers and dark-web monitoring ceased.

Impact

The launch extended Dropbox's reach into a category — secrets management — where trust assumptions are unusually high, and invited the question of whether a company that cannot zero-knowledge-encrypt its main product, and that has been breached, was the right custodian for a password vault. For privacy-conscious users it sharpened the divide between Dropbox's marketing of zero-knowledge for Passwords and its server-side-key model everywhere else.

Dropbox's Response / Official Position

Dropbox stated that Dropbox Passwords used zero-knowledge encryption with AES-256, that the master password and decryption key never left the user's devices in usable form, and that the company therefore could not access stored credentials.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation

Dropbox repeatedly assures users that AI features do not train on their data and that content is deleted within 30 days — but because these are revocable policy promises layered over server-side access rather than technical guarantees, security commentators remain skeptical that the assurances will hold.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)
Read documentation

Through 2025 Dropbox pushed Dash to general availability with self-serve sign-up and no IT required, marketing it as an AI assistant that indexes content across all of a user's connected apps — a model that, by design, reaches far beyond the files stored in Dropbox.

Privacy & Encryption ConcernsProduct Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dash connects to Google Workspace, Microsoft 365, Slack, Notion and more, and routes queries through large language models — leaving users to trust Dropbox's contractual assurances that connected and indexed data is not used to train third-party AI models.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Developer, API & Platform
Read documentation