← All journal posts

Crypto explained

What does “zero knowledge” mean in plain language?

Zero knowledge sounds like a magician's pledge. Throw the slogan out. In a password manager, people usually mean something plainer: the service is designed so it cannot read your saved logins as ordinary text. Picture a locked box you send through the post office. The office can move the box. It is not supposed to hold the key. That picture is useful. It is also incomplete unless you ask what is in the box, who has keys, and what the office still needs to see to deliver the mail.

A locked box, not an invisible person

The post office still sees the address. It still knows a package exists. “Zero knowledge” in product language is rarely a claim that a company knows nothing at all. It is a claim about the contents. The useful version says: saved passwords and private notes are protected so the service stores a sealed record, not a readable list.

That is closer to a locked box than to a disappearing act. You should expect some account information to exist so sync can work: an email address, device records, and operational events. The honest question is which secrets stay sealed, and which facts are needed to run the service.

The problem this solves in a password manager

If a company can open your password list, then so can a stolen support tool, a compelled copy, or a breach of that inner store. A password manager that encrypts on your device before sync is trying to remove that inner store. The readable record is meant to exist on an unlocked device you control, not as a customer file on a server.

The slogan is not enough on its own. Two products can say “zero knowledge” and mean different boundaries. One might encrypt before upload. Another might encrypt only on the wire, then decrypt for features. You need the floor plan, not the poster.

What Stax Pass aims for

Stax Pass is designed to encrypt records on your device before they sync, using XChaCha20-Poly1305, a method that keeps contents private and helps detect if protected data was changed. Password-based protection uses Argon2id, a memory-hard function that turns your password into cryptographic material. Sign-in uses OPAQUE (RFC 9807), a protocol that proves you know your password without making it a reusable server-side secret.

When information is protected for a specific recipient, Stax Pass uses HPKE with X25519 and HKDF-SHA-256—a standard public-key method, a shared-secret operation, and a way to derive separate keys—so the readable copy is bound to the intended person rather than forwarded as a live password. Recovery stays with your password and recovery phrase. Support has no spare key. The security guide states what is meant to stay unreadable and what the service still needs to operate.

Questions worth asking any product

When is data encrypted—before it leaves the device, or only while traveling? Can the provider decrypt saved records for support? What happens if you forget the password? Who holds the recovery material? Does sign-in require the service to store a checkable copy of the password itself?

Clear answers beat a short label. If a company cannot explain recovery without a hidden master, the locked-box picture does not hold. If it explains a real tradeoff—you hold the spare key, and lost-both means the box stays shut—that is a design you can accept or reject with open eyes.

Honest limits

A sealed box does not stop you from opening it in front of the wrong person. Encryption on the device does not stop a phishing page. It does not stop a stolen recovery phrase. It does not hide a password you type into a lookalike site, or a screen that is already unlocked.

It also does not mean the service is a blank. Account email, device approval, and sync metadata can still exist. Treat “zero knowledge” as a starting claim about readable vault contents, then read the details. The phrase is only as good as the design behind it.

Is this worth paying for?

You pay a password manager to hold a sealed box, not to become another company with a copy of your life. Stax Pass encrypts on the device before sync, uses named cryptography, and leaves the spare key with you. Family plans start at $0.99 a month, with a 45-day free trial and no credit card. The price is for that privacy model and for honest limits, not for a magic word on a homepage.

Take this with you

  • In this context, zero knowledge usually means the service is not meant to read your saved passwords as ordinary text.
  • Ask when encryption happens, who holds keys, and how recovery works; a slogan is not a floor plan.
  • A sealed vault still cannot stop phishing or a recovery phrase you hand to someone else.

Common questions

Does zero knowledge mean Stax Pass knows nothing about my account?

No. The service still needs some account and sync information to operate, such as an email address and device records. The design goal is that saved passwords and private notes stay protected so the service does not need the readable contents.

Can support open my vault in an emergency?

No. Support has no spare key. Your password and recovery phrase are the paths to decryption. That is the privacy tradeoff: a company that cannot read the box also cannot open it for you if both secrets are gone.

Is “zero knowledge” a legal guarantee?

Treat it as product language, then read the actual design. Look at the security guide for what is meant to stay unreadable and what remains visible to run the service. Specifics are more useful than the label.