Skip to main content

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

Password manager Dashlane now integrates with Intel SGX for hardware security

Password manager Dashlane has announced a new partnership with Intel that will see Dashlane use Intel’s SGX for added hardware-based security.

According to the company, the collaboration allows users to “seal” their data to their devices to avoid tampering.

Recommended Videos

Intel SGX (Software Guard Extensions) is built into Intel Core processors, which allows developers to use CPU-based capabilities for safeguarding data from attack by storing data in an “enclave” on the device. For example authentication info can be stored and used on a PC instead of being transferred to a server for verification.

“On top of encrypting user data with a key derived from the user’s master password, we add another round of encryption using a key stored inside the SGX enclave,” said Frederic Rivain, vice president of engineering at Dashlane. “Note that this is our V1 of using SGX, and we will probably evolve it in the future to use it even more.”

The combination of software and hardware provides greater protection for your passwords and accounts, the companies said. Users access their accounts via a master key password (Dashlane says this is not stored on its services), which unlocks their data stored locally on the device and cannot be altered even if exported to another device. The data is encrypted with AES-256 encryption.

“The new Intel Core processors provide a powerful new way to protect your passwords,” Dashlane CEO Emmanuel Schalit added. “Dashlane is taking full advantage of Intel’s built-in hardware security to make our users’ passwords safer than ever.”

Password managers are a convenient way of securing accounts without having to remember dozens of different passwords for each account. But like any software, they can be vulnerable to bugs as well, like LastPass last year which had a vulnerability that allowed hackers to delete passwords. This has pushed password managers like Dashlane to explore new techniques to reduce the chances of breach or hacking.

Jonathan Keane
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
LastPass reveals how it got hacked — and it’s not good news
A depiction of a hacker breaking into a system via the use of code.

Last year was a particularly bad one for password manager LastPass, as a series of hacking incidents revealed some serious weaknesses in its supposedly rock-solid security. Now, we know exactly how those attacks went down -- and the facts are pretty breathtaking.

It all began in August 2022, when LastPass revealed that a threat actor had stolen the app’s source code. In a second, subsequent attack, the hacker combined this data with information found in a separate data breach, then exploited a weakness in a remote-access app used by LastPass employees. That allowed them to install a keylogger onto the computer of a senior engineer at the company.

Read more
Hackers dug deep in the massive LastPass security breach
The LastPass logo appears in front of a menacing hooded figure.

The cybersecurity breach that LastPass owner GoTo reported in November 2022 keeps getting worse as new details are revealed, calling into question the company's transparency on this serious issue.

It has been two months since GoTo shared the alarming news that hackers stole the usernames, passwords, email addresses, phone numbers, IP addresses, and even billing information of LastPass users. In GoTo's latest blog update, the company reported that several of its other products were compromised as well.

Read more
Using LastPass? You need to switch urgently, says security firm
A dark mystery hand typing on a laptop computer at night.

It’s a good idea to use one of the best password managers to keep your logins safe, but now a security company is warning that one of the most popular password managers in the world is not safe to use.

The extraordinary claim comes from Intego, a firm that specializes in Mac security. Intego made its assertion based on a series of security breaches LastPass has suffered in recent months, the way LastPass has responded to those incidents, and the underlying technology LastPass uses to protect customer accounts.

Read more