NordPass: How A Data Breach Scanner Finds A Password From 2019
A password stops feeling like a risk the moment it's memorized and reused a few times -- which is exactly the moment breach databases start accumulating it under old, unrelated accounts. NordPass's Data Breach Scanner runs every stored login against known leak databases, flagging matches regardless of how old the original breach actually was.
The vault itself sits behind XChaCha20 encryption on a zero-knowledge architecture, meaning not even NordPass can read what's stored inside it, and access runs through Face ID or a fingerprint rather than a typed master password. Password Health checks the same vault for weak or reused credentials sitting alongside anything the breach scanner flags, and Email Masking generates disposable addresses for accounts that don't need a real inbox attached in the first place.
Autofill and autosave remove the manual re-typing that leads to password reuse in the first place, a single Premium plan extends the vault to six accounts for a family, and the whole setup runs on NordVPN's infrastructure, already serving more than eleven million users synced across every device.
None of that explains how many other accounts still matched the password traced back to 2019 -- read the full breakdown here.
Top comments (0)