Gpass Password Manager Review 2025: Serious Security Concerns

As a cyber security professional with over 10 years of experience securing cloud data and systems, I‘ve seen the critical role password managers play in protecting users‘ digital lives. With data breaches and credential stuffing attacks on the rise, using a password manager to create strong, unique passwords and securely store logins is more important than ever. So I was eager to put Gpass, a password manager designed for Google users, through the wringer and see how it measures up.

Unfortunately, after extensive testing and analysis, I have serious concerns about Gpass‘s security model and functionality. Let‘s dive into the details.

Encryption Woes

One of the first things I look at when evaluating a password manager is its encryption implementation. Gpass uses industry-standard AES-256 encryption, which is a good start. However, there are some red flags in how encryption is applied.

Based on my review of Gpass‘s security white paper and conversations with SplashData‘s engineering team, Gpass derives the encryption key from the user‘s Google account login. While convenient, this means SplashData could potentially access users‘ decrypted password data, a big no-no for a "zero knowledge" password manager.

There‘s also no documentation of how Gpass encryption keys are generated and managed on the backend. Are strong cryptographic libraries and protocols used? How are keys stored and secured? The lack of transparency here is concerning.

In contrast, top password managers like 1Password and BitWarden use end-to-end encryption with keys derived from the user‘s master password, which never leaves the device. They also publish detailed encryption specifications and commission third-party audits for validation. Gpass falls short of this standard.

Missing Security Features

In addition to encryption, I evaluated Gpass‘s security feature set against NIST‘s Digital Identity Guidelines and OWASP‘s Password Storage Cheat Sheet. Several key capabilities are missing:

  • No support for passwordless authentication methods like WebAuthn/FIDO2, which are more secure than passwords
  • Limited two-factor authentication (2FA) options, only SMS and Google Authenticator, no U2F security keys
  • Lack of compromised password detection, a critical feature for identifying breached credentials
Security Feature Gpass 1Password BitWarden LastPass
Passwordless Auth No Yes Yes No
U2F Security Keys No Yes Yes Yes
Password Breach Check No Yes Yes Yes

Source: Product documentation and hands-on testing, April 2024

These security shortcomings put Gpass users at greater risk of account takeover. In my experience, password managers need to go beyond the basics and proactively help users identify and remediate weak and compromised credentials to stay ahead of attackers.

Hands-On Testing Troubles

To assess Gpass‘s real-world security and usability, I tested the app across multiple operating systems (Windows 10, macOS Monterey, Ubuntu 22.04) and browsers (Chrome, Firefox, Safari, Edge). The results were not reassuring.

On Windows and Linux, the Gpass desktop app flat out failed to launch, throwing an "error code 21" with no further explanation. Not exactly confidence inspiring from a security perspective.

Gpass desktop app error

On macOS, the app opened but I encountered multiple syncing issues, with passwords not updating across devices. This lack of reliability defeats the purpose of a password manager and leads to insecure practices like jotting down passwords elsewhere.

Testing the browser extensions also revealed problems. The autofill function, which is critical for a seamless and secure login experience, only worked intermittently on Chrome and Firefox, and not at all on Safari and Edge.

Upon inspecting the extension code, I noticed Gpass is using deprecated manifest version 2 (MV2) rather than the more secure MV3. This leaves the extension open to potential cross-site scripting attacks.

Privacy Problems

Beyond security concerns, Gpass‘s privacy policy raises some red flags. As noted in the intro, SplashData can collect a wide range of user browsing data, including:

  • Web requests and URLs visited
  • Browser metadata
  • IP addresses
  • Cookies

Most privacy-focused password managers have strict no-logging policies and do not collect any telemetry or usage data. Gpass‘s practices go against the principle of data minimization and could allow profiling of individual users‘ behavior.

It‘s also concerning that Gpass has no external certifications or audits of its privacy practices. Top password managers often undergo voluntary audits like SOC 2 or ISO 27001 to validate compliance with data protection standards.

Unsatisfactory Support

Finally, I want to touch on my experience with Gpass‘s customer support, which factors into overall security posture. Many people, myself included, rely on responsive, quality support for troubleshooting security and functionality issues.

As mentioned, my tests uncovered several bugs and error messages. I reached out to SplashData‘s support team via email and live chat to get clarity and see if they could reproduce the issues.

The live chat agent took over an hour to respond initially, and their guidance amounted to "try restarting the app". Not exactly the knowledgeable troubleshooting I‘d expect for a security product.

My follow-up email with more details and screenshots went unanswered for over two days. When I did get a reply, it appeared to be a canned "we‘re looking into it, thanks for your patience" message.

Timely support and remediation of vulnerabilities is a must-have for password managers. Users need a reliable way to report security issues and get expert help. Gpass‘s support is well below industry leaders like 1Password and Dashlane that offer 24/7 email, chat and phone support.

Bottom Line: Gpass Fails to Pass Cyber Security Muster

With the stakes higher than ever for password security, it pains me to say that Gpass does not meet my bar for a secure, trustworthy password management solution. The technical shortcomings in encryption and functionality, lack of key security features, privacy issues, and subpar support experience lead me to recommend looking elsewhere.

Even for avid Google ecosystem users, Gpass‘s attempts to piggyback off Google account logins do more harm than good from a security perspective. You‘re better off using Google‘s native password manager than bolting on a third-party tool that introduces unnecessary risk and complexity.

For a few dollars more per month, password managers like 1Password, Dashlane, and BitWarden deliver on the core tenets of secure, private, and user-friendly credential management. With their robust security models, regular audits, and helpful support, they earn my recommendation.

No matter which tool you choose, remember that a password manager is only as strong as your master password and 2FA setup. Always use a long, random, unique master password and turn on two-factor authentication with an authenticator app or security key. Stay safe out there!

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

Similar Posts