Master password
The master password is the only thing that opens your vault. It is never stored or transmitted. Everything derived from it is computed on your device.
What happens to it
- The text is normalized (Unicode NFKC) so that the same password typed on two keyboards yields the same key.
- Argon2id turns it into the master key: 64 MiB of memory, 3 passes, 4 threads. This computation deliberately takes a moment, to make brute force expensive.
- Two subkeys are derived from it with HKDF: the authentication key, sent to the server in Cloud mode as an account password, and the wrap key, which seals the vault key and never leaves the device.
Neither subkey can be used to recover the password or the other subkey.
Choosing a good password
The application requires at least 60 bits of entropy and shows a gauge while you type. A few guidelines:
- Four or five unrelated words separated by spaces: easy to remember, very strong.
- A 14-character mixed password, if it is truly random.
- Avoid dates, first names, keyboard sequences and any password already used elsewhere.
The built-in generator offers a "pronounceable" mode that meets the entropy requirement.
Changing it
Settings, Security, Change master password. The application re-derives the keys, re-seals the vault key and, in Cloud mode, replaces the authentication key on the server. Items are not re-encrypted: the vault key does not change, only its envelope does.
Forgetting it
Without the master password, only one path remains: the recovery kit. Without both, the vault is lost. We cannot reset it, because we hold no key.
Failed unlock attempts
After several failures, a progressive delay applies: 30 seconds, then 1 minute, then 5 minutes. No silent deletion is ever triggered.
A question not answered here? support@rempar.org