giancarlomangiagli.it

CryptPass, a password manager

CryptPass is a free and open-source system for organizing credentials and keeping them in an encrypted file. It consists of the library and the application.

Read this page in Italian

Summary

What is CryptPass

I wanted to create a simple tool for a specific task: organize secrets and encrypt them in a file that users can keep wherever they choose. The library manages the format and cryptography; the app provides the interface, file handling and features needed to use the library on several platforms.

Requirement Details
Simple and focused The main features are about credentials and encrypted vaults; additional features belong in the app.
Protected by two secrets Opening a vault requires the master password and a separate recovery sequence.
Local Vault files stay in a location chosen by the user. CryptPass does not provide a cloud service.
Free and reusable The source code is public and the library can be integrated into other projects.

The use of cryptography is not a certification or independent security review. The project is maintained with security in mind, but it has not undergone a formal third-party audit.

↑ Up to summary

App features

Feature Details
Android, Linux and Windows The interface is built with Apache Cordova. Android uses the system document APIs; Linux and Windows use Electron.
Multiple wallets You can create separate local profiles, each linked to its own file and sequence. Switching profiles locks the open wallet. Removing a profile from the app does not delete the encrypted file.
Password and sequence A master password and a recovery sequence of 26 numbers from 0 to 25 protect the vault. Keep the sequence separately; you need it to restore the file in a new installation.
Entries and fields Each entry has a unique name, standard fields such as description, tags, username, password and PIN, and custom fields.
Search Free-text search covers entry names and descriptions, ignores accents, and tolerates small typos. Tags remain available as a filter.
Lock and clipboard The app locks after 10 seconds of inactivity by default; change the timeout in Preferences. If the device has a screen lock, unlocking the app requires that device credential; otherwise, enter the master password. Copied passwords are scheduled for removal from the clipboard after one minute when the platform lets the app check that the copied value is still there.
Language The app offers English and Italian as language preferences. Text that has not yet been translated remains in English.

↑ Up to summary

How it works, in a nutshell

Credentials are encrypted before they are saved in the vault file. Opening the file requires the master password and the recovery sequence. The sequence is not your cloud account password and should not be shared with the service used to synchronize the file.

You can use a storage service of your choice to keep a backup. Synchronization and backups remain under your control: CryptPass does not upload data to its own servers.

The project cannot recover a forgotten password or sequence. Losing either one may make the vault inaccessible.

↑ Up to summary

Format, security and platforms

The library

The current library writes new data using a versioned format with authenticated encryption: it encrypts the contents and also allows changes or corruption to be detected. The library derives keys from the password and keeps read compatibility with older vaults.

When you open a legacy vault and successfully save it with the current app, the library rewrites it in the authenticated format. The app does not recreate or modify cryptographic data itself.

The app

On Electron, file access is limited to the main process and files chosen by the user. The sequence and metadata are stored through the operating system's protected storage when available. On Android, the sequence is managed by the secure-storage plugin connected to the system.

Platform File selection and saving Notes
Linux and Windows Native open and save dialogs; an internal handle links the profile to the selected file. The Windows build produces an NSIS installer (.exe) and a portable archive (.zip). The generated installer does not have a publisher Authenticode signature; sign it with a trusted certificate before public distribution.
Android You grant access to a folder through the system document picker; CryptPass lists compatible files and lets you choose the vault. The persistent folder permission lets the app find the file after its contents are updated. Behavior depends on the provider. If the folder moves or its permission is revoked, you may need to select it again.

If a cloud location or its permission is no longer accessible, use the restore options and select the folder containing the vault again. Check that you chose the correct file before saving.

↑ Up to summary

Current limitations

CryptPass is available for Android, Linux and Windows; iOS and macOS are not currently supported. Android cloud-provider behavior depends on the app supplying the document and should be tested on the device in use.

The interface is being localized: English or Italian can be selected, but some screens or messages may remain in English. JavaScript cannot guarantee physical erasure of passwords from memory; locking reduces how long references remain active but does not guarantee complete zeroization.

A file kept in a synchronization service can be changed or replaced by that service. Keep backups and periodically check that you can restore the file and its sequence.

↑ Up to summary

Contributions

This software is free and contributions are welcome. Please report issues in the GitHub pages of either project.

Issue links

CryptPass library issues

CryptPassApp issues

↑ Up to summary

Downloads and source code

Install on Android

CryptPassApp on Google Play

Install on Linux

Install on Windows

Portable Windows archive (.zip)

Source code

↑ Up to summary