SMF·ENPASS
Can a prompt replace Enpass?
Security & passwords — passwords, privacy and private networking
Exhibit tracking slip
Verdict
A local encrypted vault that syncs through a storage backend you already use and control — Dropbox, iCloud Drive, or a WebDAV server — rather than a vendor-hosted cloud, is Enpass's actual differentiator and a genuine weekend build. What doesn't survive: an independent security audit and Enpass's own polished autofill across every browser and platform.
Exhibit A — The prompt
Received on31.07.2026Build a local encrypted password vault that syncs through a storage backend the user already controls — Dropbox, iCloud Drive, or a self-hosted WebDAV server — rather than a vendor-hosted cloud sync service. Use a WebExtension (Manifest V3) for browser autofill, backed by a native companion app that holds the encrypted vault, following the same architecture as this catalogue's NordPass entry. Encrypt the vault file with XChaCha20-Poly1305 via libsodium and Argon2id key derivation, same as the NordPass build — don't invent new cryptography. The actual differentiator: instead of syncing to a vendor's servers, save the single encrypted vault file inside a folder the user points at their own Dropbox, iCloud Drive, or WebDAV-mounted folder — any existing file-sync mechanism handles the actual multi-device sync, since the file is already encrypted and safe to store anywhere. Detect when the vault file has been updated externally, a newer sync, and reload it, handling the edge case where the file changed between when you opened it and when you save an edit by warning rather than silently overwriting. Do not build vendor-hosted sync infrastructure, a mobile app, or claim an independent security audit — those are out of scope; be explicit that this build hasn't been audited, same honesty as the NordPass entry. No account, vendor server, or API key needed — sync piggybacks entirely on storage you already use.
Opening prefills the prompt — press enter to run it.
Exhibit B — What you lose
- B.1 an independent third-party security audit
- B.2 polished autofill across every browser and platform
- B.3 vendor account recovery
- B.4 a mobile app with the same file-sync integrations
Prior art
Exhibit C — Why people still pay: security assurance, infrastructure, and trust
The 'sync through your own storage' idea is simple to build; a polished, reliably-autofilling app on every platform, backed by an actual security audit, is the years of engineering and credibility work.
Questions
How does syncing work without a vendor server?
The encrypted vault is just a file, saved inside a folder you point at Dropbox, iCloud Drive, or a WebDAV server you already use — that existing sync mechanism handles multi-device sync, since the file is safe to store anywhere once encrypted.
What happens if I edit the vault on two devices before they sync?
The build detects the file changed externally and warns you rather than silently overwriting — you'll need to manually reconcile, since there's no automatic conflict merge for a single encrypted file.
Is this audited the same way NordPass is?
No — same honest gap as this catalogue's NordPass entry: no independent security audit, which is worth being upfront about.
What does it cost to run?
Nothing beyond whatever storage service you're already using for sync — Dropbox, iCloud, or your own WebDAV server.
Related tools
Receipt