SMF·KEEPER-PASSWORD-MANAGER
Can a prompt replace Keeper?
Security & passwords — passwords, privacy and private networking
Exhibit tracking slip
Verdict
The vault itself is well-trodden and the catalogue says so elsewhere. What is genuinely worth building here is the health side: checking every stored password against Have I Been Pwned's k-anonymity API — which is free, does not reveal your passwords, and is the same data commercial breach monitoring resells — and reporting reused, weak and stale credentials. That is a real afternoon's work with real value. What stays out of reach is the browser autofill, the recovery path, and the audits that make a vault trustworthy to anyone but you.
Exhibit A — The prompt
Received on31.07.2026Build a local password vault whose distinguishing feature is a credential health audit.
Vault: a desktop application. Derive the encryption key from the master password with Argon2id using a per-vault random salt, with the parameters stored in the vault header so they can be raised later. Encrypt with an authenticated cipher from a maintained library; never assemble primitives by hand. Entries hold a title, username, password, TOTP secret, URLs, and notes, all inside the encrypted blob.
Behaviour: auto-lock on a timer and on system sleep, clipboard cleared after a configurable delay, a password generator with length and character-class policy, import from 1Password, Bitwarden, KeePass and CSV, and export both encrypted and plain with a warning on the plain path.
The health audit, which is the point of this build. Run it on demand over the unlocked vault and report:
- Breached: check each password against Have I Been Pwned's range API using k-anonymity. Compute the SHA-1 hash locally, send only the first five hex characters, receive the list of matching suffixes, and compare locally. The full hash and the password never leave the machine — implement it exactly this way and say so in the README, because a breach checker that uploads anything is worse than none.
- Reused: passwords appearing on more than one entry, grouped so the whole cluster can be rotated together.
- Weak: scored by an entropy estimator that accounts for dictionary words, keyboard patterns and common substitutions, not by a character-class rule — "P@ssw0rd1" passes every character-class rule ever written.
- Stale: entries not changed in longer than a configurable period, weighted by how sensitive the user marked them.
- Missing second factor: entries whose site is known to support TOTP but where no secret is stored, from a user-maintained list.
Present the audit as a prioritised action list — breached first, then reused on important accounts — with a rotate action that opens the entry, generates a new password and records the change date. A score with no next step is a number nobody acts on.
Offline behaviour: the breach check requires network access. Everything else in the audit runs entirely offline, and the interface must say which findings are stale because the last breach check was N days ago.
Display a persistent notice that this build has had no independent security review.
Out of scope: browser extension autofill, mobile apps, any sync service, secure file storage, and account recovery. Note that a forgotten master password means the vault is unrecoverable, and make the user acknowledge that at setup.
Opening prefills the prompt — press enter to run it.
Exhibit B — What you lose
- B.1 browser and mobile autofill, which is how a vault is actually used
- B.2 account recovery if you forget the master password
- B.3 independent security audits of the client and its cryptography
- B.4 the dark-web monitoring that watches for your addresses appearing in new dumps
Prior art
Exhibit C — Why people still pay: security assurance, infrastructure, and trust
Because a password manager is the one piece of software where being wrong is catastrophic, and a paid product carries audits, a recovery path and somebody answerable when it fails.
Questions
Can I import my Keeper vault?
Yes. Keeper exports to JSON and CSV including TOTP secrets and custom fields, and the standard fields map directly. Attached files and Keeper's own record types come across as notes at best, so check anything unusual before you cancel.
Is sending part of a hash to a breach API safe?
Yes, and that is the whole point of the k-anonymity design. Sending the first five characters of a SHA-1 hash returns a bucket of several hundred suffixes, so the service cannot tell which one you were asking about, and it never sees the password or the full hash. The comparison happens on your machine.
What does it cost to run?
Nothing. Local application, local vault, and the breach API is free for this use. Against a personal plan of a few dollars a month, the money argument favours building — the safety argument does not.
What is the one thing that does not survive the rebuild?
Autofill. A vault you have to open, unlock, search and copy from is a vault whose passwords stay short and reused, because friction wins. Browser and mobile autofill is what actually makes people use strong unique credentials, and it is not something a standalone desktop app provides.
Related tools
Receipt