Questions
Short answers on privacy, offline use and strength.
- Does SecurePass send or store my passwords?
- No. Everything runs in your browser and nothing is sent, saved or logged. The only outside request is the optional breach check, which sends five characters of a hash.
- How can I check that for myself?
- Open developer tools, choose the Network tab, and use the tools: no requests appear. Or go offline after one visit; it keeps working. The network counter shows the same live.
- Does it work offline?
- Yes, after your first visit. Only the breach check needs a connection.
- Is the breach check private?
- Yes. Only the first five characters of the password's SHA-1 hash are sent, and your device finds the match itself. How it works.
- What can't SecurePass protect against?
- Anything already on your device or watching your screen: malicious extensions, malware, clipboard history or sync, or someone looking over your shoulder. That's why you can hide the password.
- Why does the checker rate a long password as weak?
- Length only helps when it's unpredictable. Common words, names, dates, keyboard runs like qwerty and swaps like @ for a are tried first, so a long password made of them can fall in seconds.
- Should I use a password or a passphrase?
- Both are strong when random. Passwords suit a password manager; six or more random words are easier to type and remember, like your password manager's own password.
- How random is it?
- Every character comes from
crypto.getRandomValues, the browser's cryptographic random generator, with no bias: every password is equally likely. - Is it really free?
- Yes. No ads, accounts or tracking, and the source code is MIT licensed.