Skip to content

Vault

One encrypted file. One master password. No sync, no cloud, no recovery - which is exactly why there's nothing to breach.

Setup

blackhole vault init --vault ~/.blackhole/vault.db

The file is created chmod 0600. Pick a long master and write it down somewhere safe. If you lose it, the vault is gone.

Daily use

# save something (prompts for the rest)
blackhole vault set github --username alice --generate 24

# passphrases are nicer to type
blackhole vault set wifi --passphrase 5

# read it back
blackhole vault get github --show

# delete one you don't need (asks first unless --yes)
blackhole vault rm old-forum

# change the master (re-encrypts everything)
blackhole vault passwd

# copy without printing (best-effort clipboard, clears after ~30s)
blackhole vault get github

# what's in there
blackhole vault list

# fresh password without storing anything
blackhole vault gen --length 24

Health check

blackhole vault audit
Score: 85/100  entries=12
reused passwords: {'hunter2...': ['old-forum', 'test-box']}
weak (<12 chars): ['router']
stale (>1y): ['bank-backup-code']

Change the reused and short ones first. That's the whole game.

How it works

  • Master + random 16-byte salt go through Argon2id (t=3, m=64MiB, p=4) into a 32-byte key.
  • Everything is one JSON blob encrypted with AES-256-GCM. The header (magic, params, salt, nonce) is authenticated as AAD.
  • Unlock tries to decrypt a known verifier. Wrong password just fails.
  • The master is never written anywhere. Each command locks when it ends.

Moving machines

Copy the .db file. That's it. Back it up like you'd back up anything precious - the backup is still encrypted, safe to keep on a USB stick.