What I learned building a local-only password manager (PassForgePro)
Details
- External ID
- 46709825
- Source
- HN
- Company
- —
- Product
- What I learned building a local-only password manager (PassForgePro)
- Website domain
- github.com
- Launched
- Jan. 21, 2026
- Cohort
- —
- Upvotes
- 5
- Upvotes percentile
- 0.09617918313570488
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
Show HN: What I learned building a local-only password manager (PassForgePro)Hi HN,I built PassForgePro as a learning project to better understand password manager design, local-first security, and common cryptographic pitfalls.The goal was not to replace mature tools like Bitwarden or KeePass, but to explore:* how a local-only, zero-knowledge style design can work * key derivation with PBKDF2 and encrypted SQLite vaults (AES-256-GCM) * handling sensitive data in memory and clipboard cleanup * defining a realistic threat model and its limitationsThis project is experimental and unaudited. I’m sharing it mainly to get feedback on the architecture, crypto choices, and overall approach, and to discuss what I got wrong or could improve (audits, reproducible builds, testing, etc.).I’d really appreciate feedback, especially from people with security or cryptography experience.Repo: https://github.com/can-deliktas/PassForgePro Docs / demo: https://can-deliktas.github.io/PassForgePro
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Security
- Function
- Vertical SaaS
- Audience
- B2C
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- local-only password manager
- Manually corrected
- False
Could you build this?
Yes A local-only password manager consists of a standard desktop or CLI UI using standard cryptographic libraries (e.g., Argon2id and AES-GCM) to encrypt and decrypt a local database.
Discussion
3 comments analyzed.
Concerns raised: No API for remote access or cloud sync, Experimental project, not production-grade, Does not defend against compromised OS or malicious local software, Potential accessibility API exposure risk
Competitors
Other products that read as similar to this one — 38 launches clear the similarity bar, closest 8 shown.
Attention rank: #37 of 39 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 70 days after the earliest competitor.
- Ravenpass · ph · 2026-09-30 · 1 upvotes · similarity 0.55
- Keepr · hn · 2025-11-14 · 17 upvotes · similarity 0.50
- Bramble · hn · 2026-07-02 · 153 upvotes · similarity 0.48
- Shrouded, secure memory management in Rust · hn · 2026-03-23 · 5 upvotes · similarity 0.48
- I Dedicated 4 Years to Mastering Offline Password Cracking · hn · 2026-05-21 · 268 upvotes · similarity 0.44
- Sesame · hn · 2026-08-28 · 66 upvotes · similarity 0.43
- Open Passkey · hn · 2026-04-19 · 10 upvotes · similarity 0.42
- OwnVault · ph · 2026-09-07 · 1 upvotes · similarity 0.42
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a vertical saas tool for Insurance yet.