A password system with no database, no sync, and nothing to breach
Details
- External ID
- 46914943
- Source
- HN
- Company
- —
- Product
- A password system with no database, no sync, and nothing to breach
- Website domain
- vercel.app
- Launched
- Feb. 6, 2026
- Cohort
- —
- Upvotes
- 14
- Upvotes percentile
- 0.6314016172506739
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hi HN, Bastion Enclave is an experiment in removing centralized trust from password management by eliminating server-side state entirely. Instead of storing an encrypted vault or syncing secrets through a backend, Bastion computes credentials deterministically on-the-fly using explicit cryptographic inputs. Given the same master entropy, service name, username, and version counter, the same password is reproduced across platforms. There is no account system, no database, and no persistent server storage — the server serves static code only. Password generation uses domain-separated salts and PBKDF2-HMAC-SHA512 (210k iterations) to produce a byte stream, followed by unbiased rejection sampling to avoid modulo bias when mapping to character sets. Nothing is stored; passwords are derived when needed and discarded immediately after use. When users choose to persist data locally (vault state, notes, file keys), encryption is handled separately using Argon2id (64 MB memory, 3 iterations) to derive a master key, followed by AES-256-GCM for authenticated encryption. All plaintext exists only in volatile memory; closing the tab tears down the runtime. Recovery and key escrow are handled via Shamir Secret Sharing over a large prime field (secp256k1 order) using a hybrid scheme: the secret is encrypted with a random session key, and only that key is split into shards. Invalid or mismatched shards fail cryptographically via AEAD tag verification. The security claim here is architectural, not policy-based: no stored vaults, no encrypted blobs on servers, no sync endpoints, and no recovery infrastructure to subpoena or breach. Attacking Bastion means attacking individual devices, not a centralized honeypot. This design intentionally trades convenience (sync, automated recovery) for reduced attack surface and deterministic guarantees. It assumes a trusted local execution environment and a strong master secret; it does not attempt to defend against a compromised OS or browser runtime. Live demo: https://bastion-enclave.vercel.app Spec / source / threat model: https://github.com/imkevinchasse/Bastion-Enclave-repo-V2 I’d appreciate critique of the threat model and whether this class of design meaningfully removes attack vectors inherent to cloud-based managers.
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Security
- Function
- Compliance & governance
- Audience
- B2C
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- password system without database
- Manually corrected
- False
Could you build this?
Partial The front-end client is basic web UI, but implementing stateless deterministic credential derivation securely requires rigorous cryptographic proofs to prevent timing attacks, hash collisions, and brute force vulnerabilities.
What it would actually take: The system relies on memory-hard key derivation functions (Argon2id, scrypt) parameterized carefully, combined with HKDF and deterministic generation trees. The difficult aspect is cryptographic auditability, preventing offline precomputation attacks without storing salts, ensuring safe browser memory zeroization, and edge-case handling across platforms. A cryptographer or experienced security engineer is needed to validate that no weak key generation patterns exist.
Discussion
16 comments analyzed.
Competitors mentioned: 1Password (1P), Hardware wallets, SSH private keys
Concerns raised: Losing master secret is catastrophic with no recovery option, Doesn't defend against compromised local environment or OS, Password rotation requires tracking version parameter, Can't use passwords on devices you don't own, Offline brute-force risk if password, site, username, and version known
Feature requests: Multi-device sync capability, Passkey unlock support, Cloud recovery option, Better handling of site-specific password requirements without metadata storage
Competitors
Other products that read as similar to this one — 263 launches clear the similarity bar, closest 8 shown.
Attention rank: #95 of 264 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 99 days after the earliest competitor.
- Shrouded, secure memory management in Rust · hn · 2026-03-23 · 5 upvotes · similarity 0.57
- Lockenv · hn · 2025-12-08 · 105 upvotes · similarity 0.53
- Caution: Hosting platform for software you can't afford to have hacked · yc · 2026-08-04 · 59 upvotes · similarity 0.53
- KeeperPass · ph · 2026-09-23 · 8 upvotes · similarity 0.53
- Liberty · hn · 2026-01-14 · 7 upvotes · similarity 0.50
- CambiOS · hn · 2026-06-11 · 8 upvotes · similarity 0.48
- KeyEnv · hn · 2026-01-18 · 5 upvotes · similarity 0.47
- Tlx · hn · 2026-09-25 · 5 upvotes · similarity 0.47
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.