A password manager asks for trust. This page says how EasyKeys encrypts, and shows a way to check it without our code.
EasyKeys does not invent its own encryption. It uses two publicly standardised algorithms:
Both building blocks are checked against the published test values of their standards every time the app is built (RFC 9106 for Argon2id, the GCM specification for AES-256-GCM).
The key is derived from your master password alone. The password is not stored anywhere and not sent anywhere; the app does not hold the internet permission. There is no second key and no way back: without the master password nobody opens the vault, not even us.
If you switch on the fingerprint, the app puts a copy of the key into a locker that Android opens only after your fingerprint. That copy is expendable: if someone adds another finger on the device, it becomes worthless and the master password applies again.
You do not have to take our word for it. The program tresor_nachbau.py (about 80 lines of Python, comments in German) opens a vault file without a single line of code from the app. It knows only the format description below and two independent, widely used libraries: the Argon2 reference implementation and OpenSSL. If it opens your file, the file is encrypted exactly as described here.
pip install argon2-cffi cryptographypython3 tresor_nachbau.py tresor-….pwm and enter your master password.The program names the algorithms from the file header and the number of entries; with
--json it prints the whole content in plain text. With a wrong password or a modified
file it stops.
Do this on a computer you trust, and delete the output afterwards: it contains your passwords.
The file starts with 48 bytes that are not encrypted but protected against modification. All numbers are stored most significant byte first.
| From byte | Length | Content |
|---|---|---|
| 0 | 8 | Marker PWMGRVLT |
| 8 | 2 | Format version (1) |
| 10 | 1 | Key derivation (1 = Argon2id, version 1.3) |
| 11 | 4 | Argon2: memory in KiB |
| 15 | 4 | Argon2: passes |
| 19 | 1 | Argon2: lanes |
| 20 | 16 | Salt |
| 36 | 12 | Nonce for AES-GCM, new on every save |
| 48 | rest | AES-256-GCM over the content (JSON, UTF-8), with a 16-byte tag at the end |
The master password goes into Argon2id as UTF-8 and yields a 32-byte key. The first 48 bytes enter GCM as additional data.