Using GrailVault

Security check

Find weak, reused, old and leaked passwords, and fix them.

The Security check looks over every login in your vault and tells you what to fix. Open it from Security check in the menu.

The Security check pageThe Security check page
The Security check page

#What it checks

Check What it means What to do
Weak passwords Short, common (such as password or qwerty123) or built from a word plus a year and a symbol. Replace them with generated passwords.
Reused passwords Two or more logins share the same password. One leak then opens all of those accounts. Give each login its own password.
Leaked in a data breach The password appears in a public list of passwords from known breaches. Change it everywhere it is used, straight away.
Not changed for over a year The login has not been edited for more than a year. Consider changing it, especially for important accounts.

Each result has an Open link that takes you straight to that login.

Note

Strength is an estimate. It is deliberately strict about common patterns, but a long password from the generator always scores well. "Not changed" uses the date you last edited the login, so editing any detail resets it.

#It runs on your device

The weak, reused and old checks happen entirely in your browser, on the decrypted vault. Your passwords are never sent anywhere for these checks, and the results contain item names only.

#The breach check, and what it sends

The breach check is optional and only runs when you choose Check for breaches. It uses the Have I Been Pwned service in a way that never reveals your passwords:

  1. Your browser makes a one-way fingerprint (a SHA-1 hash) of each password.
  2. It sends only the first five characters of that fingerprint, through GrailVault's server, to the service.
  3. The service answers with every fingerprint that starts with those five characters (hundreds of them, padded so the size reveals nothing).
  4. Your browser looks for its own full fingerprint in that list. The answer is never sent anywhere.

So neither GrailVault's server nor the breach service learns your password, or even its full fingerprint. The server can see that you ran a check and which five-character prefixes were asked about, which are shared by hundreds of thousands of unrelated passwords.

The check needs an internet connection and can take a little while for large vaults.

#Limits

  • It checks Login items only.
  • A password that is not in the breach list is not guaranteed to be safe: it only means it has not appeared in a known breach.