How do you choose a strong vault password?

Published By Stillgarth3 min read

A strong vault password is long, new and memorable: at least 12 characters, not used anywhere else, and something you can type from memory. Stillgarth accepts 8 characters for the vault itself, but an encrypted backup only opens with your password if it’s 12 or more, because a backup file can be attacked offline. And since nobody can reset it, you have to remember it.

What does the password actually protect?

Your vault password is the master way in. Every file is encrypted with a random key, and that key is stored only in locked form. The password unlocks one copy of it, through Argon2id, a deliberately slow method that makes every guess expensive. Your PIN and fingerprint unlock other copies, but those depend on the phone’s security chip and work only on this phone. The password is the one that always works, and the only one that works on another phone.

The password itself is never stored anywhere. That’s why it can’t be reset.

Why is guessing slow on the phone but not on a backup?

On your phone, Stillgarth slows guessing down on purpose:

  • every wrong password makes you wait longer: 2 seconds, then 4, doubling up to 5 minutes;
  • the PIN locks for 30 minutes after 5 wrong tries;
  • both counters survive the app being closed or killed.

A backup file has none of that protection once it’s copied off the phone. Someone who gets the file can try passwords on fast computers, as many as they like, with no lockout. Stillgarth makes each guess against a backup much more expensive (a heavier Argon2id setting that needs 128 MiB of memory per try), but a short or common password is still within reach of enough computing power. That’s why a backup only opens with your password if it’s at least 12 characters, and otherwise with a 25-character recovery code.

What makes a password strong?

Length does most of the work. Some practical rules:

  • 12 characters or more. Every extra character multiplies the number of guesses needed.
  • A phrase works well. Four or five unrelated words are long, and easier to remember than a jumble of symbols.
  • Make it new. Don’t reuse a password from email or any other account. Passwords leaked from other sites are among the first things tried.
  • Keep it different from your phone’s PIN. Guard’s “Is it you?” check is there so someone who knows your phone’s PIN can’t quietly switch Guard off. That only works if your vault secret is different.
  • Avoid the obvious. Names, birthdays and keyboard patterns are guessed first.

Why can’t a password manager fill it in?

The vault’s password, PIN and duress fields are blocked from autofill on purpose. A saved vault password would be a second copy, synced off the phone, and filled in for whoever gets past the phone’s own screen lock. So the vault password is one you keep in your head. If you need it written down, keep it on paper, somewhere safe and away from the phone.

Do you still need a PIN or fingerprint?

They’re optional, and they’re for convenience. A 4 to 8 digit PIN or your fingerprint opens the vault quickly every day, while the password stays the recovery path. A short PIN is still safe on the phone, because it only works together with a key held in the phone’s security chip, and it locks after 5 wrong tries. Your password always works, even while the PIN is locked.

Fingerprint unlock turns itself off if a new fingerprint is added to the phone. Then you unlock with the password and can turn it on again in Vault settings.

How do you change your password?

Unlock the vault, then go to Vault settings and Change password. You’ll need the current password, and the new one must be at least 8 characters. If your backup opens with your password and the new one is shorter than 12 characters, the backup turns itself off and tells you, so it’s never protected by a password that’s too short.

How does this fit with a duress code?

If you set a duress code, it must be different from your password and PIN, and it erases the vault when typed. Make it something you’d never type by accident while trying your real password.

If you think you might forget your password, read what happens if you forget it now, while you can still do something about it.