đŸŽ¯ Motive & Purpose

In a modern digital world dominated by automated password managers, our natural human memory for critical credentials often degrades. pwdflash was created as a dedicated memory training utility designed to help users memorize and practice active recall for:

  • 🔑 Master Passwords & Passphrases
  • đŸ”ĸ 4-digit & 6-digit Credit Card PINs
  • 📞 Phone Numbers & Emergency Contacts
  • 🚗 Vehicle License Plates
  • 🏠 Addresses & Security Codes
  • 🧠 General Daily Memory Training

🔒 Dual-Layer Hashing Architecture

pwdflash employs a robust, two-tier cryptographic hashing architecture for secret flashcards to ensure cleartext passwords never leave your browser:

1ī¸âƒŖ Layer 1 (Client-Side SHA-256 + 256-bit Salt)

When creating, editing, or studying a secret flashcard, your browser generates a cryptographically secure 256-bit random salt (client_salt). The browser appends this salt to your secret input and hashes it with SHA-256:

client_hash = SHA-256( cleartext_value + client_salt )

Only client_hash and client_salt are transmitted to the server over HTTPS. Your cleartext secret never leaves your browser.

2ī¸âƒŖ Layer 2 (Server-Side Argon2id + 256-bit Salt)

Upon receiving client_hash, the server generates a separate 256-bit server salt (server_salt) and hashes the client payload with Argon2id before saving to SQLite:

server_hash = Argon2id( client_hash + server_salt )

The server only stores server_hash, server_salt, and client_salt. Argon2 hashes are never exposed to the client.

Server Rate Limiting: Verification requests sent to /api/flashcards/<id>/check are strictly rate-limited:

âąī¸ Maximum 2 incorrect attempts allowed per 20-minute window per secret flashcard.

🌐 Security Boundaries & Self-Hosting

Understanding the security boundaries of client-side hashing is critical for safe usage:

🔑 Strong Passphrases & Long Passwords: For long passwords (16+ characters), client-side SHA-256 hashing, while being a fast hashing algorithm, still makes it computationally infeasible for a rogue server operator to recover your cleartext password.
đŸ”ĸ Short PIN Codes: For short 4-digit PINs (e.g., labeled "Visa card ending 1234"), the search space contains only 10,000 combinations (0000–9999). Even with SHA-256 and a 256-bit client salt, a malicious server operator can precompute or brute-force all 10,000 hashes fairly quickly. Client-side hashing cannot mathematically protect low-entropy secrets against an untrusted host.

Recommendation: If you plan to train memory for sensitive financial PINs or personal identity codes, you should self-host this application. pwdflash was specifically engineered for lightweight, zero-dependency self-hosting via Docker Compose.

âŒ¨ī¸ Useful Keyboard Shortcuts

Shortcut Action / Function
Enter Verify typed answer during study session / Advance to next card when "Next" or "Finish" is focused.
Alt + X Hold down to temporarily reveal secret flashcard input text while studying (hides text when released).
Esc Close active modal dialogs.