⥠About pwdflash
Dual-layer zero-cleartext security architecture, memory training, and privacy model.
đ¯ Motive & Purpose
In a modern digital world dominated by automated password managers, our natural human memory for critical credentials often degrades. pwdflash was created as a dedicated memory training utility designed to help users memorize and practice active recall for:
- đ Master Passwords & Passphrases
- đĸ 4-digit & 6-digit Credit Card PINs
- đ Phone Numbers & Emergency Contacts
- đ Vehicle License Plates
- đ Addresses & Security Codes
- đ§ General Daily Memory Training
đ Dual-Layer Hashing Architecture
pwdflash employs a robust, two-tier cryptographic hashing architecture for secret flashcards to ensure cleartext passwords never leave your browser:
1ī¸âŖ Layer 1 (Client-Side SHA-256 + 256-bit Salt)
When creating, editing, or studying a secret flashcard, your browser generates a cryptographically secure 256-bit random salt (client_salt). The browser appends this salt to your secret input and hashes it with SHA-256:
client_hash = SHA-256( cleartext_value + client_salt )
Only client_hash and client_salt are transmitted to the server over HTTPS. Your cleartext secret never leaves your browser.
2ī¸âŖ Layer 2 (Server-Side Argon2id + 256-bit Salt)
Upon receiving client_hash, the server generates a separate 256-bit server salt (server_salt) and hashes the client payload with Argon2id before saving to SQLite:
server_hash = Argon2id( client_hash + server_salt )
The server only stores server_hash, server_salt, and client_salt. Argon2 hashes are never exposed to the client.
Server Rate Limiting: Verification requests sent to /api/flashcards/<id>/check are strictly rate-limited:
đ Security Boundaries & Self-Hosting
Understanding the security boundaries of client-side hashing is critical for safe usage:
Recommendation: If you plan to train memory for sensitive financial PINs or personal identity codes, you should self-host this application. pwdflash was specifically engineered for lightweight, zero-dependency self-hosting via Docker Compose.
â¨ī¸ Useful Keyboard Shortcuts
| Shortcut | Action / Function |
|---|---|
| Enter | Verify typed answer during study session / Advance to next card when "Next" or "Finish" is focused. |
| Alt + X | Hold down to temporarily reveal secret flashcard input text while studying (hides text when released). |
| Esc | Close active modal dialogs. |