Choosing your master password
Why this one matters more than the others
The Memoriclip vault is encrypted. Your master password is stored nowhere: it builds the decryption key, every time you unlock. Nobody here can recover it, reset it or work around it.
If someone gets hold of your hard drive one day, what they get is an unreadable file. The only thing that decides the outcome at that point is how strong your password is. Memoriclip makes each attempt expensive — building the key uses 128 MB of memory and three rounds of computation, which slows down anyone trying millions of combinations. But no amount of slowing down makes up for a weak password.
What Memoriclip requires
When you create the vault, a strength meter appears under the input field. It shows three verdicts: Weak, Fair, Strong.
A password rated Weak is rejected. The message reads: "This password is too weak. Make it longer or use a wider mix of characters."
Three things trigger that verdict: fewer than 12 characters, not enough variety in the characters, or an obvious pattern such as a repeated character or four keys in a row.
To reach Strong, you need at least 14 characters and real variety. That is the level required to export a backup of your vault.
How to build a good password
The most effective method fits in one line: string together four or five unrelated words.
window-storm-horse-blue
Twenty-three characters, and you will know it by heart after three uses. Compare that with P@ssw0rd!: nine characters, awkward to type, awkward to remember, and far quicker to guess despite the symbols.
It runs against instinct, so let's be plain about it: length counts for more than special characters. Every word you add multiplies the work for an attacker. Every symbol you add merely doubles it.
A few principles for picking your words:
- Choose words with nothing to do with each other. A phrase that makes sense is easier to guess.
- Avoid anything about you. First names, dates, your town, your pet, your team: all of it is on social media.
- Don't use a quotation or a well-known line. They are in the attackers' lists.
- Separate the words with a hyphen or a dot. It adds length and makes typing more even.
What the meter cannot see
One point of honesty, because it can cost you.
The meter measures length and character variety. It doesn't compare anything against a list of known passwords, and it doesn't spot keyboard patterns.
In practice: passwordddd rates as Fair. So does qwertyuiopas. Both are among the first things an attacker tries.
A Fair or Strong verdict therefore doesn't mean a password is good. It means it is long enough and varied enough. Whether it is predictable is something only you can know.
Which is exactly why the four-word method is worth using: it protects you from what the meter doesn't measure.
If you forget it
There is no recovery. No security question, no backup code, no intervention from us.
The only way out is to delete the vault and start over. The option exists, it works even without knowing the password, and it asks you to retype an exact word so you can't trigger it by accident. But everything the vault held is gone for good.
Two precautions are worth taking the day you create your vault:
- Write your phrase down somewhere off the computer until you have memorised it. A sheet of paper in a drawer is a very different risk from a file on your desktop.
- Unlock your vault two or three times over the following days. A phrase sticks through repetition, not through re-reading.
The backup password
When you export a backup of your vault, Memoriclip asks for a password. It is separate from your master password, and the same principles apply.
You can reuse the same one, on one condition: that you will still be able to retrieve it the day you restore the backup. A backup file with a lost password opens no more easily than a forgotten vault.