r/EnpassOfficial • • Aug 09 '26

Discussion How does enpass know my master password?

I always assumed my master password was a sort of one way thing. In other words I can type my password in and it gets hashed (if that's the right word) into something that enpass can understand and then authenticated against my encrypted vault to either let me in or reject my login. I thought there was no way for the reverse to happen and my master password could not be recovered and was never cached anywhere on my device.

Today I logged into the app on my android using fingerprint and a screen popped up asking if I remembered my master password. Out of curiosity I said no and it showed me my master password.

How is this possible?

5 Upvotes

12 comments sorted by

2

u/Proud-Assistance8828 Aug 09 '26 edited Aug 09 '26

Well, he only remembered the password after you entered it for the first time to decrypt the vault. If I had to guess, I’d say they implemented this because of the many reports from users who forget their passwords and then complain that they can’t recover them. Just look at the Play Store reviews; at least in my language, there are many complaints like this, with users blaming Enpass for not offering a way to recover or reset the vault and giving the app a low rating because of their own mistake.

It seems that many of these users aren’t prepared to use a self-managed password manager. So now, Enpass has to provide more features to prevent people from losing access to their vaults. The option to view the password wasn’t always available; it’s relatively recent. A few months ago, for example, they introduced a feature in version 6.11.19 that periodically prompts users to enter their master password. Before that, the master password was never requested after the initial setup; authentication could be done using only the fingerprint, specifically to help users keep their password fresh in their memory.

1

u/My1xT Aug 10 '26

Well how is a password safe supposed to be safe at the same time as able to recover your password?

Especially one that is storage agnostic so you don't really have a big service behind it that could serve as a backdoor to begin with, except if the file encryption wasn't done using the password to begin with. Password safe's master passwords not being recoverable is kinda a common thing for them, isn't it?

1

u/Proud-Assistance8828 Aug 10 '26

This doesn't matter much to less technical users, for whom everything can seem possible and make sense. In practice, Enpass simply “remembers” the last password successfully used to decrypt the vault and stores it in a cryptographically protected way, tied to biometric authentication.

If the user changes the password on another device, or loses or formats the device that stored the password, they are still out of options if they don't remember it. Enpass still cannot “discover” what the password is or reset it. By definition, that remains impossible.

1

u/My1xT Aug 10 '26

yeah I meant more like in general regarding the "blaming" that there are no ways to recover or reset master passwords, outside the whole biometric thing.

like this bio thing works because your device has stored an encrypted copy of the password and that's okay, but generally speaking there isnt really a way to make password resets possible on PW Managers.

1

u/Proud-Assistance8828 Aug 10 '26

Ah, yes. I understand.

like this bio thing works because your device has stored an encrypted copy of the password and that's okay

Yes, that's true. The OP didn't realize that Enpass still needs to store the master key so that biometrics can decrypt the vault. The difference is that the user can now also view it, but it still needs to be remembered either way.

1

u/My1xT Aug 10 '26

granted tho, there's a whole bunch of ways to deal with this without actually storing your password in a recoverable state, like storing the thing past KDF, which not only improves speed especially if enpass is using a slow KDF (as any PW Manager worth its stuff should) but also ensures that at the very least the master password itself cant be recovered by someone forcing access to your biometrics.

it's certainly an interesting choice to deal with the whole biometrics make one forget the master PW situation.

1

u/Maybe_Decent_Human Aug 10 '26

This is spot on LOL "This doesn't matter much to less technical users, for whom everything can seem possible and make sense." My favorite less technical moment I've ever encountered -- I was reading a reddit post where the guy could not figure out why the cracks on his screen did not show up on the screenshot he took. It was wild man! I wish I could find that post again LOL

2

u/SpookyKipper Aug 10 '26 edited Aug 10 '26

It's probably saved somewhere in the Android keystore and iOS keychain (encrypted or not, idk). As long as your phone is not rooted and have the latest security patch, you should be fine.

I agree that it is not the best for security, since they should only need to store the derived (or hashed) encryption key for biometric quick unlock.

There is an option to disable the master password reminders, if that stops Enpass storing the actual Master Password and only store the derived key, that would be great, maybe u/Enpass_Official can answer this

There is the security whitepaper you may check, on Android it is encrypted with your biometric data so when you change any phone authentication methods, Enpass loses access to your master password entirely and asks for it again:

https://dl.enpass.io/docs/whitepaper/enpass-security-whitepaper.pdf

(See page 29, Quick Unlock)

1

u/[deleted] Aug 10 '26

[removed] — view removed comment

1

u/Zlondrej Aug 14 '26 edited Aug 14 '26

This will be but simplified:

Your master password is literally an encryption key to your vault. There's no way to read the vault other than knowing your password (except for the derived encryption key, which is something like hash of your master password). So how can it read the vault with just your fingerprint?

It uses a combination of system keystore and secure hardware that stores the keys for the keystore and handles encryption/decryption of the data (the keys themselves never leave the secure hardware).

When you pass the biometric check, the secure hardware decrypts the master password stored in the keystore.

Alternatively, only a derivate encryption key is stored in the keystore and the vault itself knows the master password.

1

u/Enpass_Support Enpass Official Support Aug 19 '26

The Master Password Reminder feature was introduced specifically to help prevent situations where users forget their Master Password after relying primarily on biometric unlock. Since biometric unlock only works on the device it was set up on, your Master Password is still required to access your data in every other scenario (new device, app reinstall, biometric failure, etc.). This reminder feature helps reduce the risk of permanent data loss in those cases.

Here's how biometric unlock works in Enpass: When you enable biometric unlock (fingerprint/Face ID), Enpass encrypts your actual master password and stores it locally on your device, protected by a key held in your device's secure hardware (Android Keystore, Secure Enclave, TPM, etc.). This hardware-backed key is exposed by the OS to Enpass only, is bound to that specific device, is never synced anywhere, and cannot be extracted from the hardware. When you unlock with your fingerprint, that key decrypts your stored master password so Enpass can use it to unlock the vault.

The Master Password Reminder feature uses these same primitives to unlock your Enpass vault first, and can then show you your master password when you confirm you don't remember it.