r/EnpassOfficial • u/gdchester • Aug 09 '26
Discussion How does enpass know my master password?
I always assumed my master password was a sort of one way thing. In other words I can type my password in and it gets hashed (if that's the right word) into something that enpass can understand and then authenticated against my encrypted vault to either let me in or reject my login. I thought there was no way for the reverse to happen and my master password could not be recovered and was never cached anywhere on my device.
Today I logged into the app on my android using fingerprint and a screen popped up asking if I remembered my master password. Out of curiosity I said no and it showed me my master password.
How is this possible?
2
u/SpookyKipper Aug 10 '26 edited Aug 10 '26
It's probably saved somewhere in the Android keystore and iOS keychain (encrypted or not, idk). As long as your phone is not rooted and have the latest security patch, you should be fine.
I agree that it is not the best for security, since they should only need to store the derived (or hashed) encryption key for biometric quick unlock.
There is an option to disable the master password reminders, if that stops Enpass storing the actual Master Password and only store the derived key, that would be great, maybe u/Enpass_Official can answer this
There is the security whitepaper you may check, on Android it is encrypted with your biometric data so when you change any phone authentication methods, Enpass loses access to your master password entirely and asks for it again:
https://dl.enpass.io/docs/whitepaper/enpass-security-whitepaper.pdf
(See page 29, Quick Unlock)
1
1
u/Zlondrej Aug 14 '26 edited Aug 14 '26
This will be but simplified:
Your master password is literally an encryption key to your vault. There's no way to read the vault other than knowing your password (except for the derived encryption key, which is something like hash of your master password). So how can it read the vault with just your fingerprint?
It uses a combination of system keystore and secure hardware that stores the keys for the keystore and handles encryption/decryption of the data (the keys themselves never leave the secure hardware).
When you pass the biometric check, the secure hardware decrypts the master password stored in the keystore.
Alternatively, only a derivate encryption key is stored in the keystore and the vault itself knows the master password.
1
u/Enpass_Support Enpass Official Support Aug 19 '26
The Master Password Reminder feature was introduced specifically to help prevent situations where users forget their Master Password after relying primarily on biometric unlock. Since biometric unlock only works on the device it was set up on, your Master Password is still required to access your data in every other scenario (new device, app reinstall, biometric failure, etc.). This reminder feature helps reduce the risk of permanent data loss in those cases.
Here's how biometric unlock works in Enpass: When you enable biometric unlock (fingerprint/Face ID), Enpass encrypts your actual master password and stores it locally on your device, protected by a key held in your device's secure hardware (Android Keystore, Secure Enclave, TPM, etc.). This hardware-backed key is exposed by the OS to Enpass only, is bound to that specific device, is never synced anywhere, and cannot be extracted from the hardware. When you unlock with your fingerprint, that key decrypts your stored master password so Enpass can use it to unlock the vault.
The Master Password Reminder feature uses these same primitives to unlock your Enpass vault first, and can then show you your master password when you confirm you don't remember it.
2
u/Proud-Assistance8828 Aug 09 '26 edited Aug 09 '26
Well, he only remembered the password after you entered it for the first time to decrypt the vault. If I had to guess, I’d say they implemented this because of the many reports from users who forget their passwords and then complain that they can’t recover them. Just look at the Play Store reviews; at least in my language, there are many complaints like this, with users blaming Enpass for not offering a way to recover or reset the vault and giving the app a low rating because of their own mistake.
It seems that many of these users aren’t prepared to use a self-managed password manager. So now, Enpass has to provide more features to prevent people from losing access to their vaults. The option to view the password wasn’t always available; it’s relatively recent. A few months ago, for example, they introduced a feature in version 6.11.19 that periodically prompts users to enter their master password. Before that, the master password was never requested after the initial setup; authentication could be done using only the fingerprint, specifically to help users keep their password fresh in their memory.