Backing Up Without a Cloud

Lomenett backs up without a cloud: the device hands you one encrypted zip file you can keep anywhere, locked behind a 12-word phrase, and that file is useless to anyone who does not have those words. There is no account, no server, and no subscription involved, just a locked copy that you hold.

"No cloud" is usually where people get nervous. If NuLenke does not keep a copy of your vault, what happens when the stick breaks, goes through the wash, or falls down a storm drain? That is a fair question, and here is the whole answer, including exactly how the backup gets made.

Making a backup

You create backups from the device itself. Open the settings menu, click Create Backup, and enter your PIN on the wheel. The device then prompts you to plug it in, and when you do, it appears as a flash drive the same way it does for editing. On that drive is a single encrypted zip file.

You can copy that file anywhere, whether that is your computer, a second thumb drive in a desk drawer, or an email to yourself. Ideally you keep it in more than one place, because the point of a backup is having more than one copy. The file is locked either way, so it does not matter where it sits.

Opening the file without a Lomenett

The backup is a standard encrypted archive, on purpose. Any software that opens encrypted archives can open it, including 7-Zip, WinRAR, and the tools most systems already have. You go to open it, type in your 12-word phrase, and boom, you can see your passwords.

That choice matters, because reading your backup does not depend on NuLenke existing, on our software surviving, or on you owning a working Lomenett. The file opens with tools the world has had for decades, which is part of what ownership means here.

"So my passwords are on my computer again?"

Kelly, one of the first normal humans we put a Lomenett in front of, asked us exactly this: "I won't have to save my passwords on my computer anymore? It's all on the stick?"

Yes, it is all on the stick, and that is the product.

The backup file, if you choose to keep one on your computer, is not your passwords sitting in the open, and it is not a document malware can read for plaintext logins. It is an encrypted blob that only becomes passwords again with your 12 words. Your passwords never live on your computer in readable form, because they live on the stick and get typed out one at a time, only when you ask.

The 12 words

The phrase that locks your backup is a list of ordinary words using BIP39, which is the same open standard hardware cryptocurrency wallets have trusted for years to recover funds from nothing but words on paper. You write it down once and put it somewhere you would keep cash. Do not photograph it and do not type it into a notes app, because it is the deepest fallback you have and it deserves to be treated that way. A phrase in a fireproof box survives every dead laptop, lost drive, and forgotten email account at once.

Could someone brute-force the backup file?

Since the file can sit anywhere, here is the honest math on someone finding it and attacking it with hardware. Twelve words means 2128 possible phrases. Give an attacker the fastest GPU money can buy and assume, very generously, that it could test a trillion phrases every second. On average the crack would still take roughly five quintillion years, which is hundreds of millions of times the age of the universe, and a real GPU working through this kind of encrypted archive runs millions of times slower than that assumption.

Brute force is not the realistic risk. The realistic risk is the phrase itself leaking by being photographed, typed into an app, or left where someone can read it. As long as the words stay private, the file stays locked.

Restoring from a backup

If the stick fails, gets lost, or gets stolen, you order a replacement Lomenett and put it in Restore From Backup mode. It appears as a flash drive again, and you drag your backup file onto it, drop it, and confirm on the device. Your vault is back. Whoever has the old stick is holding a dead end, for reasons we cover in Lose It and Shrug, and if the loss involved anything important you should change those passwords anyway. Our threat model page explains why restoring and rotating go together.

NuLenke never holds your vault, which also means NuLenke can never lose it, leak it, or hand it over. The copies that exist are the ones you made, in the places you chose.

Where the cloud honestly wins

Cloud password managers back up continuously and automatically, without you ever thinking about it. That is a real advantage and we will not pretend otherwise. With Lomenett, keeping your backup current is your job, so when you have added a batch of new logins, you spend the minute and save a fresh file. It is a small job, but it is yours.

We think that is the right trade. Their version means a copy of your vault sits on servers that attackers work against constantly, while our version means the only copies in existence are on a stick with no radios and in files that are unreadable without your 12 words. If that trade sounds right to you, the Lomenett page has the rest.