Can Lomenett Be Hacked?
Lomenett can be hacked, because everything can be hacked. What a security product actually sells is how much time and access an attack costs, and Lomenett is built to make every attack cost more than your passwords are worth.
That is our whole security philosophy, and it comes straight from our CEO: "Everything is hackable. It's just a matter of time. All we can do is extend that time." Any company that answers "can it be hacked?" with a flat no is lying to you, and we would rather lose a sale than do that. Here is the honest breakdown, attack by attack.
"If somebody hacks my computer do they have access to my passwords?"
This is a real question from one of our first testers, and it deserves the straightest answer.
They get part of it. If malware is running on your computer, it can capture a password at the moment Lomenett types it, the same way it captures the ones you type with your fingers. That is true of every password manager ever made, whether it is a hardware stick, a cloud vault, browser autofill, or a notebook in a drawer. The password has to arrive at the computer eventually or you could not log in, and a machine the attacker controls can read it at that moment.
Here is what they do not get. A hacked computer never sees your vault, because the vault never leaves the stick. It never sees your PIN, because you enter that on the device itself rather than the keyboard. It also never sees the entries you did not use, so if you type two passwords while the malware is watching, the attacker has those two passwords and none of the other 998. With a software password manager on that same machine, the attacker can go after the whole vault at once, while with Lomenett they get exactly what was typed while they were watching and nothing else.
Can someone hack it remotely?
No, and this one is not a matter of time, because it is a matter of physics. Lomenett has no Wi-Fi, no Bluetooth, no radios of any kind, no app, no account, and no server, so there is nothing to connect to. A hacker in another country cannot reach a device that has no path to the internet and no signal to intercept. Our servers cannot be breached for your vault, because your vault has never been on a server. Every real attack on a Lomenett starts with someone physically holding your specific stick.
That single decision removes the attacks that actually happen to normal people, meaning breached password databases, cloud vault leaks, and phished accounts. We go through the full list in our attack surface.
What about someone with a lab?
Now we are at the honest edge, so let us describe it plainly. Say a skilled attacker steals your Lomenett and takes it to a bench. Desoldering the flash and dumping the memory gets them ciphertext, because the key that decrypts it lives in a separate tamper-resistant secure element and never leaves it. Guessing the PIN gets them a handful of attempts, counted in the chip's own hardware, before the key is destroyed forever. Cloning the device does not work, because the secure element cannot be copied. The full mechanism is on the PIN page.
Could a nation-state lab with an electron microscope and months of effort eventually beat a secure element? We assume yes, because we assume everything falls given enough time. But look at what that attack requires: stealing your specific device, world-class equipment, and a long window before you notice it is gone and change your important passwords. Encryption does not have to hold forever, because it only has to buy you more time than the attacker has. If someone with those resources is targeting you personally, they have far cheaper ways to get your passwords than through our chip, and no product on this page or any other will save you from them.
So what's the honest verdict?
Nobody can hack your Lomenett from the internet, because there is no path. A hacked computer gets only what is typed on it while it is watching, which is a floor no password manager gets under. A thief with your stick faces encrypted data, a key they cannot extract, and a handful of guesses before that key is gone for good. Meanwhile you restore from backup and rotate anything important, which is a story we tell in full at lose it and shrug.
We cannot make Lomenett unhackable, and nobody can make anything unhackable. What we did was make the cheap attacks impossible and the expensive attacks slow, and our firmware will be open source so you can check that claim instead of trusting it. That is the deal, stated plainly, and it is the same deal on the Lomenett launch page, because we only have one version of the truth.