No Wi-Fi. No Bluetooth. On Purpose.

Lomenett has no Wi-Fi, no Bluetooth, and no radios of any kind, so there is no remote path to your passwords. It is an offline password manager in the strictest sense, and the only way to talk to it is to hold it in your hand and plug it in.

People ask us why it doesn't sync, why there's no app, and why we "left out" wireless. We didn't leave wireless out, because leaving something out implies an oversight. We kept it out on purpose.

Every big password breach you've read about needed a network

Think about how password managers actually get attacked. Nobody flies to your town and breaks into your house. They attack a server, from anywhere on earth, at scale, against millions of vaults at once, or they attack the connection, meaning the app, the browser extension, the sync channel, or the Bluetooth pairing. Every one of those is an attack path that exists only because the product is reachable over a network.

Any wireless connection is a path into the device that has to be defended for as long as the product exists. Lomenett removes the problem by having no such path at all.

What no radios actually buys you

Nobody can reach it over the air. There is no pairing to hijack, no signal to intercept, and no exploit to deliver remotely. A Lomenett on your desk is unreachable from the internet because it is not on the internet and can never be, since there is no hardware in it that could connect.

Even a tampered Lomenett has no way to phone home. Assume the worst case, where someone gets hold of your device and modifies it. Whatever their modification finds, it has no transmitter to send it with, because there is physically nothing inside that can produce a signal. The only way data leaves a Lomenett is through the USB port, into a machine you plugged it into on purpose.

Every attack requires your specific device, in hand. Having no radios shrinks the pool of possible attackers from everyone on the internet down to someone who can physically take your stick. As we explain in Our Attack Surface, even that person is stopped, because the key lives in a secure element that destroys it after a handful of wrong PIN guesses and cannot be cloned.

Air-gapped by construction

Security people call this an air gap, meaning a machine with no connection to any network at all. It is how the most careful setups store secrets, and normally it takes real discipline to maintain, because one careless connection breaks it. Lomenett is air-gapped password storage by construction, so there is no careless connection to make. The air gap cannot be broken if the radio was never installed.

The trade, said out loud

Cloud password managers win on sync, and we won't pretend otherwise. If you want a new password to appear on your laptop, your phone, and your work machine by itself, a cloud manager does that and Lomenett never will. With Lomenett, the passwords travel because the stick travels: one device that plugs into Windows, Mac, Linux, Chromebooks, and most phones, and types your login wherever the cursor is. The cost is that you carry it, and what it buys is that no remote path to your passwords exists.

The other honest limit doesn't go away either. A computer that's already running malware can capture any password as it's typed, from any password manager ever made. Everything is hackable. It's just a matter of time. All we can do is extend that time, and removing every wireless path is the single biggest extension we know how to build.

So where does the internet fit?

It doesn't fit anywhere, because there is no account to create, no cloud to trust, and no server of ours holding your vault. That raises a fair question: with no cloud, how do you back it up? That gets its own page at Backing Up Without a Cloud. If losing the stick is the worry that brought you here, start with Lose It and Shrug, or read the whole picture at the Lomenett page.