Our Attack Surface
Lomenett is an offline hardware password manager. It's an aluminum USB stick with a screen and a thumbwheel that plugs in and types your passwords like a keyboard, with no app, no cloud, and no radios. This page is the whole security picture, covering what it protects you from, what it doesn't, and why we're comfortable saying both out loud.
Most security products tell you what they protect you from, and almost none tell you what they don't. We think that's backwards, because if you can't reason clearly about a password manager, you shouldn't trust it with your passwords.
The promise: lose it and shrug
The day you lose a password manager should not be the day you panic. You misplace your Lomenett, it falls out of your bag, or you leave it in a hotel room, and the right reaction is a shrug, because whoever finds it cannot get into your vault. You order a new one, restore from your backup, and move on.
That's the entire bar we built to. A lost or stolen Lomenett is a dead end for whoever holds it. It's a dead end for us too, on purpose, because there is no backdoor, no master key, and no recovery channel we control. NuLenke cannot open your vault, which means nobody who pressures us, hacks us, or impersonates us can open it either.
What that protects you from
You lose it
A lost, locked Lomenett gives up nothing. The finder has an aluminum stick, not your accounts.
Someone steals it
The outcome is the same, because holding the device is not the same as being inside it.
Someone rips the memory chip off and reads it
A determined attacker can desolder the flash and dump every byte, and what they get is encrypted data with no way to decrypt it. The key that unlocks your vault is not in that memory. It lives inside a separate tamper-resistant secure element (an NXP SE050) and never leaves that chip, so a full memory dump is unreadable without it.
Someone tries to guess your PIN
The secure element counts wrong attempts in hardware, and after a handful of failures it destroys the key permanently. This is not a timeout, and it is not a lockout you can wait out or reset by pulling the plug. Once the key is destroyed, the vault becomes unrecoverable by anyone, forever.
This is exactly why a short, memorable PIN is safe on Lomenett. An attacker gets a few guesses on the one device that can ever unlock the vault, rather than unlimited guesses on a copy, and the device can't be cloned into something guessable, because the chip that holds the key can't be copied or faked.
Put plainly, the secret that guards your Lomenett vault is sealed in hardware that never hands it out and destroys it under attack. Losing the device, having it stolen, or having it taken apart does not expose your passwords.
What Lomenett does not protect you from
You should hear this from us instead of finding it out later. The honest limit is this, and it's true of every password manager ever made, hardware or software:
A computer that's already compromised. If malware is running on the machine you plug Lomenett into, it can capture your passwords as they're typed, no matter where they came from. A hardware key, a cloud vault, and a notebook in a drawer are all exposed the moment a password gets entered on a machine an attacker controls. No password manager can defend a computer that's already owned, because the attacker just reads the password at the point of use and never touches the vault at all.
What Lomenett does have is no wireless of any kind, meaning no Wi-Fi, no Bluetooth, and no radio. That's a security decision rather than a missing feature, because it means there is no remote path to your data. Nobody can reach your Lomenett over the air, and even a tampered Lomenett has no way to send anything home. Every real attack requires someone to physically get your specific device, and even then, breaking in still means stealing the actual device, because the secure element can't be copied. Anyone with that much access to you and your computer already has easier ways to get your passwords.
The things we protect, we protect completely, and the one thing we don't protect against is the thing nothing in this category can.
Why we can say all of this out loud
Our promise is "too dumb to betray you," and we mean it literally, because Lomenett keeps no secret whose safety depends on you not understanding how the device works.
You can read our design, dump the flash, and study exactly how the lock works, and a locked Lomenett still doesn't give up your vault. That's not because we hid the method, but because the method holds even when it's fully understood.
We only sell security that survives being explained, because that's the only kind we're willing to put our name on.
Lomenett is launching soon. The launch page covers what it is, what it costs, and how to get on the beta list.