Lose It and Shrug
A lost, locked Lomenett gives up nothing. Whoever finds it is holding an aluminum stick full of encrypted data and a chip that will destroy the key before it lets anyone guess their way in, so you order a new one, restore from your backup, and move on with your day.
That's the whole answer, and the rest of this page is the reasoning behind it.
What does the finder actually have?
They do not have your passwords. They have the hardware, meaning a screen, a thumbwheel, and a flash chip full of ciphertext. Your vault is encrypted, and the key that decrypts it is sealed inside a separate tamper-resistant secure element that never hands it out. Plugging the stick into a computer shows them nothing, taking it apart shows them nothing readable, and even desoldering the memory chip and dumping every byte gets them encrypted noise, because the key isn't in that memory and never was.
Holding the device is not the same as being inside it.
Can't they just guess the PIN?
They can try, but they won't get far. The secure element counts wrong attempts in its own hardware, and after a handful of failures it destroys the key permanently. This is not a timeout, and it is not a lockout that resets when you pull the battery, because once the key is destroyed the vault becomes unrecoverable by anyone, forever, including us.
That's why a short PIN is safe here when it wouldn't be safe anywhere else. A thief gets a few guesses on the one chip that can ever open the vault, rather than millions of guesses per second on a copy, and there is no copy, because the chip that holds the key can't be cloned. We wrote up the full mechanism at why a short PIN is safe here.
How do I get my passwords back?
You get them back from your backup. Lomenett has no account and no cloud, so recovery doesn't depend on us, and it works like this:
- An encrypted backup file. You keep a copy of your vault anywhere you like, such as a computer, a second USB stick, or an email to yourself. It's encrypted, so it's safe sitting anywhere.
- A BIP39 recovery phrase. This is a list of ordinary words you write down once and store somewhere safe, and it's what lets a new Lomenett decrypt that backup file.
With a new stick, your backup file, and your recovery phrase, you're back where you were, while the finder of the old one is still staring at a locked aluminum stick.
So the honest cost of losing a Lomenett is $90 and a few minutes of restoring, rather than your email, your bank, or a weekend of resetting two hundred accounts.
The shrug is the design goal
The day you lose a password manager should not be the day you panic, and that was the bar we built to, rather than "hard to break into" or "probably fine." A lost or stolen Lomenett is a dead end for whoever holds it, and it's a dead end for us too, on purpose, because there is no backdoor, no master key, and no recovery channel we control. Nobody who pressures us, hacks us, or impersonates us can open your vault, because we can't either.
One caveat, because we don't do fine print: all of this protects a lost Lomenett, and it does not protect passwords typed into a computer that already has malware on it. That limit is real, it applies to every password manager ever made, and we lay it out plainly in our attack surface. For what an attacker with real skills and a real lab would face, read can Lomenett be hacked?
One piece of plain best practice still applies: if you are afraid someone else may have access to your device, change your passwords anyway, especially the ones to important accounts like your bank and your email, since email can reset most other accounts. Restore onto the replacement first, and the device will type the new passwords for you as you update each account.
Lomenett is a password typer, meaning an offline USB stick that stores your logins and types them for you. It's $90 one time, and it's launching soon. Lose it and shrug. We named the promise before we built the product, and we built the product to keep it.