Magick Pot - Password Manager without storage

The password manager that does not require a file/cloud/whatever archive.

Grab the binary 👉 ⬇️ Magick Pot CLI for Windows or … much better download the Android app 👉 Get it on Google Play

Passwords become complicated (one capital letter, one number, one punctuation mark, one emoji, etc.)…

  • It’s impossible to use and remember different passwords for all of your accounts?
  • You often reuse the same passwords on various accounts?

With Magick Pot all you need to remember are:

  1. a username
  2. a scope - can be the web site URL or the service name (whatever you find it easy to associate with that account)
  3. a secret phrase - anything that is easy for you to remember!

While username and scope must vary from service to service (eg. GMail, Twitter, etc.), the secret phrase can always be the same.

Using these parameters Magick Pot will generate a password:

  • unique
  • complex and safe
  • that meets all validation standards (uppercase, lowercase, numbers and special characters)

Using Magick Pot does not stop you from managing your passwords using a secure ‘wallet’ and in fact this is encouraged. The combination of both tools will be winning.

What Magick pot gives to you is:

  • a simple way to generate good quality and safe passwords for websites and other services
  • a secure mechanism to retrieve your passwords even when you are away from home
  • an easy system for managing your passwords

WARNING!

To recreate the same password for a given account you must make sure you don’t forget the original values ​​you used (points 1-2-3)

If you enter different values, Magick Pot will produce a different password! (the difference between upper and lower case is also important)

How does Magick Pot work?

  • The text composed by (username + scope) is encrypted using the secret phrase.

Password-Based Key Derivation Function 2

  • The result of this encryption is used to feed a deterministic random number generator (let’s call it RNG).

  • The password is composed picking random characters using the integers generated by this RNG.

All these calculations are done “on the fly” every time you request it. This is why Magick Pot does not need any archive.

Usage

$ magick-pot.exe
Magick Pot - Crafted with passion by Luca Sepe.
The password manager that does not require a file/cloud or whatever archive.

Usage: magick-pot -username <ACCOUNT USERNAME> -scope <ACCOUNT SCOPE/URL/SERVICE>
  -username    The username of the account. Required.
  -scope       The account / service URL or name. Required.
  -secret      Secret phrase used for encryption. If not provided, magick-pot
               will ask for it interactively.

A simple example:

$ magick-pot -username pinco.pallo -scope gmail.com
Enter your secret phrase:**************
Your secret phrase again:**************
Here your token for <pinco.pallo/gmail.com> is: w2%FcoyTu1
What if you need to roll the password perodically?

Simply add a counter or something similiar.

$ magick-pot -username pinco.pallo -scope gmail.com/1
Enter your secret phrase:**************
Your secret phrase again:**************
Here your token for <pinco.pallo/gmail.com/1> is: 8Pt29vkR\j