Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Enpass

From Wikipedia, the free encyclopedia
Password management software
Enpass
DeveloperEnpass Technologies Inc.
Operating systemWindows,Windows Phone,macOS,Linux,ChromeOS,iOS,Android,Wear OS,WatchOS
PlatformChrome,Safari,Edge,Firefox andBrave
TypePassword manager
LicenseFreemium
Websiteenpass.io

Enpass is afreemiumpassword manager andpasskey manager available forMacOS,Windows,iOS,Android andLinux, with browser extensions for all major browsers,[1][2] and pricing plans for both personal use and business.[3][4][5]

By default, Enpass stores encrypted password vaults on users’ personal cloud accounts, locally on device, or in business clients’ internal cloud infrastructure.[1][6][7]

Functionality

[edit]

It features:

  1. Multiple vaults
  2. Password generation
  3. Biometric authentication
  4. Form filling for all supported platforms
  5. Integrated software keyboard for form filling on Android devices
  6. Generation oftime-based one-time passwords for online services[8]
  7. The Password Checkup tool uses zxcvbn to assesspassword strength.[9]
  8. It detects credential breaches by querying theHave I Been Pwned? database.[9]
  9. Privacy: The application features client-side encryption, using SQLCipher[10] to encrypt its keychain file locally with a user-defined master password. The Enpass app retains no user data on its company servers,[11][6] instead storing and syncing encrypted password vaults on storage controlled by the end user.
  10. Synchronisation: Enpass vaults are usually stored on users' owncloud storage service likeGoogle Drive,Box,Dropbox,OneDrive,iCloud. Enpass also supports self-hostedWebDAV solutions such asownCloud andNextcloud, as well as onbrowsers, plus offline synchronisation.[12][13][14]

Availability

[edit]

Enpass provides multiple client applications, including desktop applications, browser extensions and mobile apps. The desktop apps are available for Windows, macOS, and Linux,[15] while browser extensions are offered for Chrome, Firefox, Safari, Edge, Opera, Vivaldi and Brave.[16] Mobile apps are available for Android and iOS.[15]

Enpass products include Personal and Family editions that feature vault sharing via personal cloud accounts,[17] and Business and Enterprise editions with users’ vaults stored within each clients’ business-cloud infrastructure.[18] For personal and family users, the desktop app is free, and the mobile app is free up to 25 records, with more records and additional features available with a software subscription.[17][19] The Business and Enterprise editions are billed per user, per month, and include security audits, access recovery, and password-less vault sharing between invited co-workers.[18]

Encryption and Whitepaper

[edit]

The entire database is protected using AES-256 encryption. SQLCipher is used to technically implement the AES-256 encryption.[20]

In addition, the encryption key is derived from the master password using PBKDF2-HMAC-SHA512 with 320,000 iterations, which makes brute-force attacks extremely difficult.[20]

Enpass provides official security whitepapers[21] that explain the security architecture and encryption methods in more detail. These whitepapers are available for download on the Enpass website and are part of the official documentation on security and encryption.

Security Criticism

[edit]

2024 Evaluation of Password Checkup Tools

[edit]

A 2024 study by Hutchinson et al. examined the “password checkup” features of 14 password managers, including Enpass, using weak, breached, and randomly generated passwords. The authors found that the evaluated products reported weak and compromised passwords inconsistently and sometimes incompletely. No manager successfully flagged all known breached passwords. The study concludes that such inconsistencies may give users a false sense of security.[9]

2025 DOM-based Extension Clickjacking

[edit]

Security researcher Marek Tóth presented a vulnerability in browser extensions of several password managers, including Enpass, atDEF CON 33 on August 9, 2025. In their default configurations, these extensions were shown to be exposed to a DOM-based extension clickjacking technique, allowing attackers to exfiltrate user data with just a single click.[22] The affected password manager vendors were notified in April 2025. According to Tóth, Enpass version 6.11.6 (released August 13, 2025) addressed this issue.[23]

See also

[edit]

References

[edit]
  1. ^abGraw, Mike Jennings; Hale, Craig (2021-03-23)."Enpass Review: Pros & Cons, Features, Ratings, Pricing and more".TechRadar. Retrieved2024-09-30.
  2. ^"Enpass - Download Password Manager".Enpass.Archived from the original on 2024-10-02. Retrieved2024-09-30.
  3. ^Millares, Luis (2024-02-05)."Enpass Review 2024: Pricing, Security, Pros & Cons".TechRepublic. Retrieved2024-09-30.
  4. ^"Pricing & Free Trial".Enpass.Archived from the original on 2022-04-08. Retrieved2024-09-30.
  5. ^"Pricing for Businesses".Enpass. Retrieved2024-09-30.
  6. ^ab"Syncing and accessing Enpass data across devices".support.enpass.io. Retrieved2024-09-30.
  7. ^"Enpass Business integration with Microsoft 365 and Google Workspace".support.enpass.io. Retrieved2026-02-02.
  8. ^Thorp-Lancaster, Dan (28 December 2018)."Enpass 6 rolls out to all with multiple vaults, new design, and much more".Windows Central. Mobile Nations. Retrieved23 January 2019.
  9. ^abcHutchinson, Adryana; Munyendo, Collins W.; Aviv, Adam J; Mayer, Peter (2024-05-11). "An Analysis of Password Managers' Password Checkup Tools".Extended Abstracts of the CHI Conference on Human Factors in Computing Systems. CHI EA '24. New York, NY, USA: Association for Computing Machinery. pp. 1–7.doi:10.1145/3613905.3650741.ISBN 979-8-4007-0331-7.
  10. ^"SQLCipher".GitHub.Archived from the original on 2017-07-01. Retrieved2019-02-22.
  11. ^Singh, Karandeep (2023-01-03)."Why Enpass is my perfect LastPass replacement password manager".Android Police. Retrieved2024-09-30.
  12. ^"A Full Enpass Review for 2024 — Features, Pricing, Pros and Cons".The Tech Report. 2024-09-13. Retrieved2024-09-30.[dead link]
  13. ^"Using Wi-Fi sync in Enpass".support.enpass.io. Retrieved2024-09-30.
  14. ^"Using folder sync in Enpass".support.enpass.io. Retrieved2024-09-30.
  15. ^ab"Download Password Manager".Enpass. Retrieved2025-11-21.
  16. ^"Download Password Manager (Browser)".Enpass. Retrieved2025-11-21.
  17. ^ab"Pricing & Free Trial".Enpass.Archived from the original on 2022-04-08. Retrieved2024-10-28.
  18. ^ab"Pricing for Businesses".Enpass. Retrieved2024-10-28.
  19. ^"Enpass Review 2024: Is It a Good Password Manager?".SafetyDetectives. Retrieved2024-10-28.
  20. ^ab"Security and Data Encryption".
  21. ^"Enpass Security Whitepaper"(PDF).
  22. ^Benedict Collins (2025-08-22)."Multiple top password managers vulnerable to password stealing clickjacking attacks - here's what we know".TechRadar. Retrieved2025-11-09.
  23. ^Tóth, Marek (2025-08-09)."DOM-based Extension Clickjacking: Your Password Manager Data at Risk".marektoth.com. Retrieved2025-11-09.

External links

[edit]
Proprietary
Open source
Discontinued
Retrieved from "https://en.wikipedia.org/w/index.php?title=Enpass&oldid=1338692259"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp