BlindLock has introduced a new local password vault that utilizes steganography to hide encrypted user data within standard PNG image files. This method conceals the vault's presence, making it appear as an ordinary image rather than a dedicated vault file. The complete password vault resides encrypted inside the PNG carrier.
Opening the BlindLock vault requires three matching components: the specific PNG carrier file, the user's master password, and an authorized device. A copied file alone is insufficient for access. BlindLock operates without transmitting vault contents to its servers, ensuring that no central collection of customer vaults exists for potential breaches.
The resting vault file employs 256-bit authenticated encryption. The system also incorporates NIST post-quantum components, specifically ML-KEM-1024 and ML-DSA-87 (FIPS 203/204), to address potential future quantum attacks on symmetric cryptography. The initial PIN for access is processed through Argon2id, a memory-hard key derivation function.
BlindLock includes a built-in authenticator and supports storing various data types, such as notes, 2FA secrets, and files in separate encrypted containers. It can also display crypto account balances without holding private keys, facilitating transaction preparation that must be approved on an external hardware wallet. BlindLock does not function as a crypto wallet or exchange and does not custody assets or sign transactions.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
BlindLock released a new password vault that conceals encrypted user data within ordinary PNG image files, requiring a master password and authorized device for access. This approach aims to enhance security by removing a central vault database and making the vault invisible to attackers.